Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-22.5%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
11 Sept 2014Happy Fit s.r.l.Happy Fit s.r.l. was fined by the Garante in the amount of EUR 16,400 for making an unsolicited promotional phone call. The company did not provide the required information or obtain consent, breaching data protection rules.ITGaranteGDPR€16,400
13 May 2015Barbirato Danilo s.a.s.Barbirato Danilo s.a.s. was fined by the Garante EUR 16,800 for failing to provide the required privacy notice on its website and for improper use of a video surveillance system. The authority cited inadequate CCTV signage and excessive retention of recorded images.ITGaranteGDPR€16,800
24 Jan 2013Saverio ProcopioSaverio Procopio was fined €16,800 by the Garante for sending unsolicited promotional emails without obtaining explicit consent from recipients. The authority also found that the required privacy notice was not provided, in breach of the Italian Data Protection Code.ITGaranteGDPR€16,800
20 Feb 2014Società Editrice Sud s.p.a.Società Editrice Sud s.p.a. was fined by the Garante in the amount of 16,800 EUR for using inadequate information notices on data collection forms. The authority found a breach of Article 13 of the Italian Data Protection Code.ITGaranteGDPR€16,800
13 May 2015Barbirato Danilo s.a.s. di Barbirato Marco e c.Barbirato Danilo s.a.s. was fined by the Garante 16,800 EUR for failing to provide the required privacy notice on its data collection form. The authority also found breaches of CCTV rules, including inadequate signage and excessive retention of recorded images.ITGaranteGDPR€16,800
20 Apr 2017Hotel Savoia Genova s.r.l.Hotel Savoia Genova s.r.l. was fined €16,800 by the Garante. The authority found that the company failed to provide the required information to individuals about its video surveillance system and kept surveillance footage longer than permitted.ITGaranteGDPR€16,800
05 Feb 2026Dane anonimowe (pana H. G., prowadzącego działalność gospodarczą pod firmą H.)The President of the Polish DPA (UODO) imposed a fine of PLN 16,804 on an anonymous sole proprietor. The sanction resulted from failure to cooperate with the authority and from not providing access to personal data and information necessary for the performance of its duties.PLUODOGDPR€3,982
26 Sept 2024Azienda Sanitaria Territoriale di Ascoli PicenoThe Garante fined Azienda Sanitaria Territoriale di Ascoli Piceno EUR 17,000 for failing to implement procedures that would prevent unauthorized linkage between individuals and health departments. The issue could reveal information about a person's health status.ITGaranteGDPR€17,000
12 Jan 2024Alior Bank SA Varșovia Sucursala BucureștiAlior Bank SA, through its Romanian branch, was fined EUR 17,000 by ANSPDCP. The sanction followed an investigation that identified GDPR violations.ROANSPDCPGDPR€17,000
25 Oct 2017TICKETMASTER SPAIN S.A.Ticketmaster Spain S.A. was fined 17,000 EUR by the AEPD for failing to provide adequate information and obtain valid consent for the use of cookies on its website. The authority found that this conduct breached data protection and privacy rules.ESAEPDePrivacy€17,000
29 Jun 2021Anonymisé (CNPD decision-24-fr-2021)The company was fined EUR 17,000 by the CNPD for breaching the data minimization principle and for failing to provide adequate information to data subjects. The deficiencies concerned employees and third parties in relation to processing activities.LUCNPDGDPR€17,000
04 Sept 2025SOCIETE COLLECTANT DES DONNEES DE PROSPECTS A PARTIR DE PLUSIEURS SOURCES, NOTAMMENT DES FORMULAIRES DE PARTICIPATION A DES JEUX CONCOURS EN LIGNE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 17,000 on SOCIETE COLLECTANT DES DONNEES DE PROSPECTS A PARTIR DE PLUSIEURS SOURCES, NOTAMMENT DES FORMULAIRES DE PARTICIPATION A DES JEUX CONCOURS EN LIGNE under the simplified procedure. The case concerned the processing of prospect data collected from multiple sources, including online contest entry forms.FRCNILGDPR€17,000
07 Jul 2022SIA "DEPO DIY"DVI imposed a fine of 17,495 EUR on SIA "DEPO DIY". The decision concerns a breach of obligations and has entered into force.LVDVIGDPR€17,495
01 Aug 2025društvo XThe company failed to implement appropriate organizational and technical security measures, which led to the unauthorized disclosure of personal data of clients involved in credit financing. AZOP imposed a fine of 17,500 EUR.HRAZOPGDPR€17,500
04 Aug 2021Anonymisé (CNPD decision-29-fr-2021)The CNPD found that the organization did not appoint a Data Protection Officer based on the required professional qualities, did not provide the necessary resources, and did not ensure the DPO's autonomy. This constituted breaches of GDPR Articles 37, 38, and 39.LUCNPDGDPR€17,700
20 Jun 2013ASL di SalernoASL di Salerno was fined EUR 18,000 by the Garante for failing to implement minimum security measures. The authority cited, among other issues, the absence of designated data processing managers and the use of common, outdated passwords for electronic systems.ITGaranteGDPR€18,000
08 Nov 2012Enterprise Service s.r.l.Enterprise Service s.r.l. was fined by the Garante for sending unsolicited promotional faxes without prior explicit consent from recipients. The authority also found that the required information notice was not provided, in breach of Article 13 of the Italian Privacy Code.ITGaranteGDPR€18,000
26 Jul 2018Mercati s.p.aMercati s.p.a was fined 18,000 EUR by the Garante for failing to provide adequate information to users about data collection through a reservation form. The authority also found that the company used a video surveillance system without proper notice, in breach of Article 13 of the Italian Privacy Code.ITGaranteGDPR€18,000
24 May 2024G&F&S SECURITY GROUP, S.L.G&F&S SECURITY GROUP, S.L. was fined by the AEPD €18,000 for failing to properly handle a data subject access request. The authority found a breach of Article 15 GDPR and non-compliance with a data protection authority resolution.ESAEPDGDPR€18,000
26 Dec 2024SOCIETE EXPLOITANT DES SUPERMARCHES (procédure simplifiée)The CNIL imposed an administrative fine of EUR 18,000 on SOCIETE EXPLOITANT DES SUPERMARCHES. The case was handled under a simplified procedure.FRCNILGDPR€18,000