Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
26 Oct 2023A.C. Group S.r.l.s.A.C. Group S.r.l.s. was fined by the Garante 10,000 EUR for making an unsolicited marketing call to a number listed in the Public Register of Objections without prior informed consent. The authority also found that the company failed to adequately respond to a data subject rights request.ITGaranteGDPR€10,000
13 Feb 2024LA VANGUARDIA EDICIONES, S.L.LA VANGUARDIA EDICIONES, S.L. was fined by the AEPD €10,000 for installing non-essential cookies on its website without obtaining valid user consent. The authority found this to be a breach of the LSSI.ESAEPDePrivacy€10,000
05 Oct 2017Qiu JunjieQiu Junjie was fined EUR 10,000 by the Garante for failing to protect video surveillance recordings with a password. The authority found this breached the minimum security measures required under the Italian Data Protection Code.ITGaranteGDPR€10,000
04 Apr 2024GAFAS EN RED DE ÓPTICAS, S.L.GAFAS EN RED DE ÓPTICAS, S.L. was fined €10,000 by the AEPD for sending unsolicited advertising SMS messages without providing an opt-out link. The conduct breached the LSSI rules governing electronic marketing communications.ESAEPDePrivacy€10,000
24 Oct 2019Anonymizováno (ÚOOÚ UOOU-01096/19-19)The entity was fined by the UOOU for sending commercial communications without a valid legal basis. The messages were not properly identified as commercial and the sender was not correctly identified.CZUOOUePrivacy€391
30 Apr 2025BITDEFENDER SRLIn April 2025, the Romanian authority ANSPDCP completed an investigation into BITDEFENDER SRL and found a GDPR violation. The company was fined EUR 10,000.ROANSPDCPGDPR€10,000
08 Mar 2012Comune di Marano PrincipatoThe Municipality of Marano Principato was fined by the Garante for processing personal data without appointing data processors and for failing to adopt minimum security measures. The authority found a breach of Article 33 of the Italian Privacy Code.ITGaranteGDPR€10,000
22 May 2018Ordinanza ingiunzione - 22 maggio 2018 [9027240]A general practitioner was fined for failing to adopt minimum security measures in a health information system. The deficiencies allowed unauthorized access to the data.ITGaranteGDPR€10,000
29 Jan 2020CASA GRACIO OPERATION, SLUCASA GRACIO OPERATION, SLU was fined by the AEPD 10,000 EUR for installing a video surveillance system that could capture public areas and access points. The authority found that this processing breached data protection rules.ESAEPDGDPR€10,000
28 Apr 2022Ministero della DifesaMinistero della Difesa was fined EUR 10,000 by the Garante for improperly disclosing personal data, including health-related information, to unauthorized personnel. The authority found a breach of the principles of lawfulness, fairness, and transparency.ITGaranteGDPR€10,000
15 Jan 2020Comune di Francavilla FontanaThe Municipality of Francavilla Fontana was fined 10,000 EUR by the Garante for publishing personal data on its institutional website. The conduct breached data protection rules and triggered supervisory action.ITGaranteGDPR€10,000
13 Apr 2026Dane anonimowe (Pana L. A. prowadzącego działalność gospodarczą pod nazwą: A.)UODO issued a reprimand to the controller, two agents and a sub-agent, and imposed an administrative fine on the sub-agent. The case concerned GDPR breaches related to processing security, verification of processors, and the principles of confidentiality and accountability.PLUODOGDPR€2,385
22 Apr 2010Cassine di Pietra s.r.l.Cassine di Pietra s.r.l. was fined by the Garante €10,400 for making unsolicited promotional calls using automated systems. The authority found that proper information was not provided and consent had not been obtained, constituting a data protection breach.ITGaranteGDPR€10,400
05 Apr 2012XY s.r.l.XY s.r.l. was fined by the Garante 10,400 EUR for sending unsolicited commercial communications by email despite the recipient's repeated objections. The case indicates a breach of data protection rules governing electronic marketing and respect for opt-out requests.ITGaranteGDPR€10,400
15 Nov 2012Italiasalute s.r.l.Italiasalute s.r.l. was fined by the Garante EUR 10,400 for processing personal data on its website without providing data subjects with adequate information. The authority also found that consent was obtained in a non-compliant manner, particularly for profiling and marketing purposes.ITGaranteGDPR€10,400
04 Oct 2011Mancosu Editore s.r.l.Mancosu Editore s.r.l. was fined by the Garante 10,400 EUR for sending promotional emails without providing the required information to data subjects and without obtaining explicit consent. The conduct breached Articles 13 and 130 of the Italian Data Protection Code.ITGaranteGDPR€10,400
29 Nov 2012Eco Education s.r.l.Eco Education s.r.l. was fined by the Garante 10,400 EUR for sending promotional faxes without prior, specific, and informed consent from recipients. The authority found this to be a breach of data protection rules.ITGaranteGDPR€10,400
15 Sept 2011XY s.r.l.XY s.r.l. was fined by the Garante in the amount of EUR 10,400 for sending an unsolicited promotional fax. The conduct breached data protection and marketing communication rules.ITGaranteGDPR€10,400
09 Nov 2017Consorzio di Polizia locale Valle AgnoConsorzio di Polizia locale Valle Agno was fined EUR 10,400 by the Garante for deploying a mobile video surveillance system and a localization system on employee devices without the required information or prior notification. The authority found this to be a breach of data protection rules.ITGaranteGDPR€10,400
11 Oct 2012Professional Pneus sccrlProfessional Pneus sccrl was fined EUR 10,400 by the Garante. The authority found that personal data were processed without giving users the option to refuse consent for marketing purposes, breaching transparency requirements.ITGaranteGDPR€10,400