Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
18 Apr 2024DELPASO CAR HIRE, S.L.U.DELPASO CAR HIRE, S.L.U. was fined by the AEPD EUR 2,000 for failing to provide a customer with access to their personal data. The authority found a breach of Article 15 of the GDPR.ESAEPDGDPR€2,000
24 Nov 2022Dello Russo Giulio ditta individualeThe company was fined for using a biometric fingerprint system to record employee attendance without a valid legal basis. The authority found that the processing did not comply with data protection requirements.ITGaranteGDPR€1,000
17 Jan 2025DELIVERY SOLUTIONS S.A.The company was fined for failing to implement adequate technical and organizational measures to ensure a level of security appropriate to the risk. The authority also found insufficient safeguards to ensure data confidentiality.ROANSPDCPGDPR€2,000
31 Aug 2025DELAFRUIT, S.L.DELAFRUIT, S.L. was fined by the AEPD in the amount of 6,000 EUR for installing cameras in a break area without proper notice to affected individuals. The authority treated this as a breach of data protection rules.ESAEPDGDPR€6,000
03 Sept 2020Deichmann Cipőkereskedelmi Korlátolt Felelősségű TársaságThe company failed to respond properly to data subject requests for access and restriction of processing. The authority also found inadequate technical and organizational measures for the processing of CCTV data.HUNAIHGDPR€55,800
01 Jan 2023DEH NOTIFICACION ELECTRONICA HABILITADA S.L.DEH NOTIFICACION ELECTRONICA HABILITADA S.L. was fined by the AEPD €30,000 for sending unencrypted passwords for digital certificates. The authority considered this a potential data security risk. The procedure concerning Article 6(1) GDPR was archived due to no infringement.ESAEPDGDPR€30,000
08 Jun 2020de heer YThe APD Litigation Chamber fined de heer Y 5,000 EUR. It found that personal data from the municipal staff list was processed for election propaganda, breaching the GDPR principles of purpose limitation and lawfulness.BEAPDGDPR€5,000
30 Jan 2021DEGOM, S.A.DEGOM, S.A. was fined EUR 3,000 by the AEPD for failing to display cookie warnings and data protection acceptance checkboxes on its website. The case concerned deficiencies in online transparency and user consent requirements.ESAEPDePrivacy€3,000
26 Feb 2026Dedalus Italia S.p.A.Dedalus Italia S.p.A. was fined EUR 32,000 by the Garante for inadequate security measures that led to a data breach. The company implemented corrective actions promptly, but prior violations were taken into account when setting the penalty.ITGaranteGDPR€32,000
23 Mar 2023Dedalus Italia S.p.a.Dedalus Italia S.p.a. was fined EUR 15,000 by the Garante for failing to implement adequate measures to protect personal data. The authority found a breach of Article 32 GDPR on security of processing.ITGaranteGDPR€15,000
13 Feb 2025D.e.c. soc. coop.The Garante imposed a EUR 20,000 fine on D.e.c. soc. coop. for failing to deactivate an ex-employee's email account after the employment ended. The authority found this conduct breached GDPR principles of fair and transparent processing of personal data.ITGaranteGDPR€20,000
10 Jan 2026DÉCIMAS, S.L.DÉCIMAS, S.L. was fined by the AEPD in the amount of EUR 200,000 for a personal data breach. The incident exposed personal data and breached GDPR Article 5(1)(f).ESAEPDGDPR€200,000
25 Feb 2016Decatel s.r.l.Decatel s.r.l. was fined €10,000 by the Italian Garante. The case concerned the processing and retention of telephone traffic data without the required safeguards, including biometric recognition and strong authentication.ITGaranteGDPR€10,000
09 Mar 2023Deca s.r.l.Deca s.r.l. was fined EUR 1,600 by the Garante. The authority found that the company failed to respond to requests for access to personal data relating to work attendance and unlawfully processed data through an incomplete video surveillance system.ITGaranteGDPR€1,600
23 Jan 2008Deas Desideri e associati s.r.l.Deas Desideri e associati s.r.l. was fined €10,000 by the Garante for failing to notify the processing of sensitive personal data within the required timeframe. The authority found a breach of Article 163 of the Italian Data Protection Code.ITGaranteGDPR€10,000
31 May 2023D.D.D.The entity installed surveillance cameras without authorization, breaching Article 5(1)(c) of the GDPR. The AEPD imposed a fine of EUR 500.ESAEPDGDPR€500
03 May 2024D.D.D.The entity published images of a minor on its Telegram channel without consent, breaching data protection rules. AEPD imposed a fine of EUR 5,000.ESAEPDGDPR€5,000
24 Nov 2022D. B.B.B.The entity was fined EUR 300 by the AEPD for installing surveillance cameras on a building facade facing public areas without prior administrative authorization. The authority found this to be a breach of Article 5(1)(c) GDPR.ESAEPDGDPR€300
01 Jan 2019D. B.B.B.The respondent was fined for publishing intimate photos and conversations of the complainant on WhatsApp without consent. The authority found a breach of data protection rules.ESAEPDGDPR€10,000
01 Jan 2021DAVISER SERVICIOS, S.L.DAVISER SERVICIOS, S.L. was fined by the AEPD 20,000 EUR for using biometric data from fingerprint readers and surveillance cameras without properly informing employees. The authority found this to be a breach of data protection principles.ESAEPDGDPR€20,000