Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-22.8%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
19 Sept 2013Estav Nordovest ToscanaEstav Nordovest Toscana was fined 10,000 EUR by the Garante. The violation concerned the unlawful publication of candidates' judicial data on its website during a recruitment process.ITGaranteGDPR€10,000
01 Jan 2014ESTABLIMENTS MIRÓ, S.L.ESTABLIMENTS MIRÓ, S.L. was fined by the AEPD EUR 1,000 for sending unauthorized advertising text messages to the complainant's mobile phone. The messages were sent after the data subject had requested cancellation of their data.ESAEPDePrivacy€1,000
26 Mar 2026Esselunga S.p.A.Esselunga S.p.A. was fined EUR 5,000 by the Italian supervisory authority, Garante. The case concerned a failure to respond to a data access request under Article 15 GDPR, including access to employee attendance records.ITGaranteGDPR€5,000
14 Apr 2010Espectáculos InterfaceEspectáculos Interface was fined EUR 1,200 by the AEPD for sending commercial emails without prior consent from recipients. The case concerned Article 21 of the LSSI, which governs unsolicited commercial communications.ESAEPDePrivacy€1,200
01 Mar 2017ESPASA CALPE, S.A.ESPASA CALPE, S.A. was fined EUR 2,500 by the AEPD for continuing to send commercial emails to a customer after confirming deletion of the customer’s personal data. The authority found this to be a breach of electronic communications and data protection rules.ESAEPDePrivacy€2,500
29 Oct 2013ESPASA CALPE, S.A.ESPASA CALPE, S.A. was fined EUR 35,000 by the AEPD for sending unsolicited commercial emails. The conduct breached Article 21 of the LSSI despite prior requests to be removed from the mailing list.ESAEPDePrivacy€35,000
06 Oct 2016ESPACIO DOCENTE, S.L.ESPACIO DOCENTE, S.L. was fined EUR 1,000 by the AEPD for sending unsolicited commercial emails without prior consent. The company also failed to stop communications after being asked to do so, breaching Article 21.1 of the LSSI.ESAEPDePrivacy€1,000
07 Jul 2022E Software Concept SRLE Software Concept SRL was fined EUR 3,000 by ANSPDCP. The authority found that the company had not implemented adequate technical and organizational measures to ensure a level of security appropriate to the processing risk.ROANSPDCPGDPR€3,000
07 Jul 2022E Software Concept SRLE Software Concept SRL was fined EUR 1,000 by ANSPDCP. The sanction was imposed for failing to provide requested information to the supervisory authority.ROANSPDCPGDPR€1,000
26 Jun 2020ESLORA PROYECTOS, S.L.ESLORA PROYECTOS, S.L. was fined by the AEPD 10,000 EUR for failing to provide cookie information and for not obtaining user consent before using cookies. The authority cited a breach of Article 22.2 of the LSSI.ESAEPDePrivacy€10,000
05 Dec 2024ESL Consultancy Services Ltd Between 15 September 2022 and 5 December 2023, 37,977 complaints were received about direct marketing messages sent at the instigation of ESL Consultancy Services Ltd. The ICO fined the company GBP 200,000 and issued an enforcement notice.GBICOGDPR€241,000
30 May 2012ESCUELA HIPICA OLIMPIA, S.L.ESCUELA HIPICA OLIMPIA, S.L. was fined by the AEPD EUR 1,200 for sending commercial emails after the individual requested deletion of personal data and cessation of advertising communications. The case concerns failure to respect the recipient’s opt-out and data erasure request.ESAEPDePrivacy€1,200
01 Jan 2024ESCOLA LES CAROLINES COOP. V.The school was fined by the AEPD 10,000 EUR for processing a minor’s image without a lawful basis. The child’s photograph was displayed on posters inside the school premises, which was found to breach GDPR Article 6(1).ESAEPDGDPR€10,000
11 Apr 2013Errebian S.p.aErrebian S.p.a was fined EUR 6,000 by the Italian Garante. The case concerned the failure to provide the required data protection notice on website forms, in breach of Article 13 of the Italian Data Protection Code.ITGaranteGDPR€6,000
18 Jul 2023Ermeslink di Giovanni Di StefanoThe Garante imposed a fine of EUR 5,000 on Ermeslink di Giovanni Di Stefano for improperly handling video surveillance data. The breach concerned data protection rules and could have affected all residents and non-residents of the Municipality of Modica.ITGaranteGDPR€5,000
20 Feb 2019Érintetti joggyakorlásra vonatkozó kérelem elbírálásaThe supervisory authority fined the controller for failing to facilitate the exercise of data subject rights and for not meeting transparency requirements when handling a deletion request. The case concerned an improperly handled request for erasure and insufficient information provided to the requester.HUNAIHGDPR€1,575
11 May 2021Érintetti jog és tájékoztatási kötelezettség megsértéseThe case concerned unlawful processing of personal data in connection with debt collection. The entity failed to respond to data subject requests and unlawfully transferred personal data.HUNAIHGDPR€1,395
04 Feb 2026E-RETAIL ADVERTISING, S.L.E-RETAIL ADVERTISING, S.L. was fined by the AEPD in the amount of 5,000 EUR for installing non-exempt cookies on its website without prior user consent. The case concerns non-compliance with cookie consent requirements and user privacy obligations.ESAEPDePrivacy€5,000
26 May 2011Eredi Trossello dei Fratelli Trossello C.A.R. s.n.c.The company was fined EUR 10,000 by the Garante for operating a video surveillance system without the required privacy notice. The authority found a breach of Article 13 of the Italian Privacy Code.ITGaranteGDPR€10,000
16 Dec 2010Eraclea Minoa Village s.r.l.Eraclea Minoa Village s.r.l. was fined 6,000 EUR by the Garante for collecting personal data through its website without providing the required privacy notice. The case concerned a breach of Article 13 of the Italian Data Protection Code.ITGaranteGDPR€6,000