Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
17 Oct 2024Ente di Supporto Tecnico Amministrativo Regionale DirezionaleEnte di Supporto Tecnico Amministrativo Regionale Direzionale was fined 5,000 EUR by the Garante for improper handling of personal data during a public selection process. The issue concerned the transmission of files with incorrect names, even though the content was correct.ITGaranteGDPR€5,000
10 Apr 2025Ente di Patrocinio ed Assistenza per i Cittadini e l’Agricoltura (EPACA)EPACA was fined EUR 5,000 by the Italian Garante. The authority found that the organization retained personal data beyond the legally permitted period and accessed the INPS database without a valid mandate.ITGaranteGDPR€5,000
15 Jul 2013ENTABAN SERVICIOS, S.C.ENTABAN SERVICIOS, S.C. was fined by the AEPD EUR 600 for sending unsolicited commercial emails. The messages did not include a means for recipients to opt out, which breached Article 21.1 of the LSSI.ESAEPDePrivacy€600
04 Dec 2014Enrico TecchioThe Garante fined Enrico Tecchio EUR 2,400 for failing to provide data subjects with information about the processing of personal data through a video surveillance system at a dental practice. The case concerned the duty to inform individuals subject to monitoring.ITGaranteGDPR€2,400
26 Mar 2026Eni S.p.A.Eni S.p.A. was fined 96,000 EUR by the Garante for publishing personal data on its website, including dates of birth and addresses, without proper masking. The authority found this breached GDPR principles of lawfulness, fairness, and transparency.ITGaranteGDPR€96,000
06 Jun 2024Eni Plenitude S.p.A. Società BenefitEni Plenitude S.p.A. was fined by the Garante 6,419,631 EUR for making unsolicited promotional calls without prior consent. The company also used numbers listed in the Public Opposition Register, which constituted a breach of GDPR rules.ITGaranteGDPR€6,419,000
11 Dec 2019Eni Gas e Luce S.p.A.Eni Gas e Luce S.p.A. was fined EUR 8,500,000 by the Garante for making unsolicited telemarketing calls without consent. The conduct also affected individuals who had opted out or were listed in the public opposition register.ITGaranteGDPR€8,500,000
20 Dec 2024English Home SRLEnglish Home SRL was fined EUR 1,000 by ANSPDCP for violating Article 21 of the GDPR. The case concerned failure to respect the data subject’s right to object to processing.ROANSPDCPGDPR€1,000
20 Dec 2024English Home SRLEnglish Home SRL was fined €4,000 by ANSPDCP for violating Article 21 of the GDPR. The case concerned failure to respect the data subject’s right to object to processing.ROANSPDCPGDPR€4,000
27 Nov 2024Engineering Ingegneria Informatica S.p.A.The Garante imposed a fine of EUR 10,000 on Engineering Ingegneria Informatica S.p.A. for a data breach involving the Molise regional health portal. A system vulnerability allowed unauthorized access to personal data.ITGaranteGDPR€10,000
13 Aug 2020Engedményezés után kezelt telefonszám és e-mail címThe case concerned unlawful processing of personal data in connection with debt collection. The controller was fined for breaching the GDPR principles of data minimization and lawful basis.HUNAIHGDPR€5,800
22 Mar 2021Engedményezés utáni követeléskezeléssel kapcsolatos adatkezelés jogalapja, érintetti kérelem teljesítéseThe supervisory authority found a GDPR breach in the processing of personal data for debt collection after assignment of a claim. The controller did not establish a proper legal basis, failed to provide clear information about that basis, and did not properly handle data subject requests.HUNAIHGDPR€13,650
03 Jun 2019Engedély nélkül végzett követelésvásárlási tevékenységgel összefüggő adatkezelésThe authority found that the controller processed personal data without a valid legal basis and for unlawful purposes in connection with unauthorized debt purchasing activities. A fine of HUF 1,000,000 was imposed.HUNAIHGDPR€3,090
23 Jan 2023ENFOKA SISTEMAS GLOBALES, S.L.ENFOKA SISTEMAS GLOBALES, S.L. was fined by the AEPD 30,000 EUR for processing personal data without consent. The company signed an energy supply contract in the complainant's name without their knowledge, which breaches Article 6(1) of the GDPR.ESAEPDGDPR€30,000
12 Feb 2015Enescu Georgiana OfeliaEnescu Georgiana Ofelia was fined 2,400 EUR by the Italian supervisory authority Garante. The case concerned failure to provide data subjects with the required information about video surveillance at the business premises, in breach of Article 13 of the Italian Privacy Code.ITGaranteGDPR€2,400
23 Feb 2024ENERGY WINNER, S.L.ENERGY WINNER, S.L. was fined EUR 600 by the AEPD. The case concerned the failure to provide access to personal data and information requested by the data protection authority, which constitutes a breach of Article 58.1 GDPR.ESAEPDGDPR€600
30 Mar 2026Energy Prices Direct LimitedThe ICO fined Energy Prices Direct Limited, an energy switching services provider, for breaches of the PECR. The company obtained data from public sources and list providers, but failed to screen it against the TPS/CTPS registers before making marketing calls.GBICOePrivacy€184,000
29 Apr 2025Energia Verde S.p.A.Energia Verde S.p.A. was fined EUR 100,000 by the Garante for making unsolicited promotional calls without a legal basis. The authority also found that the company did not adequately respond to data subjects' requests, indicating failures in data protection compliance.ITGaranteGDPR€100,000
14 May 2026Energia Sostenibile S.r.l.Energia Sostenibile S.r.l. was fined EUR 100,000 by the Garante for making unsolicited calls to numbers listed in the Public Opposition Register. The authority also found that the company did not adequately respond to data subjects’ requests to exercise their rights.ITGaranteGDPR€100,000
27 Feb 2025Energia Pulita S.r.l.Energia Pulita S.r.l. was fined EUR 300,000 by the Garante for making unsolicited marketing calls without a valid legal basis. The authority found a breach of GDPR Article 5.ITGaranteGDPR€300,000