Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
08 Dec 2025Anonimizirano (IP-RS 0609-112/2025/7)A legal entity was fined 4,800 EUR by IP-RS for failing to provide concise, transparent, and understandable information to individuals when collecting personal data through online forms. The authority found this to be a breach of Article 13 GDPR.SIIP-RSGDPR€4,800
06 Mar 2014Danilo DiscolpaDanilo Discolpa was fined by the Garante 4,800 EUR for processing personal data through video surveillance and recording customer identification documents without providing the required notice. The authority found this to be a breach of the Italian Privacy Code.ITGaranteGDPR€4,800
25 Jul 2013Axis Strategic Vision srlAxis Strategic Vision srl was fined by the Garante in the amount of 4,800 EUR for providing inadequate privacy notices on its websites. The authority found that the notices did not meet data protection requirements.ITGaranteGDPR€4,800
30 Jan 2014Orovicenza di Picaro CristinaOrovicenza di Picaro Cristina was fined EUR 4,800 by the Garante. The authority found that the website’s contact and registration forms did not provide the required data protection information, in breach of the Italian data protection code.ITGaranteGDPR€4,800
05 Nov 2015Romagna Giochi srlRomagna Giochi srl was fined EUR 4,800 by the Italian Garante. The authority found that the company failed to provide adequate notice about video surveillance at its premises, breaching data protection rules.ITGaranteGDPR€4,800
18 Aug 2022niegoThe Polish DPA (UODO) imposed an administrative fine of PLN 4,569 on an individual. The authority found a failure to cooperate with the President of UODO and a failure to provide access to information necessary for the performance of its duties.PLUODOGDPR€967
23 Dec 2021wyżej wymienionąAn administrative fine was imposed on an individual conducting business activity. The violation consisted of failing to provide the President of the Personal Data Protection Office with access to personal data and information necessary to perform his duties.PLUODOGDPR€983
22 Dec 2021wyżej wymienionąA financial penalty was imposed on an individual conducting business activity for failing to ensure that the President of the Personal Data Protection Office had access to personal data and information necessary to perform his duties. The case concerned obstruction of the supervisory authority’s powers.PLUODOGDPR€982
12 May 2023CHIRURGIEN DENTISTE (procédure simplifiée)The CNIL imposed a fine of EUR 4,500 on CHIRURGIEN DENTISTE and issued an injunction. The case was handled under a simplified procedure.FRCNILGDPR€4,500
12 May 2017RED UNIVERSAL DE MARKETING Y BOOKINGS ONLINE S.A.The entity sent unsolicited commercial emails. It continued sending them despite requests to delete the data, which breached electronic communications rules.ESAEPDePrivacy€4,500
09 Dec 2024SOBLADA RESTAURACIÓN, S.L.SOBLADA RESTAURACIÓN, S.L. was fined by the AEPD EUR 4,500 for installing a video surveillance system without proper signage. The company also failed to inform employees about the system and its purposes, breaching GDPR Articles 5(1)(c) and 13.ESAEPDGDPR€4,500
23 May 2024Azienda Socio-sanitaria Territoriale RhodenseAzienda Socio-sanitaria Territoriale Rhodense was fined EUR 4,500 by the Garante for breaching GDPR Article 16. The case concerned data processing in the health sector, where strict compliance controls are required.ITGaranteGDPR€4,500
13 Sept 2017MASTERZEN, S.L.MASTERZEN, S.L. was fined by the AEPD €4,500 for sending unsolicited marketing emails without the recipient’s consent. The emails were sent despite the recipient’s objection, indicating a breach of rules on direct electronic marketing.ESAEPDePrivacy€4,500
23 Oct 2025Comune di Arcinazzo RomanoThe Garante fined Comune di Arcinazzo Romano 4,500 EUR for unlawfully processing personal data through a video system. The system was used to verify tax compliance for waste disposal, in breach of the principles of lawfulness, fairness, transparency, and purpose limitation.ITGaranteGDPR€4,500
13 Dec 2022Anonymisé (CNPD decision-20-fr-2022)The entity failed to meet GDPR transparency obligations, particularly by not providing information in a clear and accessible manner. CNPD imposed a fine of 4,200 EUR.LUCNPDGDPR€4,200
01 Jan 2014EASY CUT FRANQUICIA, S.L.EASY CUT FRANQUICIA, S.L. was fined by the AEPD 4,100 EUR for sending unsolicited commercial emails. The recipient had previously requested that such communications stop, but the emails continued. This constituted a breach of Article 21.1 of the LSSI.ESAEPDePrivacy€4,100
01 Jan 2016WIZINK BANK S.A.WIZINK BANK S.A. was fined by the AEPD €4,100 for sending unsolicited commercial communications by electronic means. The authority found that the legal requirements for such communications were not met.ESAEPDePrivacy€4,100
20 Sept 2016CEPSA COMERCIAL PETROLEO, S.A.U.CEPSA COMERCIAL PETROLEO, S.A.U. was fined EUR 4,100 by the AEPD for sending commercial emails to a customer after the customer had requested to unsubscribe. The authority found this to be a breach of Article 21.1 of the LSSI.ESAEPDePrivacy€4,100
07 Jul 2016ORANGE ESPAGNE, S.A.U.Orange Espagne, S.A.U. was fined EUR 4,100 by the AEPD for sending unsolicited advertising calls and SMS messages to a customer who had opted out of such contact. The authority found a breach of Article 21.1 of the LSSI.ESAEPDePrivacy€4,100
09 Oct 2025SOCIETE EXERCANT UNE ACTIVITE DE VENTE A DISTANCE SUR CATALOGUE GENERAL (procédure simplifiée)The CNIL imposed an administrative fine of EUR 4,000 on SOCIETE EXERCANT UNE ACTIVITE DE VENTE A DISTANCE SUR CATALOGUE GENERAL. The case was handled under a simplified procedure.FRCNILGDPR€4,000