Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
14 Dec 2010EQUIPAMIENTO INTEGRAL DE OFICINAS S.L.EQUIPAMIENTO INTEGRAL DE OFICINAS S.L. was fined EUR 600 by the AEPD for sending unsolicited commercial emails. The conduct breached Article 21.1 of the LSSI, which prohibits this type of communication without prior consent.ESAEPDePrivacy€600
26 Jul 2017Equilibra s.r.l.Equilibra s.r.l. was fined by the Garante for failing to provide adequate data protection information to individuals and for not appointing the required data processing officers. The case concerned breaches of the Italian Data Protection Code.ITGaranteGDPR€12,400
19 Jan 2021EQUIFAX IBERICA, S.L.EQUIFAX IBERICA, S.L. was fined by the AEPD 50,000 EUR for including personal data in a credit file without a valid debt and without proper notice. The authority found this breached data processing principles.ESAEPDGDPR€50,000
18 Feb 2020Equifax Iberica, S.L.Equifax Iberica, S.L. was fined by the AEPD in the amount of 75,000 EUR for processing personal data without a proper legal basis. The authority cited a breach of Article 6(1)(f) of the GDPR.ESAEPDGDPR€75,000
25 Sept 2025E-Power S.r.l.E-Power S.r.l. was fined EUR 35,000 by the Garante for making promotional calls without a valid legal basis. The authority also found that the company failed to respond to data subject rights requests, which breaches GDPR requirements.ITGaranteGDPR€35,000
03 Feb 2023Epic LtdEpic Ltd was fined by the CyDPC in the amount of 3,250 EUR for making unsolicited calls to former customers without a legal basis. The authority also found insufficient technical and organizational measures to ensure compliant data processing and inadequate data security controls.CYCyDPCGDPR€3,250
11 Jul 2024EOS MatrixAZOP imposed a EUR 5.47 million fine on EOS Matrix for a personal data protection breach following an incident involving the data of 181,641 debtors. The case was described as a GDPR violation and the largest fine in the authority's history.HRAZOPGDPR€5,470,000
09 Oct 2025EON ENERGIE ROMANIA S.A.ANSPDCP completed an investigation at EON ENERGIE ROMANIA S.A. and found a breach of GDPR provisions. As a result, an administrative fine of EUR 25,000 was imposed.ROANSPDCPGDPR€25,000
27 Nov 2024E.ON Energia S.p.A.E.ON Energia S.p.A. was fined EUR 892,738 by the Garante for telemarketing-related violations. The authority cited repeated contact attempts and numerous communications sent without proper consent.ITGaranteGDPR€892,000
25 May 2025ENTIDAD DE CONSERVACION TORREMIRONAThe entity was fined by the AEPD for operating a video surveillance system that excessively covered public areas. This infringed the privacy of residents and passersby.ESAEPDGDPR€5,000
29 Nov 2012Enterprise Work s.r.l.Enterprise Work s.r.l. was fined by the Garante in the amount of 41,600 EUR. The case concerned the sending of unsolicited promotional faxes without valid recipient consent.ITGaranteGDPR€41,600
05 Nov 2015Enterprise Service s.r.l.Enterprise Service s.r.l. was fined EUR 62,000 by the Garante. The sanction concerned sending unsolicited promotional faxes without prior consent, in breach of privacy rules.ITGaranteGDPR€62,000
08 Nov 2012Enterprise Service s.r.l.Enterprise Service s.r.l. was fined by the Garante for sending unsolicited promotional faxes without prior explicit consent from recipients. The authority also found that the required information notice was not provided, in breach of Article 13 of the Italian Privacy Code.ITGaranteGDPR€18,000
29 Sept 2011Enterprise Service s.r.l.Enterprise Service s.r.l. was fined by the Garante for sending unsolicited promotional faxes without prior explicit consent from recipients. The company also failed to provide the required information notice under Article 13 of the Italian Data Protection Code.ITGaranteGDPR€10,000
07 Apr 2011Enterprise Service s.r.l.Enterprise Service s.r.l. was fined EUR 6,000 by the Garante for sending unsolicited promotional faxes without prior explicit consent from recipients. The authority also found that the required privacy notice was not provided, constituting a breach of privacy rules.ITGaranteGDPR€6,000
25 Oct 2012Enterprise Group S.r.l.Enterprise Group S.r.l. was fined EUR 70,000 by the Garante. The case concerned unsolicited promotional communications sent by fax without proper consent, in breach of data protection rules.ITGaranteGDPR€70,000
24 Jun 2010Enterprise Group s.r.l.Enterprise Group s.r.l. was fined EUR 238,000 by the Garante. The authority found that the company failed to provide timely information to data subjects and sent unsolicited marketing communications without prior consent.ITGaranteGDPR€238,000
11 Sept 2025Ente Parco Regionale Migliarino San Rossore MassaciuccoliEnte Parco Regionale Migliarino San Rossore Massaciuccoli was fined EUR 8,000 by the Garante for failing to implement adequate technical and organizational measures. The authority found that more personal data was processed than necessary, in breach of the GDPR and national data protection rules.ITGaranteGDPR€8,000
25 Nov 2015Ente Parco dei NebrodiEnte Parco dei Nebrodi was fined EUR 8,000 by the Garante for processing employees’ biometric data without prior notification. The authority found a breach of Article 37 of the Codice Privacy.ITGaranteGDPR€8,000
23 Mar 2017Ente Nazionale per L’Aviazione Civile (ENAC)ENAC was fined by the Garante in the amount of 10,000 EUR. The authority found that adequate security measures were not implemented, in breach of Articles 33 and 34 of the Italian Data Protection Code.ITGaranteGDPR€10,000