Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-22.8%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
26 Oct 2017M&M Centro analisi s.r.l.M&M Centro analisi s.r.l. was fined by the Garante 20,000 EUR for failing to notify the processing of sensitive health data. The obligation arose under the Italian Data Protection Code.ITGaranteGDPR€20,000
29 Apr 2025Cooperativa Sociale QuadrifoglioThe Garante imposed a fine of EUR 20,000 on Cooperativa Sociale Quadrifoglio for violations related to data processing. The case concerned non-compliance with personal data protection requirements.ITGaranteGDPR€20,000
18 Feb 2020ZSZZS.440.768.2018StatusuchylonaTytuUODO found a breach related to the processing of children’s biometric data in connection with use of the school canteen. A fine of PLN 20,000 was imposed.PLUODOGDPR€4,679
28 Sept 2023SOCIETE DE FABRICATION DE PRODUITS DE CONSOMMATION COURANTE EN MATIERES PLASTIQUES (procédure simplifiée)The CNIL imposed a fine of EUR 20,000 on SOCIETE DE FABRICATION DE PRODUITS DE CONSOMMATION COURANTE EN MATIERES PLASTIQUES under a simplified procedure. The decision concerns a breach of the rules covered by the administrative proceeding.FRCNILGDPR€20,000
27 Mar 2023QUALITY-PROVIDER S.A.QUALITY-PROVIDER S.A. was fined EUR 20,000 by the Spanish data protection authority, AEPD. The company failed to provide requested information, obstructing the authority’s investigative powers under Article 58(1) GDPR.ESAEPDGDPR€20,000
13 May 2021Synlab Med srlSynlab Med srl was fined EUR 20,000 by the Garante. The authority found that personal data were improperly transmitted to an entity not competent to process them, breaching the principles of data minimization and integrity.ITGaranteGDPR€20,000
24 Jan 2024ACTIVITE DE COMMERCE DE GROS PHARMACEUTIQUES (procédure simplifiée)The CNIL imposed an administrative fine of EUR 20,000 on ACTIVITE DE COMMERCE DE GROS PHARMACEUTIQUES. The case was handled under a simplified procedure.FRCNILGDPR€20,000
08 Oct 2024SEAT, S.A.SEAT, S.A. was fined by the AEPD €20,000 for using cookies on its website without obtaining user consent. The authority found this conduct to be in breach of the LSSI.ESAEPDePrivacy€20,000
11 Dec 2025SOCIETE AYANT POUR ACTIVITE L'ACCOMPAGNEMENT, L'ORIENTATION ET L'EDUCATION DE VICTIMES D'INCESTES (procédure simplifiée)The CNIL imposed an administrative fine of EUR 20,000 on SOCIETE AYANT POUR ACTIVITE L'ACCOMPAGNEMENT, L'ORIENTATION ET L'EDUCATION DE VICTIMES D'INCESTES and issued an injunction. The case was handled under a simplified procedure.FRCNILGDPR€20,000
25 Jan 2024ASSOCIATION A CARACTERE POLITIQUE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 20,000 on ASSOCIATION A CARACTERE POLITIQUE. The case was handled under a simplified procedure.FRCNILGDPR€20,000
21 Apr 2021Isinc S.r.l.s.Isinc S.r.l.s. was fined 20,000 EUR by the Garante for sending promotional emails using personal data taken from public databases without proper consent. The authority found this conduct to be in breach of GDPR Article 5.ITGaranteGDPR€20,000
21 Apr 2011Azienda USL della Valle D'AostaAzienda USL della Valle D'Aosta was fined for processing personal data during phone bookings without providing the required information notice and for failing to update the security program document. The authority found these actions breached data protection rules.ITGaranteGDPR€20,000
23 Jan 2024CAJA RURAL DE NAVARRA, S.C.C.CAJA RURAL DE NAVARRA was fined EUR 20,000 by the AEPD for a personal data breach. The incident compromised the confidentiality and integrity of personal data, breaching Article 5(1)(f) of the GDPR.ESAEPDGDPR€20,000
09 May 2018Amiu S.p.a.Amiu S.p.a. was fined by the Garante 20,000 EUR for improper processing of personal data through its video surveillance systems. The authority found that the company failed to properly designate data processing personnel and to implement adequate data protection measures.ITGaranteGDPR€20,000
31 Jan 2024EDITEUR DE SITE WEB - ACTUALITES DANS LE DOMAINE DES NOUVELLES TECHNOLOGIES (procédure simplifiée)The CNIL imposed an administrative fine of EUR 20,000 on EDITEUR DE SITE WEB - ACTUALITES DANS LE DOMAINE DES NOUVELLES TECHNOLOGIES under a simplified procedure. The case concerned a breach of personal data protection rules.FRCNILGDPR€20,000
01 Jan 2024SUPERVISTA OPTICS SLUSUPERVISTA OPTICS SLU was fined by the AEPD 20,000 EUR for sending commercial electronic communications to a user who had previously opted out. The authority found a breach of Article 21 of the LSSI.ESAEPDePrivacy€20,000
25 Sept 2025S.C. PRIMONET RO S.R.L.The company was fined for a data security breach that enabled unauthorized transactions on affected cards. The incident caused financial losses to the data subjects.ROANSPDCPGDPR€20,000
28 Sept 2023SOCIETE AYANT UNE ACTIVITE DE COMMERCE DE DETAIL OPTIQUE (procédure simplifiée)CNIL imposed a fine of EUR 20,000 on SOCIETE AYANT UNE ACTIVITE DE COMMERCE DE DETAIL OPTIQUE and issued an injunction. The case was handled under a simplified procedure.FRCNILGDPR€20,000
10 Apr 2025SOCIETE DE COMMERCE DE DETAIL D'ARTICLES DE SPORT EN MAGASIN SPECIALISE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 20,000 on SOCIETE DE COMMERCE DE DETAIL D'ARTICLES DE SPORT EN MAGASIN SPECIALISE. The case was handled under a simplified procedure.FRCNILGDPR€20,000
05 Aug 2022Cosmopol Security S.p.A.Cosmopol Security S.p.A. was fined EUR 20,000 by the Garante for failing to respond to a data subject's request to exercise GDPR rights. The case also involved not explaining the origin of the personal data after electronic invoices were received without any contractual relationship.ITGaranteGDPR€20,000