Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-22.8%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
28 Apr 2022Amiu s.p.a.Amiu s.p.a. was fined EUR 20,000 by the Italian supervisory authority, Garante. The case concerned breaches of lawfulness, fairness, transparency, and purpose limitation in the improper use of surveillance cameras in waste management services.ITGaranteGDPR€20,000
08 Aug 2024SOCIETE DE COURTAGE EN ENERGIE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 20,000 on SOCIETE DE COURTAGE EN ENERGIE and issued an injunction. The case was handled under a simplified procedure.FRCNILGDPR€20,000
08 Dec 2025SOCIETE EXERCANT UNE ACTIVITE DE COMMERCE DE DETAIL (procédure simplifiée)The CNIL imposed an administrative fine of EUR 20,000 on SOCIETE EXERCANT UNE ACTIVITE DE COMMERCE DE DETAIL. The case was handled under a simplified procedure.FRCNILGDPR€20,000
12 Apr 2018Tonino CeciliaTonino Cecilia, owner of Telefonia Trigoria, was fined by the Italian authority Garante. The penalty concerned activating phone cards for two individuals without their consent, which breached data protection rules.ITGaranteGDPR€20,000
12 Dec 2024SOCIETE EDITANT DES LOGICIELS OUTILS DE DEVELOPPEMENT ET DE LANGAGES (procédure simplifiée)The CNIL imposed an administrative fine of EUR 20,000 on SOCIETE EDITANT DES LOGICIELS OUTILS DE DEVELOPPEMENT ET DE LANGAGES and issued an injunction. The case was handled under a simplified procedure.FRCNILGDPR€20,000
15 Feb 2018AUTONOLEGGI 24 S.a.s. DI GIAQUINTO GIOVANNIAUTONOLEGGI 24 S.a.s. was fined by the Garante for processing personal data through a geolocation system without the required notification. The case concerned breaches of notification and supervisory obligations linked to that processing.ITGaranteGDPR€20,000
12 Apr 2018Insurances Global Services S.r.l.Insurances Global Services S.r.l. was fined by the Garante EUR 20,000 for violations involving access to and handling of client data from credit risk databases without proper authorization. The case concerned the unauthorized use of personal data in the context of credit risk assessment.ITGaranteGDPR€20,000
27 Jun 2024METRO AEBEThe supervisory authority found that the company did not properly investigate and notify a personal data breach. It also failed to comply with data subject requests for access and erasure.GRHDPAGDPR€20,000
05 Feb 2026Tensa Art Design S.AThe National Supervisory Authority for Personal Data Processing completed an investigation in January 2026 at Tensa Art Design S.A. It found violations of GDPR provisions and imposed a fine of EUR 20,000.ROANSPDCPGDPR€20,000
30 Jul 2024NUDE PROJECT, S.L.NUDE PROJECT, S.L. was fined EUR 20,000 by the AEPD for sending unsolicited advertising emails to a customer without obtaining explicit consent. The authority found this conduct breached Article 21 of the LSSI.ESAEPDePrivacy€20,000
21 Sept 2017Tra.n.sider S.p.A.Tra.n.sider S.p.A. was fined EUR 20,000 by the Italian Garante. The case concerned the failure to notify the installation of a geolocation system on company vehicles, breaching data protection notification requirements.ITGaranteGDPR€20,000
16 Dec 2009Campolongo Hospital s.p.a.Campolongo Hospital s.p.a. was fined by the Garante in the amount of 20,000 EUR. The case concerned the processing of personal data without the required notification under the Italian Data Protection Code.ITGaranteGDPR€20,000
13 Mar 2025Encore Thermoengineering s.r.l.Encore Thermoengineering s.r.l. was fined EUR 20,000 by the Garante. The case concerned an inadequate response to former employees’ requests about the status and deletion of their email accounts, which infringed data protection rights.ITGaranteGDPR€20,000
10 Jun 2021dott. MariniThe Garante imposed a EUR 20,000 fine on dott. Marini for unlawfully collecting information about patients' HIV status. The authority found a breach of the principles of necessity and proportionality in personal data processing.ITGaranteGDPR€20,000
03 Dec 2024VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD 20,000 EUR for sending commercial electronic communications to a customer who had opted out. The authority also found that there was no effective mechanism to revoke consent.ESAEPDePrivacy€20,000
01 Mar 2023VODAFONE ESPAÑA, S.A.U.Vodafone España was fined by the AEPD in the amount of 20,000 EUR for sending unsolicited commercial communications by text messages and phone calls. The conduct continued despite the recipient’s request to stop contacting them and not to share their phone number for commercial purposes.ESAEPDGDPR€20,000
28 May 2015People & Comunication s.r.l.People & Comunication s.r.l. was fined EUR 20,000 by the Garante. The authority found that the company retained telephone traffic data for more than 24 months, in breach of Article 132 of the Italian Data Protection Code.ITGaranteGDPR€20,000
12 Dec 2024SOCIETE EXPLOITANT DES PORTAILS INTERNET (procédure simplifiée)The CNIL imposed an administrative fine of EUR 20,000 on SOCIETE EXPLOITANT DES PORTAILS INTERNET and issued an injunction. The case was handled under a simplified procedure.FRCNILGDPR€20,000
09 Mar 2021NBQ TECHNOLOGY, S.A.U.NBQ TECHNOLOGY, S.A.U. was fined by the AEPD €20,000 for processing personal data without a legal basis. The case was related to identity theft in a microcredit contract.ESAEPDGDPR€20,000
01 May 2025ALBOR ENERGÍA S.L.ALBOR ENERGÍA S.L. was fined by the AEPD in the amount of 20,000 EUR for a data protection breach. The case concerned unauthorized subcontracting without informing the responsible party, as required by Article 28 of the GDPR.ESAEPDGDPR€20,000