Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
22 Oct 2015Liceo scientifico statale Plinio SenioreLiceo scientifico statale Plinio Seniore was fined EUR 10,400 by the Garante for processing biometric data and using video surveillance without providing adequate information to the data subjects. The authority found this conduct to be in breach of the Italian Data Protection Code.ITGaranteGDPR€10,400
20 Jan 2012Manage Consulting International s.r.l.Manage Consulting International s.r.l. was fined by the Italian Garante in the amount of 10,400 EUR. The sanction concerned sending unsolicited promotional faxes without proper consent and required information.ITGaranteGDPR€10,400
08 Mar 2018Carriere Italia s.r.l.Carriere Italia s.r.l. was fined for processing personal data revealing health status without notifying the Garante. The authority also found that required information was not provided to data subjects in job advertisements.ITGaranteGDPR€10,400
22 Apr 2010Cassine di Pietra s.r.l.Cassine di Pietra s.r.l. was fined EUR 10,400 by the Garante for making unsolicited promotional calls using automated systems. The authority found that proper information was not provided and consent had not been obtained.ITGaranteGDPR€10,400
30 Dec 2011Dike Giuridica s.r.l.Dike Giuridica s.r.l. was fined by the Garante in the amount of 10,400 EUR for sending unsolicited commercial emails without prior explicit consent from recipients. The authority also found that the required privacy notice was not provided, in breach of the Italian data protection code.ITGaranteGDPR€10,400
07 Mar 2013Greentel Soc. Coop.Greentel Soc. Coop. was fined by the Garante 10,400 EUR for sending promotional communications by fax without providing adequate information or obtaining explicit consent. The authority found violations of Articles 13 and 130 of the Italian Data Protection Code.ITGaranteGDPR€10,400
08 May 2013Profile 2100 srlProfile 2100 srl was fined EUR 10,400 by the Garante for sending unsolicited promotional communications by fax without valid consent. The case concerned a breach of data protection rules and direct marketing requirements.ITGaranteGDPR€10,400
01 Jun 2016Liceo Scientifico di Stato G. BattagliniLiceo Scientifico di Stato G. Battaglini was fined by the Garante 10,400 EUR for processing staff biometric data without providing the required information. The authority also found that the processing had not been notified as required by law.ITGaranteGDPR€10,400
29 Sept 2011XX s.a.s.XX s.a.s. was fined for sending unsolicited promotional emails without the recipients' explicit consent. The authority also found that the required privacy notice was not provided, constituting a data protection breach.ITGaranteGDPR€10,400
01 Aug 2012Spazio S s.r.l.Spazio S s.r.l. was fined by the Garante 10,400 EUR for sending unsolicited commercial emails. The authority found that the company failed to provide adequate information and did not obtain valid consent from recipients, breaching privacy rules.ITGaranteGDPR€10,400
07 Jul 2022Anonymisé (CNPD decision-15-fr-2022)The company was fined by the CNPD EUR 10,500 for breaching the data minimization principle and for failing to adequately inform individuals about video surveillance systems. The authority cited violations of GDPR Articles 5(1)(c) and 13.LUCNPDGDPR€10,500
21 Jan 2016CAIXABANK, S.A.CAIXABANK, S.A. was fined by the AEPD EUR 10,500 for sending unsolicited advertising SMS messages without prior recipient consent. The authority also found that no opt-out mechanism was provided, in breach of Article 21 of the LSSI.ESAEPDePrivacy€10,500
29 Jul 2025Anonimizirano (IP-RS 0609-18/2025/7)The legal entity was fined by IP-RS for unlawfully processing personal data by redirecting emails without a legal basis. The authority found a breach of the GDPR principle of lawfulness.SIIP-RSGDPR€10,614
24 Apr 2024Dane anonimowe (Komitet Inicjatywy Ustawodawczej W. na rzecz ustawy o zmianie ustawy z dn. 24 lipca 2015 r. Prawo o zgromadzeniach oraz niektórych innych ustaw)UODO imposed an administrative fine on the entity responsible for a list of citizens supporting a legislative initiative. The authority found inadequate technical and organisational measures for the risk, a failure to regularly test security controls, and delays in reporting and notifying the personal data breach.PLUODOGDPR€2,527
04 Jan 2024N*** -FußballvereinigungThe football association failed to implement appropriate technical and organizational measures for handling data deletion requests. The authority found breaches of Articles 25 and 17 GDPR and imposed a fine of EUR 11,000.ATDSBGDPR€11,000
29 Sept 2021Prefettura - Ufficio Territoriale del Governo di GenovaPrefettura - Ufficio Territoriale del Governo di Genova was fined by the Garante for publishing personal data on its institutional website. The conduct breached GDPR requirements on lawful processing and protection of personal data.ITGaranteGDPR€11,000
12 Sept 2025Dane anonimowe (Q. Sp. z o.o.)The Polish DPA (UODO) imposed an administrative fine of PLN 11,365 on Q. Sp. z o.o. The authority found a breach of Article 38(6) GDPR because the data protection officer role was performed by the company’s president.PLUODOGDPR€2,669
15 Dec 2021Anonymisé (CNPD decision-48-fr-2021)The company did not comply with GDPR requirements on data minimization and on providing information to data subjects, including employees and third parties, in connection with its video surveillance system. CNPD imposed a fine of 11,600 EUR.LUCNPDGDPR€11,600
07 Dec 2023Dane anonimowe (N. Sp. z o.o. z siedzibą w W. przy ul.)The President of UODO imposed a PLN 11,790 administrative fine on N. Sp. z o.o. The company failed to cooperate with the authority in the performance of its duties and did not provide access to personal data and information necessary for those duties.PLUODOGDPR€2,722
12 Jul 2023Dane anonimowe (Panią K.W. prowadzącą działalność gospodarczą pod nazwą W. z miejscem wykonywania działalności w O. przy ul.)UODO imposed an administrative fine on the business for failing to report a personal data breach to the supervisory authority within 72 hours. The authority also found that the affected individuals were not notified without undue delay.PLUODOGDPR€2,651