Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
07 Feb 2022DESPACHO IBERFORO MADRID SLPDESPACHO IBERFORO MADRID SLP was fined EUR 1,000 by the AEPD for failing to comply with a decision concerning the right to erasure. The authority found a breach of Article 58(2) GDPR.ESAEPDGDPR€1,000
01 Jan 2020DESOLASOL RESTAURACIÓN, S.L.The restaurant disclosed a customer's complaint form to other patrons, breaching data protection principles. The case involved unauthorized disclosure of personal information contained in the complaint document.ESAEPDGDPR€6,000
09 Oct 2015DESIGN MASTER DIMA, S.L.DESIGN MASTER DIMA, S.L. was fined by the AEPD EUR 1,400 for sending unsolicited commercial emails to an individual who had requested that such communications stop. The conduct breached Article 21.1 of the LSSI.ESAEPDePrivacy€1,400
11 Aug 2020DERDIX 5000 SLThe entity published photos of minors in a magazine without obtaining consent, which constitutes a breach of data protection rules. The case concerns the unauthorized disclosure of children’s images and was sanctioned by the AEPD.ESAEPDGDPR€2,000
12 Feb 2026Depurazione Acqua S.r.l.Depurazione Acqua S.r.l. was fined by the Garante for carrying out promotional activities without a valid legal basis. The case concerns GDPR breaches related to data processing and consent.ITGaranteGDPR€15,000
09 Jun 2025Department of Social ProtectionThe Irish DPC imposed a fine of €550,000 on the Department of Social Protection in inquiry IN-21-7-3. The matter is currently pending appeal (TBC).IEDPCGDPR€550,000
16 Jun 2023Department of HealthThe Irish DPC fined Department of Health €22,500 in inquiry IN-21-3-2. The fine has been collected.IEDPCGDPR€22,500
26 Feb 2026Depac Società Cooperativa Sociale a r.l.Depac Società Cooperativa Sociale a r.l. was fined by the Garante EUR 15,000 for unauthorized processing of employees' biometric data. The case concerned the collection and storage of fingerprint data without proper consent or a valid legal basis.ITGaranteGDPR€15,000
31 Jan 2023Dent Estet Clinic SADent Estet Clinic SA was fined by ANSPDCP EUR 1,000 for breaches of the transparency obligations under GDPR Articles 12–14. The case concerned inadequate compliance with information duties toward data subjects.ROANSPDCPGDPR€1,000
31 Jan 2023Dent Estet Clinic SADent Estet Clinic SA was fined EUR 1,000 by ANSPDCP for failing to notify the supervisory authority within 72 hours of becoming aware of a personal data breach. The incident involved unauthorized disclosure of health data, which required prompt reporting under GDPR rules.ROANSPDCPGDPR€1,000
28 Mar 2023DENTAL REY-GAR, S.L.DENTAL REY-GAR, S.L. was fined by the AEPD EUR 1,000 for failing to comply with a resolution concerning the right of access to personal data. The authority found a breach of Article 58(2) of the GDPR.ESAEPDGDPR€1,000
27 Jan 2021Dental Leader S.p.A.Dental Leader S.p.A. was fined EUR 10,000 by the Garante. The authority found that the company required consent to process personal data for promotional purposes in order to complete an online order, even though this was not necessary for contract performance.ITGaranteGDPR€10,000
09 Aug 2022Denmar Nacrut SRLANSPDCP imposed a fine of EUR 1,000 on Denmar Nacrut SRL for violating GDPR provisions. The case concerned non-compliance with personal data protection requirements.ROANSPDCPGDPR€1,000
09 Aug 2022Denmar Nacrut SRLDenmar Nacrut SRL was fined EUR 1,500 by ANSPDCP for violating GDPR provisions. The case concerns non-compliance with personal data protection requirements.ROANSPDCPGDPR€1,500
22 May 2018De Nittis MicheleDe Nittis Michele, a general practitioner, was fined for failing to implement minimum security measures to protect patients' personal and sensitive data. This deficiency allowed unauthorized access to the healthcare system.ITGaranteGDPR€10,000
27 Jan 2021De Nationale Dienst voor Promotie van Kinderartikelen, NVThe company was fined for unlawfully sharing personal data of (expectant) mothers with third parties for direct marketing without valid consent. The authority found breaches of GDPR transparency and information obligations.BEAPDGDPR€50,000
14 Sept 2006De.Mo. s.r.l.De.Mo. s.r.l. was fined 3,000 EUR by the Garante for failing to provide the required information to data subjects under Article 13 of the Italian Data Protection Code. The breach occurred in connection with the company’s marketing activities.ITGaranteGDPR€3,000
21 Mar 2019Demokratikus KoalícióThe Democratic Coalition was fined by NAIH 11,000,000 HUF for failing to meet incident notification and data subject communication obligations. The case involved a data breach affecting high-risk special category data.HUNAIHGDPR€34,980
21 Mar 2019Demokratikus KoalícióDemocratic Coalition was fined HUF 11,000,000 by the NAIH for failing to report a personal data breach. The authority also found that affected individuals were not informed, contrary to GDPR Articles 33 and 34.HUNAIHGDPR€34,980
20 Jan 2023DELSA ALQUILERES, S.L.DELSA ALQUILERES, S.L. installed a surveillance camera covering common areas without a valid legal basis and without adequate informational signage. The AEPD found this to breach GDPR Articles 6 and 13.ESAEPDGDPR€1,000