Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
11 Sept 2025Comune di VeronaThe Comune di Verona was fined for improperly sharing personal data of TARI taxpayers with a third party for engagement communications. The authority found a breach of the principles of lawfulness, fairness, and transparency.ITGaranteGDPR€6,000
21 Mar 2014GRUPOPSCOM SCPGRUPOPSCOM SCP was fined EUR 6,000 by the AEPD. The sanction concerned sending unsolicited commercial emails without recipient consent, in breach of Article 21 of the LSSI.ESAEPDePrivacy€6,000
11 Jul 2013Slots R Us srlSlots R Us srl was fined EUR 6,000 by the Garante for failing to provide the required information notice for its video surveillance system. The case concerned non-compliance with data protection rules on informing individuals subject to CCTV monitoring.ITGaranteGDPR€6,000
04 Aug 2017VODAFONE ONO, S.A.U.VODAFONE ONO, S.A.U. was fined by the AEPD in the amount of 6,000 EUR for making numerous advertising calls to numbers registered on the Robinson List. The conduct breached privacy rules and the right to object to direct marketing.ESAEPDePrivacy€6,000
12 Dec 2024AGENCE DE COMMUNICATION ET DE PRODUCTION AUDIOVISUELLE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 6,000 on AGENCE DE COMMUNICATION ET DE PRODUCTION AUDIOVISUELLE under a simplified procedure. The case concerns a confirmed breach of rules supervised by the CNIL.FRCNILGDPR€6,000
16 Dec 2009Campolongo Hospital s.p.a.Campolongo Hospital s.p.a. was fined by the Garante for collecting personal data through its website without providing users with the required information notice. The authority found a breach of Article 13 of the Italian Data Protection Code.ITGaranteGDPR€6,000
12 Jul 2022LEGAL TRAINING GROUP, S.L.LEGAL TRAINING GROUP, S.L. was fined by the AEPD €6,000 for sending commercial emails without the recipients’ consent. The case concerned a breach of Article 21 of the LSSI and reflects unlawful direct marketing activity.ESAEPDePrivacy€6,000
30 May 2023B.B.B.The entity was fined for keeping an operational surveillance camera inside a rented apartment without informing the tenants. The authority found this to be a breach of data protection rules.ESAEPDGDPR€6,000
14 Jan 2020REAL CLUB NAÚTICO DE RIBADEOREAL CLUB NAÚTICO DE RIBADEO was fined by the AEPD 6,000 EUR for publishing a court judgment containing personal data on its website and Facebook without anonymization. This constituted a breach of data protection rules.ESAEPDGDPR€6,000
28 May 2026Azienda Tutela della Salute per la LiguriaAzienda Tutela della Salute per la Liguria was fined by the Garante 6,000 EUR for violations related to the processing of personal data using a satellite localization system in a disciplinary procedure against an employee. The case concerned the use of data in a manner that did not comply with data protection requirements.ITGaranteGDPR€6,000
17 Nov 2020PEDROSO Y GÓMEZ ASESORÍA DE EMPRESAS, S.L.The company was fined by the AEPD in the amount of 6,000 EUR for sending emails without the recipients' consent. The authority also noted the absence of contact information for exercising data protection rights.ESAEPDGDPR€6,000
12 May 2011Centrale Palace HotelCentrale Palace Hotel was fined EUR 6,000 by the Garante. The violation concerned the failure to provide the required privacy notice for its video surveillance system, in breach of the Italian data protection code.ITGaranteGDPR€6,000
12 Dec 2023B*** GmbHB*** GmbH was fined by the DSB EUR 5,900 for failing to timely report a data breach to the supervisory authority and for not providing sufficient information required under GDPR. The company also did not cooperate with the authority’s further requests for information.ATDSBGDPR€5,900
16 Mar 2021SIA "“fit People”A fine of EUR 5,836 was imposed. The decision has entered into force.LVDVIGDPR€5,836
01 Jan 2018IBERIA LÍNEAS AÉREAS DE ESPAÑA, S.A. OPERADORA UNIPERSONALThe AEPD fined Iberia 5,700 EUR for sending unsolicited commercial emails to a complainant. The company had previously confirmed the cancellation of the complainant’s personal data, yet it continued marketing communications, breaching Article 21.1 of the LSSI.ESAEPDePrivacy€5,700
03 Jan 2017EL CORTE INGLES, S.A.EL CORTE INGLES, S.A. was fined by the AEPD in the amount of EUR 5,700 for continuing to send marketing emails to a complainant despite requests to stop. The authority found a breach of Article 21.1 of the LSSI.ESAEPDePrivacy€5,700
25 Oct 2016CEPSA COMERCIAL PETROLEO, SAUCEPSA COMERCIAL PETROLEO, SAU was fined by the AEPD in the amount of 5,700 EUR. The sanction concerned the sending of unauthorized commercial emails in breach of Article 21.1 of the LSSI.ESAEPDePrivacy€5,700
25 Jul 2025Anonimizirano (IP-RS 0609-34/2025/8)The legal entity did not establish a valid contract with a data processor. This breaches Article 28 GDPR, which requires processing by a processor to be governed by a contract.SIIP-RSGDPR€5,610
30 Jun 2022Anonymisé (CNPD decision-13-fr-2022)The company breached GDPR by failing to respect data retention limits and by not providing employees with adequate information about the vehicle geolocation system. The CNPD imposed a fine of EUR 5,600.LUCNPDGDPR€5,600
11 Dec 2025CANDIDAT AUX ELECTIONS LEGISLATIVES DE 2024 (procédure simplifiée)The CNIL imposed an administrative fine of EUR 5,500 on CANDIDAT AUX ELECTIONS LEGISLATIVES DE 2024. The case was handled under a simplified procedure.FRCNILGDPR€5,500