Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-22.8%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
30 Jun 2022Federazione Italiana Sommelier, Albergatori e RistoratoriFederazione Italiana Sommelier, Albergatori e Ristoratori was fined by the Garante 5,000 EUR for unlawful processing of personal data. The breach involved the improper communication of one member’s data to all associates.ITGaranteGDPR€5,000
16 Jun 2022Federazione Italiana NuotoFederazione Italiana Nuoto was fined EUR 2,000 by the Italian supervisory authority, Garante. The case concerned a failure to respond to a data access request under Article 15 of the GDPR.ITGaranteGDPR€2,000
10 Oct 2024FEDERAL NAJANAJANA, S.L.FEDERAL NAJANAJANA, S.L. was fined by the AEPD €2,000 for sending unsolicited commercial messages via WhatsApp without the recipient’s explicit consent. The authority found a breach of Article 21 of the LSSI.ESAEPDePrivacy€2,000
23 Dec 2021Federación Estatal de Servicios, Movilidad y Consumo de la UGT (FESMC-UGT)FESMC-UGT was fined 2,000 EUR by the AEPD for sending emails to employees’ corporate addresses without proper authorization. The authority found this to be a breach of data protection rules.ESAEPDGDPR€2,000
02 Jan 2024FEDERACIÓN DE SERVICIOS PÚBLICOS DE LA UGT (FSP-UGT)The entity sent emails that disclosed personal data of multiple recipients. The AEPD found a breach of the confidentiality principle under Article 5(1)(f) GDPR.ESAEPDGDPR€5,000
01 Jan 2022FEDERACIÓN DE SERVICIOS A LA CIUDADANÍA DE CCOOThe entity was fined by the AEPD €3,000 for breaching data protection principles. The case involved the improper disclosure of personal data related to a COVID-19 case among employees.ESAEPDGDPR€3,000
17 Mar 2025FEDERACION DE COLUMBICULTURA DE CASTILLA-LA MANCHAThe Federation published a voter list on its website, disclosing members’ personal data without consent. The authority found that adequate security measures were not in place to protect the data.ESAEPDGDPR€1,000
11 Aug 2020FEDERACIÓN DE BALONCESTO DE CASTILLA Y LEÓNFEDERACIÓN DE BALONCESTO DE CASTILLA Y LEÓN was fined by the AEPD 5,000 EUR for the unauthorized disclosure of personal data. The data included names, DNI numbers, and signatures, which were published in a newspaper and on social media.ESAEPDGDPR€5,000
15 Jul 2022FEDERACIÓN DE ATENCIÓN A LA CIUDADANÍA DE LA UNIÓN SINDICAL OBRERA (FAC-USO)The organization continued sending emails to an individual after they requested deletion of their personal data. The AEPD found a breach of Article 6 of the GDPR and imposed a EUR 3,000 fine.ESAEPDGDPR€3,000
16 Feb 2022FEDERACION CASTELLANO-LEONESA DE SALVAMENTO Y SOCORRISMOThe organization was fined EUR 2,000 by the AEPD for requiring participants to consent to data processing and image rights transfers without any option to refuse. The authority found this incompatible with Article 6(1) GDPR.ESAEPDGDPR€2,000
15 Sept 2022FCA Italy S.p.A.FCA Italy S.p.A. was fined by the Garante for failing to respond to a data subject's request for access to personal data related to employment. The authority found a breach of GDPR Article 15.ITGaranteGDPR€40,000
16 Dec 2021FCA Italy s.p.a.FCA Italy s.p.a. was fined 20,000 EUR by the Garante for breaching GDPR provisions on the right of access and transparency obligations. The case arose from a complaint by an English citizen about the handling of their personal data.ITGaranteGDPR€20,000
06 Jun 2024FCA Bank S.p.A.FCA Bank S.p.A. was fined EUR 1,000,000 by the Italian supervisory authority Garante for data protection violations. The case concerned the use of blacklists in car rental services, raising compliance concerns about personal data processing.ITGaranteGDPR€1,000,000
07 Jul 2011F.B. Aurum di Ferrero Wilma e Barathier Sergio s.n.c.F.B. Aurum di Ferrero Wilma e Barathier Sergio s.n.c. was fined by the Garante 10,000 EUR for operating a video surveillance system without providing the required notice to data subjects. This constituted a breach of Article 13 of the Italian Privacy Code.ITGaranteGDPR€10,000
16 Sept 2021Favrskov KommuneFavrskov Kommune was fined 75,000 DKK for failing to implement appropriate security measures, including encryption, to protect sensitive personal data on a stolen laptop. The authority found a breach of GDPR Article 32.DKDatatilsynetGDPR€10,086
20 Mar 2025FAVORIT SPORTSKA KLADIONICA d.o.o.FAVORIT SPORTSKA KLADIONICA d.o.o. was fined by AZOP EUR 175,000 for failing to store personal data only as long as necessary and for not implementing appropriate technical safeguards. The case concerned breaches of Articles 5 and 32 of the GDPR.HRAZOPGDPR€175,000
18 Sept 2014Fattoria di Casalbosco s.r.l.Fattoria di Casalbosco s.r.l. was fined 2,400 EUR by the Garante. The case concerned the collection of personal data through a website form without providing the required privacy notice, in breach of Article 13 of the Italian Data Protection Code.ITGaranteGDPR€2,400
20 Jun 2024Fastweb S.p.A.Fastweb S.p.A. was fined by the Garante EUR 1,000,000 for carrying out telemarketing activities without obtaining proper consent from the contacted individuals. The authority found a breach of fairness and transparency principles in the processing of personal data.ITGaranteGDPR€1,000,000
25 Mar 2021Fastweb S.p.A.Fastweb S.p.A. was sanctioned by the Garante for making unauthorized promotional calls and sending messages without proper consent. The authority also found insufficient measures to ensure data processing security and GDPR compliance.ITGaranteGDPR€4,501,000
18 Oct 2012Fastweb S.p.A.Fastweb S.p.A. was fined by the Garante in the amount of EUR 300,000 for violations related to unsolicited telemarketing calls and improper data processing. The case indicates deficiencies in marketing compliance and personal data protection controls.ITGaranteGDPR€300,000