Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
20 Apr 2021EB CREATIVE LABEB CREATIVE LAB was fined by the AEPD EUR 5,000 for failing to provide information or obtain consent for cookies on its website. The breach concerned Article 22.2 of the LSSI.ESAEPDePrivacy€5,000
01 Jan 2016EASYVOYAGE SASEASYVOYAGE SAS was fined by the AEPD in the amount of 20,000 EUR for sending unsolicited commercial emails. The conduct continued despite requests for data cancellation, which breached Article 21.1 of the LSSI.ESAEPDePrivacy€20,000
07 Oct 2010Easynetwork s.r.l.Easynetwork s.r.l. was fined EUR 6,000 by the Italian data protection authority, Garante. The sanction concerned the sending of promotional communications by fax without providing data subjects with the required information. This constituted a breach of Article 13 of the Italian Data Protection Code.ITGaranteGDPR€6,000
09 Mar 2023EASYJET AIRLINE COMPANY LIMITEDEasyJet Airline Company Limited was fined by the AEPD 10,000 EUR for failing to provide timely access to personal data requested by an individual. The authority found a breach of Article 15 GDPR, which governs the right of access.ESAEPDGDPR€10,000
01 Jan 2014EASY CUT FRANQUICIA, S.L.EASY CUT FRANQUICIA, S.L. was fined by the AEPD 4,100 EUR for sending unsolicited commercial emails. The recipient had previously requested that such communications stop, but the emails continued. This constituted a breach of Article 21.1 of the LSSI.ESAEPDePrivacy€4,100
04 May 2017Easy C@ll s.r.l.Easy C@ll s.r.l. was fined EUR 32,000 by the Garante for making unsolicited promotional calls to individuals listed in the public opt-out register. The authority found that the company’s conduct breached data protection rules.ITGaranteGDPR€32,000
24 Jul 2014Easy Call srlEasy Call srl was fined EUR 112,000 by the Garante for making unsolicited promotional calls. The company contacted individuals listed in the opposition register, breaching data protection rules.ITGaranteGDPR€112,000
11 Dec 2015EAE INSTITUCION SUPERIOR DE FORMACION UNIVERSITARIA S.L.EAE INSTITUCION SUPERIOR DE FORMACION UNIVERSITARIA S.L. was fined by the AEPD EUR 3,000 for sending commercial emails without the required consent. The authority found this conduct breached Article 21.2 of the LSSI.ESAEPDePrivacy€3,000
12 May 2021E4LEGAL ANALYTICS, S.L. (EMÉRITA LEGAL)E4LEGAL ANALYTICS, S.L. was fined by the AEPD EUR 3,100,000 for processing personal data from judicial sentences without proper authorization. The case concerned the reuse of data in a way that may have breached data protection rules and restrictions on further use.ESAEPDGDPR€3,100,000
28 Feb 2025DYNAMIC EXPRESS COURIER S.LDYNAMIC EXPRESS COURIER S.L was fined 15,000 EUR by the AEPD for subcontracting without prior authorization and for failing to put proper contracts in place with subcontractors. The authority found this conduct breached GDPR Article 28 on processor arrangements.ESAEPDGDPR€15,000
26 May 2011DVDR.it s.r.l.DVDR.it s.r.l. was fined EUR 7,000 by the Garante. The authority found that the company sent unsolicited commercial emails without consent, in breach of data protection rules.ITGaranteGDPR€7,000
15 Nov 2012Dusty s.r.l.Dusty s.r.l. was fined by the Italian Garante 66,000 EUR for implementing a biometric data collection system for employee attendance without properly appointing data processing officers and without obtaining the required consent. The authority found violations of several provisions of the data protection code.ITGaranteGDPR€66,000
22 May 2025Dumitru Viorel FocșaThe National Supervisory Authority for Personal Data Processing imposed a fine on Dumitru Viorel Focșa for GDPR violations. The case followed a complaint from a data subject.ROANSPDCPGDPR€1,000
02 Jan 2023Dulnevnd fyritøka (Dátueftirlitið)DATFO referred a company to the police for suspected breaches of data protection law. The company collected and stored personal data without a valid legal basis and without providing adequate information to the data subjects. Its website contact mechanism also caused data intended for a specific provider to be collected and retained by the company.FODATFOGDPR€13,446
24 Feb 2014DTS DISTRIBUIDORA DE TELEVISION DIGITAL, S.A.DTS DISTRIBUIDORA DE TELEVISION DIGITAL, S.A. was fined by the AEPD in the amount of EUR 37,000 for continuing to send unsolicited emails to a former customer. The conduct occurred after the customer requested deletion of their data and breached Article 21 of the LSSI.ESAEPDePrivacy€37,000
14 Sept 2023društvo XThe company processed excessive personal data, including CVC/CVV numbers and copies of identity documents, without a legal basis during hotel booking. It also failed to provide transparent information to data subjects, which constitutes a GDPR breach.HRAZOPGDPR€15,000
01 Aug 2025društvo XThe company failed to implement appropriate organizational and technical security measures, which led to the unauthorized disclosure of personal data of clients involved in credit financing. AZOP imposed a fine of 17,500 EUR.HRAZOPGDPR€17,500
15 Feb 2024Dr TelemarketingBetween 11 February 2021 and 24 January 2022, 80,240 connected unsolicited marketing calls were made to subscribers registered with the TPS who had not consented to receive them. Two complaints were received, and the calls related to the Irish Lottery. The company stopped engaging with the Commissioner during the investigation and did not provide a satisfactory explanation for the Lotto Express calls.GBICOGDPR€116,000
01 Oct 2015dr. Ruben Omar UnzurrunzagaDr. Ruben Omar Unzurrunzaga was fined by the Garante for processing clients’ personal data for medical purposes without obtaining documented consent. The authority found a breach of Article 23 of the Italian Data Protection Code.ITGaranteGDPR€10,000
18 Sept 2025Dr.Max SRLIn August of the current year, ANSPDCP completed an investigation at Dr.Max SRL and found a breach of GDPR provisions. As a result, the operator was fined EUR 1,000.ROANSPDCPGDPR€1,000