Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
03 Jul 2023ENDESAENDESA was fined by the AEPD EUR 2,500,000 for failing to ensure the integrity and confidentiality of personal data and for inadequate security measures. The authority found breaches of GDPR Articles 5(1)(f) and 32.ESAEPDGDPR€2,500,000
13 Mar 2025Encore Thermoengineering s.r.l.Encore Thermoengineering s.r.l. was fined EUR 20,000 by the Garante. The case concerned an inadequate response to former employees’ requests about the status and deletion of their email accounts, which infringed data protection rights.ITGaranteGDPR€20,000
19 Dec 2024ENCAS ADMINISTRACIONS, S.L.ENCAS ADMINISTRACIONS, S.L. was fined 500 EUR by the AEPD. The case concerned sending emails containing personal data without proper consent, which breached data protection principles.ESAEPDGDPR€500
15 Feb 2022EMPRESA.1The company was fined EUR 300 by the AEPD for improperly orienting surveillance cameras toward public spaces without prior authorization. The conduct breached data protection rules.ESAEPDGDPR€300
26 Oct 2020***EMPRESA.1.The company was fined by the AEPD 10,000 EUR for sending an email containing personal data of a former employee to a third party without authorization. The case involved a breach of data protection principles and unauthorized disclosure of information.ESAEPDGDPR€10,000
07 Sept 2021***EMPRESA.1The entity was fined for failing to display visible signage informing individuals about video surveillance. The authority considered this a breach of Article 13 of the GDPR.ESAEPDGDPR€1,500
17 Jan 2022***EMPRESA.1The entity was fined for improperly orienting surveillance cameras so they captured public pedestrian areas without justification. The authority found this to be a breach of data protection rules.ESAEPDGDPR€1,500
01 Jan 2024EMPRENDEDORES ONLINE, LLCEMPRENDEDORES ONLINE, LLC was fined by the AEPD 10,000 EUR for recording and sharing course participants’ personal data without consent. The authority found a breach of GDPR Articles 5(1)(f) and 6(1), indicating unlawful processing and insufficient legal basis.ESAEPDGDPR€10,000
14 Jun 2018EMMECI LOGISTICA S.r.l.EMMECI LOGISTICA S.r.l. was fined by the Garante 8,000 EUR for violations related to the processing of personal data. The case concerned the use of a geolocation system without the required compliance measures.ITGaranteGDPR€8,000
14 May 2026EmiratesEmirates was fined by the Italian Garante €180,000 for breaching data protection rules. The airline required passengers with reduced mobility to complete a medical form without providing adequate information about how their data would be processed.ITGaranteGDPR€180,000
23 Oct 2025Emera SrlEmera Srl was fined by the Garante EUR 6,000 for sending unsolicited promotional SMS messages despite the recipient's repeated requests for data deletion. The authority also found inadequate data retention and organizational procedures to ensure respect for data subject rights.ITGaranteGDPR€6,000
27 Jun 2023embætti landlæknisThe Icelandic DPA fined embætti landlæknis 12,000,000 ISK for security weaknesses in the Heilsuvera website. The flaw allowed unauthorized access to personal data, indicating a failure to maintain adequate safeguards.ISPersónuverndGDPR€80,640
12 Apr 2018Emanuele CollaEmanuele Colla was fined by the Garante for activating seven phone cards without the consent of the person whose data was used. The case concerns a breach of data protection rules and the unauthorized use of personal data.ITGaranteGDPR€16,000
02 Oct 2025EMAGISTER SERVICIOS DE FORMACIÓN, S.L.EMAGISTER SERVICIOS DE FORMACIÓN, S.L. was fined EUR 80,000 by the AEPD for a data security incident involving unauthorized processes on its web servers. The authority found a breach of data protection principles.ESAEPDGDPR€80,000
20 Apr 2021Elszámoltathatóság elvének megsértéseThe entity was fined by the NAIH for breaching the accountability principle and failing to implement appropriate technical and organizational measures to ensure GDPR compliance. The violations concerned data processing activities related to its websites.HUNAIHGDPR€2,770
01 Jan 2019EL PERIODICO DE CATALUNYA, S.L.EL PERIODICO DE CATALUNYA, S.L. was fined by the AEPD 10,000 EUR for sending a commercial email after a data deletion request. The authority found this conduct to be in breach of Article 6 of the GDPR.ESAEPDGDPR€10,000
08 Mar 2017Elliniki Etaireia Systimikon MeletonThe company was fined by the HDPA for illegally collecting and using personal data for direct marketing purposes. The infringement involved unsolicited electronic communications sent without prior consent from the data subjects.GRHDPAePrivacy€3,000
01 Jan 2023EL LEÓN DE EL ESPAÑOL PUBLICACIONES, S.A.EL ESPAÑOL was fined 10,000 EUR by the AEPD for publishing a private video without the consent of the data subject. The case concerns a breach of data protection rules.ESAEPDGDPR€10,000
01 Apr 2025EL LEÓN DE EL ESPAÑOL PUBLICACIONES, S.A.The AEPD fined EL LEÓN DE EL ESPAÑOL PUBLICACIONES, S.A. 20,000 EUR for publishing unnecessary personal data in a news article. A video in the article revealed the identity of a minor, which was considered disproportionate and unnecessary for the informational purpose.ESAEPDGDPR€20,000
04 Jun 2026ElkjøpThe Norwegian DPA, Datatilsynet, fined Elkjøp 20 million NOK for processing personal data in its customer club without valid consent. The authority found that the practice breached GDPR requirements on lawful processing.NODatatilsynetGDPR€1,844,000