Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-22.5%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
23 Jan 2024CAJA RURAL DE BURGOS, FUENTEPELAYO, SEGOVIA Y CASTELLDANS, S.C.C.CAJABURGOS was fined by the AEPD for failing to ensure the confidentiality and integrity of personal data. The breach resulted in unauthorized access following a data security incident.ESAEPDGDPR€15,000
24 Jan 2024CAIXA RURAL D'ALGEMESÍ, S.C.V.CCAIXA RURAL D'ALGEMESÍ, S.C.V.C. was fined by the AEPD 15,000 EUR for breaching data protection principles, including confidentiality and integrity. The breach led to unauthorized access to personal data.ESAEPDGDPR€15,000
07 Jul 2025Partidul Alianța pentru Unirea Românilor (AUR)Partidul Alianța pentru Unirea Românilor (AUR) was fined EUR 15,000 by ANSPDCP for violations related to data security breaches. The case concerned reported data security incidents within the political party.ROANSPDCPGDPR€15,000
02 Oct 2025UNIVERSITE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 15,000 on UNIVERSITE (procédure simplifiée). The case concerns a breach of rules supervised by the CNIL.FRCNILGDPR€15,000
20 Oct 2022Policlinico Casilino di RomaPoliclinico Casilino di Roma was fined by the Garante for violations related to the handling of personal data in the healthcare sector. The case concerned improper processing of patient data and privacy compliance requirements.ITGaranteGDPR€15,000
10 Jul 2025Outly di Veneziani & Co s.r.l.The Garante fined Outly di Veneziani & Co s.r.l. EUR 15,000 for insufficient transparency when obtaining consent and for inadequate information on data retention periods. The issues affected all interested parties and potential customers.ITGaranteGDPR€15,000
26 Jan 2023Политическа партия ******The political party unlawfully processed personal data by including individuals in a list supporting its election registration without their consent. The authority found breaches of GDPR Articles 5, 6, and 24.BGCPDPGDPR€7,823
06 Jun 2022Dane anonimowe (C.)UODO imposed an administrative fine of PLN 15,994 on Anonymous Data (C.). The case concerned the failure to report a personal data breach involving the loss of an employee’s employment certificate.PLUODOGDPR€3,491
24 Apr 2013ModenaFiere S.r.l.ModenaFiere S.r.l. was fined EUR 16,000 by the Garante for processing personal data without adequate notice and consent. The violations covered promotional communications, statistical activities, and the dissemination of data on its website and in publications.ITGaranteGDPR€16,000
20 Nov 2014Asl Napoli 2 nordThe Garante imposed a 16,000 EUR fine on Asl Napoli 2 nord for failing to designate data protection officers and for keeping surveillance footage longer than permitted without prior authorization. The case concerned organizational compliance failures and unlawful data retention.ITGaranteGDPR€16,000
26 May 2022Regione ToscanaThe Garante fined Regione Toscana EUR 16,000 for publishing unnecessary personal data on the web. The data were later removed, but the authority still found a sanctionable breach.ITGaranteGDPR€16,000
12 Oct 2016Lorenzo RiccitelliLorenzo Riccitelli was fined 16,000 EUR by the Italian data protection authority, Garante. The case concerned unsolicited emails and SMS messages used for electoral propaganda without the required information or consent from recipients.ITGaranteGDPR€16,000
12 Apr 2018Emanuele CollaEmanuele Colla was fined by the Garante for activating seven phone cards without the consent of the person whose data was used. The case concerns a breach of data protection rules and the unauthorized use of personal data.ITGaranteGDPR€16,000
20 Mar 2014Liguria Radiologia s.r.lLiguria Radiologia s.r.l was fined by the Garante EUR 16,000 for breaching data protection rules. The company improperly communicated patient data to third parties without adequate consent.ITGaranteGDPR€16,000
02 Mar 2017MM Group s.r.l.MM Group s.r.l. was fined EUR 16,000 by the Italian Garante. The case concerned promotional calls made without providing the required data protection information and without obtaining consent, in breach of Articles 13 and 23 of the Italian Data Protection Code.ITGaranteGDPR€16,000
16 Mar 2017Welcome s.a.s. di Somma MicheleWelcome s.a.s. di Somma Michele was fined EUR 16,000 by the Garante for making unsolicited promotional calls. The authority found that the required privacy notice was not provided and consent was not obtained.ITGaranteGDPR€16,000
03 Apr 2014Travelplan Italia s.r.l.Travelplan Italia s.r.l. was fined EUR 16,000 by the Garante for sending unsolicited promotional faxes. The authority found that the company failed to provide the required information notice and did not obtain consent, in breach of the Italian Data Protection Code.ITGaranteGDPR€16,000
15 Jun 2017F2F Communications s.r.l.F2F Communications s.r.l. was fined by the Garante 16,000 EUR for making unsolicited promotional calls. The authority found that the required privacy notice was not provided and consent was not obtained, in breach of data protection rules.ITGaranteGDPR€16,000
21 Feb 2013Stefano Giovanni MaulluStefano Giovanni Maullu was fined by the Garante in the amount of 16,000 EUR for sending unsolicited political SMS messages. The authority also found that the required data protection information was not provided.ITGaranteGDPR€16,000
16 Mar 2017Obiettivo Ferrari s.r.l.Obiettivo Ferrari s.r.l. was fined by the Garante €16,000 for making an unsolicited promotional call. The company did not provide the required data protection information or obtain consent from the recipient.ITGaranteGDPR€16,000