Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-22.8%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
27 Dec 2012Euro-Catering O.E.The company installed a CCTV system without notifying the supervisory authority, failed to display required informational signs, and collected excessive data. These actions breached privacy protection rules.GRHDPAGDPR€20,000
27 Dec 2012Euro-Catering O.E.The company was fined for failing to comply with a prior decision by the authority. It was noted that it no longer operated the stores concerned and that its financial situation was difficult.GRHDPAGDPR€10,000
21 Aug 2018Eurobank Ergasias A.E.Eurobank Ergasias A.E. was fined by the HDPA in the amount of 5,000 EUR for failing to maintain and process accurate data of its debtors. The authority found that the company’s handling of debtor information breached data protection requirements.GRHDPAGDPR€5,000
20 Mar 2017Eurobank Ergasias A.E.Eurobank Ergasias A.E. was fined EUR 10,000 by the HDPA. The authority found that the bank did not adequately satisfy the complainant’s right of access to recorded telephone conversations. The case concerned the legal obligation to provide access to such recordings.GRHDPAGDPR€10,000
16 Jun 2015Eurobank Ergasias AEA fine was imposed for failing to maintain appropriate organizational and technical security measures. This led to unauthorized employee access to the complainant's personal data.GRHDPAGDPR€5,000
16 Jun 2015Eurobank Ergasias AEA fine was imposed on Eurobank Ergasias AE for unlawful processing of the complainant’s personal data. The case concerned a breach of data protection rules by the bank.GRHDPAGDPR€5,000
26 Mar 2026Euro Bangla MinimarketThe Garante fined Euro Bangla Minimarket EUR 1,000 for improper use of a video surveillance system. Images from six cameras were visible to everyone on a monitor in the store, which breached GDPR requirements.ITGaranteGDPR€1,000
18 Aug 2021EULEN SEGURIDAD, S.A.EULEN SEGURIDAD, S.A. was fined by the AEPD 3,000 EUR for disclosing employees' DNI numbers in a workplace notice. The authority found a breach of confidentiality and data security principles.ESAEPDGDPR€3,000
11 Feb 2022Etterforsker1 Gruppen ASEtterforsker1 Gruppen AS was fined NOK 50,000 by Datatilsynet for conducting a credit assessment of an individual without a legal basis. The assessment was carried out on behalf of a client who claimed to have a compensation claim against the complainant.NODatatilsynetGDPR€4,964
23 May 2024ETABLISSEMENT PUBLIC NATIONAL (ENSEIGNEMENT) (procédure simplifiée)CNIL imposed an administrative fine of EUR 6,000 on ETABLISSEMENT PUBLIC NATIONAL (ENSEIGNEMENT) under a simplified procedure. The case concerned a breach identified by the supervisory authority.FRCNILGDPR€6,000
29 Jan 2026ÉTABLISSEMENT PUBLIC EXERÇANT UNE ACTIVITÉ DE TRANSPORT URBAIN (procédure simplifiée)The CNIL imposed an administrative fine of EUR 20,000 on ÉTABLISSEMENT PUBLIC EXERÇANT UNE ACTIVITÉ DE TRANSPORT URBAIN. The case was handled under a simplified procedure.FRCNILGDPR€20,000
11 Dec 2025ETABLISSEMENT PUBLIC EXERCANT UNE ACTIVITE DE GESTION LOCATIVE DE LOGEMENTS (procédure simplifiée)The CNIL imposed an administrative fine of EUR 20,000 on ETABLISSEMENT PUBLIC EXERCANT UNE ACTIVITE DE GESTION LOCATIVE DE LOGEMENTS and issued an injunction. The case concerns a regulatory breach in the area of data protection.FRCNILGDPR€20,000
22 Jan 2026ÉTABLISSEMENT PUBLIC ADMINISTRATIFCNIL imposed an administrative fine of EUR 5,000,000 on ÉTABLISSEMENT PUBLIC ADMINISTRATIF and issued an injunction. The case concerns a confirmed breach of rules supervised by CNIL.FRCNILGDPR€5,000,000
25 Jul 2024ETABLISSEMENT D'ENSEIGNEMENT SUPERIEUR PRIVE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 20,000 on ETABLISSEMENT D'ENSEIGNEMENT SUPERIEUR PRIVE under a simplified procedure. The case concerned a confirmed breach of rules supervised by the CNIL.FRCNILGDPR€20,000
14 Apr 2023ESTUDIO VILLALBA ANTIQUE, S.L.ESTUDIO VILLALBA ANTIQUE, S.L. was fined by the AEPD for processing personal data without consent. The authority found a breach of the lawfulness principle under Article 6(1) GDPR.ESAEPDGDPR€5,000
26 Jan 2022ESTUDIO INMOBILIARIO SAN ISIDRO, S.L.UESTUDIO INMOBILIARIO SAN ISIDRO, S.L.U was fined by the AEPD EUR 5,000 for unlawfully obtaining personal data and visiting the complainant's home to promote real estate services without proper consent. The case concerns unlawful processing and improper direct marketing contact.ESAEPDGDPR€5,000
07 Feb 2025ESTUDIO ALCAZAR DEL GENIL 2022, S.L.ESTUDIO ALCAZAR DEL GENIL 2022, S.L. was fined EUR 10,000 by the AEPD for collecting and storing personal data taken from mailboxes without consent or notice to the data subjects. The authority found breaches of the lawful basis and transparency requirements under GDPR Articles 6(1) and 14.ESAEPDGDPR€10,000
21 Apr 2016Estracom s.p.a.Estracom s.p.a. was fined EUR 20,000 by the Garante for retaining customers’ call data for more than thirty days. The authority found this to be a breach of data protection rules.ITGaranteGDPR€20,000
21 Mar 2024Estlevante s.r.l.s.The Garante imposed a EUR 2,000 fine on Estlevante s.r.l.s. for failing to provide the required privacy notice for its video surveillance system. The breach concerned Article 13 of the GDPR.ITGaranteGDPR€2,000
26 Oct 2020ESTILO 1221, S.C.ESTILO 1221, S.C. was fined by the AEPD EUR 1,500 for sending unsolicited commercial emails without recipient consent. The conduct breached Article 21.1 of the LSSI, which prohibits this type of marketing communication without prior consent.ESAEPDePrivacy€1,500