Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
01 Apr 2019EL GYM IBERIA, S.L.EL GYM IBERIA, S.L. was fined by the AEPD 2,500 EUR for sending unsolicited marketing emails. This occurred despite a prior request to cancel personal data.ESAEPDePrivacy€2,500
21 Feb 2013Elettrodomestici Parise sncElettrodomestici Parise snc was fined 222,000 EUR by the Italian Garante. The company improperly registered numerous phone cards to unaware third parties and then sold them to phone centers, breaching data protection rules.ITGaranteGDPR€222,000
15 Nov 2022Elektronikus direkt marketing hozzájárulás érvényességeThe entity did not provide data subjects with adequate information about the duration of electronic direct marketing (EDM) and did not have valid consent for EDM processing. NAIH found violations of GDPR Articles 6, 7, and 12 and imposed a fine of HUF 2,000,000.HUNAIHGDPR€4,940
07 Jan 2022Elektro & Automasjon Systemer ASElektro & Automasjon Systemer AS was fined NOK 200,000 by Datatilsynet for conducting a credit assessment of an individual without a legal basis. The company checked a co-owner of another company despite having no business relationship or justification for the credit check.NODatatilsynetGDPR€19,942
28 Jun 2021ELEGA ENERGÍA, S.L.ELEGA ENERGÍA, S.L. was fined EUR 2,000 by the AEPD for failing to provide information about cookies and for not obtaining user consent before placing them. The authority found a breach of Article 22.2 of the LSSI.ESAEPDePrivacy€2,000
12 Feb 2021ELECTROTECNIA BASTIDA, S.L.ELECTROTECNIA BASTIDA, S.L. was fined by the AEPD 3,000 EUR for leaving employees’ confidential medical information abandoned in a field. The incident constituted a breach of data protection rules and required supervisory action.ESAEPDGDPR€3,000
01 Jan 2019ELECTRIC RENTING GROUP, S.L.ELECTRIC RENTING GROUP, S.L. was fined by the AEPD EUR 2,500 for sending a promotional email without using BCC. This exposed recipients’ email addresses and breached data protection rules.ESAEPDGDPR€2,500
18 Dec 2024Electrica Furnizare S.A.The National Supervisory Authority for Personal Data Processing completed an investigation in November 2024 at Electrica Furnizare S.A. and found violations of GDPR provisions. As a result, a fine of EUR 3,000 was imposed.ROANSPDCPGDPR€3,000
07 Jun 2023ELECTRAWORKS - CEUTA, S.A.ELECTRAWORKS - CEUTA, S.A. did not comply with a data deletion request and retained personal data for 10 years without proper justification. The AEPD found this to be a breach of Article 13 GDPR and imposed a 10,000 EUR fine.ESAEPDGDPR€10,000
28 May 2015El Dom S.a.s.El Dom S.a.s. was fined EUR 174,000 by the Garante for activating 185 phone cards under the names of 58 individuals without their knowledge. The case involved a breach of data protection rules and the unauthorized use of personal identification data.ITGaranteGDPR€174,000
23 May 2022EL DIARIO DE PRENSA DIGITAL, S.L.EL DIARIO DE PRENSA DIGITAL, S.L. was fined by the AEPD 50,000 EUR for publishing audio of a victim's testimony in a high-profile court case. The authority found a breach of the GDPR data minimization principle.ESAEPDGDPR€50,000
07 Feb 2011EL CORTE INGLES, S.A.EL CORTE INGLES, S.A. was fined 35,000 EUR by the AEPD for sending nine commercial emails without the recipient’s consent. The authority found a breach of Article 21.1 of the LSSI.ESAEPDePrivacy€35,000
01 Jan 2012EL CORTE INGLES, S.A.EL CORTE INGLES, S.A. was fined EUR 1,800 by the AEPD for sending commercial emails without providing a proper means to exercise the right to object. The case concerned non-compliance with the LSSI rules on marketing communications.ESAEPDePrivacy€1,800
03 Jan 2017EL CORTE INGLES, S.A.EL CORTE INGLES, S.A. was fined by the AEPD in the amount of EUR 5,700 for continuing to send marketing emails to a complainant despite requests to stop. The authority found a breach of Article 21.1 of the LSSI.ESAEPDePrivacy€5,700
01 Jan 2014EL CORTE INGLES, S.A.EL CORTE INGLES, S.A. was fined by the AEPD 1,000 EUR for sending unsolicited commercial emails. The conduct breached Article 21.1 of Spain’s LSSI, which restricts marketing communications without recipient consent.ESAEPDePrivacy€1,000
18 Dec 2025Elba Catering Distribuzioni s.r.l.s.Elba Catering Distribuzioni s.r.l.s. was fined EUR 2,000 by the Garante for installing a video surveillance system that primarily captured public streets. The authority found that this processing breached data protection rules.ITGaranteGDPR€2,000
28 Apr 2022Ekss s.r.l.Ekss s.r.l. was fined by the Garante EUR 2,000 for operating a video surveillance system without the required informational signage. The authority found this to be a breach of Article 13 GDPR.ITGaranteGDPR€2,000
10 Oct 2022EKO ABEEThe fine was imposed for a violation of Article 15 GDPR because the controller failed to provide the data subject with access to their personal data. The case concerns non-compliance with the obligation to ensure the right of access within the required scope.GRHDPAGDPR€10,000
22 May 2014Eismann s.r.l.Eismann s.r.l. was fined by the Garante 40,000 EUR for making promotional phone calls without prior express consent from recipients. The company also concealed the caller's identity, which breached Italian data protection rules.ITGaranteGDPR€40,000
05 Jan 2022Egnatia Odos S.A.Egnatia Odos S.A. was fined by the HDPA EUR 1,000 for failing to provide the complainant with access to personal data related to a toll violation. The authority found a breach of the right of access under the GDPR.GRHDPAGDPR€1,000