Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
22 Jul 2019SANTI 3000, S.L.SANTI 3000, S.L. was fined by the AEPD for using video surveillance footage without informing employees. The authority treated this as a breach of data protection principles.ESAEPDGDPR€5,500
05 Jul 2023Anonymisé (CNPD decision-06-fr-2023)The company failed to implement appropriate technical and organizational measures to ensure data security. It also did not cooperate with the supervisory authority, breaching Articles 31 and 32 of the GDPR.LUCNPDGDPR€5,330
06 Oct 2021Anonymisé (CNPD decision-35-fr-2021)The company was fined by the CNPD in the amount of 5,300 EUR for breaching GDPR requirements. The authority found that it failed to provide adequate information to data subjects and did not comply with the data minimization principle.LUCNPDGDPR€5,300
16 Jun 2023B.B.B.The entity was fined for installing a surveillance camera in a rented property without informing the tenant. The authority treated this as a breach of data protection rules.ESAEPDGDPR€5,300
13 Jul 2006Comune di LatinaThe Municipality of Latina was fined by the Garante for failing to notify the processing of students’ personal data obtained from public records. The authority found a breach of the obligations under the data protection code.ITGaranteGDPR€5,164
06 Jul 2006Ced di Demartis CarloThe sole proprietorship Ced di Demartis Carlo was fined by the Garante for failing to notify the processing of personal data. This constituted a breach of Article 7 of Law 675/1996.ITGaranteGDPR€5,164
06 Jul 2006Comune di AugustaThe Municipality of Augusta was fined by the Garante for failing to make a required notification under data protection law. The breach concerned Article 163 of the Codice Privacy.ITGaranteGDPR€5,164
05 Mar 2026ASSOCIATION DE DÉFENSE DE DROITS FONDAMENTAUX(procédure simplifiée)CNIL imposed a EUR 5,100 penalty on ASSOCIATION DE DÉFENSE DE DROITS FONDAMENTAUX in connection with the liquidation of astreinte. The matter concerns enforcement of a prior obligation, with the amount arising from non-compliance.FRCNILGDPR€5,100
25 Jul 2021CALDERERIA Y SOLDADURA DE ESTRUCTURAS METALICAS, S.L.The company was fined by the AEPD for processing personal data without consent, which breaches Article 6 of the GDPR. The case indicates that no valid legal basis was in place for the processing activity.ESAEPDGDPR€5,000
11 Jun 2020XFERA MÓVILES, S.A.XFERA MÓVILES, S.A. was fined EUR 5,000 by the AEPD for failing to provide requested information. The breach concerned the duty to cooperate with the data protection authority during its proceedings.ESAEPDGDPR€5,000
09 Aug 2022XFERA MÓVILES, S.A.XFERA MÓVILES, S.A. was fined 5,000 EUR by the AEPD for sending commercial SMS messages without the recipient’s consent. The authority found this conduct breached Article 21 of the LSSI.ESAEPDePrivacy€5,000
17 Apr 2026Framos Italia s.r.l. in liquidazioneFramos Italia s.r.l. in liquidation was fined EUR 5,000 by the Garante. The authority found that former employees’ email accounts were not deactivated and that information on data processing was not clear and comprehensive.ITGaranteGDPR€5,000
26 Oct 2022FUNDACIÓN CITIZENGOFUNDACIÓN CITIZENGO was fined by the AEPD EUR 5,000 for sending unsolicited emails without recipients’ consent. The authority found a breach of Article 7 GDPR on valid consent.ESAEPDGDPR€5,000
25 Jul 2022MZN HELLAS A.E.The company was fined for sending unsolicited SMS messages for marketing purposes despite the recipient's objection. This conduct breached GDPR rules on personal data processing and direct marketing.GRHDPAGDPR€5,000
01 Jan 2021ASOCIACIÓN ESPAÑOLA PARA LA ENSEÑANZA ONLINEThe entity was fined by the AEPD 5,000 EUR for failing to comply with a data deletion request and for sending unsolicited marketing emails without consent. The case indicates non-compliance with data subject rights and rules on direct marketing communications.ESAEPDGDPR€5,000
04 Aug 2017VodafoneVodafone was fined 5,000 EUR by the HDPA for failing to satisfy the complainant’s request to access their personal data. The case concerns a breach of the data subject’s access rights under the controller’s obligations.GRHDPAGDPR€5,000
01 Jun 2023Comune di GuardiagreleComune di Guardiagrele was fined EUR 5,000 by the Garante for failing to provide an adequate response to a data access request. The authority found a breach of the principles of lawfulness, fairness, and transparency in data processing.ITGaranteGDPR€5,000
01 Jan 2020BANCO DE SABADELL, S.A.Banco de Sabadell was fined for sending a commercial email to a customer who had previously opted out of such communications. The authority found a breach of Article 21 of the LSSI governing electronic commercial communications.ESAEPDePrivacy€5,000
27 Oct 2022COPY COFFEE, S.L.COPY COFFEE, S.L. was fined EUR 5,000 by the AEPD for sending unsolicited commercial emails despite the recipient's prior objection. The authority found a breach of Article 21 of the LSSI governing electronic marketing communications.ESAEPDePrivacy€5,000
12 Mar 2026Bakeca s.r.l.Bakeca s.r.l. was fined €5,000 by the Italian data protection authority, Garante. The case concerned the publication of online ads without the required consent, which breached data protection rules.ITGaranteGDPR€5,000