Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.6%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
22 Apr 2022Anonymisé (CNPD decision-10-fr-2022)The public transport organization breached GDPR requirements on storage limitation, data minimization, and providing adequate information to data subjects. CNPD imposed a fine of EUR 4,000.LUCNPDGDPR€4,000
10 Mar 2021B.B.B.The entity was fined by the AEPD in the amount of 4,000 EUR for installing a video surveillance system aimed at public areas. The authority also found that images were captured without justified cause and retained longer than permitted by law.ESAEPDGDPR€4,000
12 May 2016Leonardo SestaLeonardo Sesta, a lawyer, was fined by the Italian data protection authority, Garante. The violation concerned transmitting personal data by email instead of registered mail, contrary to data protection rules.ITGaranteGDPR€4,000
22 Jan 2015Provincia di Reggio CalabriaProvincia di Reggio Calabria was fined EUR 4,000 by the Garante. The authority found that personal data had been unlawfully published on its website for longer than the legally permitted fifteen days.ITGaranteGDPR€4,000
03 Jun 2020MALAGATROM, S.L.U.MALAGATROM, S.L.U. was fined by the AEPD 4,000 EUR for processing and disclosing personal data on Amazon without consent. The authority found this conduct to be contrary to Article 6 of the GDPR.ESAEPDGDPR€4,000
13 Jul 2016Italian Lab s.r.l.Italian Lab s.r.l. was fined EUR 4,000 by the Garante. The case concerned the processing of personal data for a mailing list and newsletter without obtaining user consent.ITGaranteGDPR€4,000
22 Nov 2023LOS NIÑOS DE MONTESSORI, S.L.The company was fined by the AEPD for failing to publish a privacy policy on its website and for installing non-exempt cookies without informing users or obtaining consent. The case reflects deficiencies in basic transparency and consent requirements under data protection rules.ESAEPDGDPR€4,000
28 Mar 2019Vestas s.r.l.Vestas s.r.l. was fined by the Garante 4,000 EUR for obtaining a single mandatory consent covering different processing purposes. This approach breached data protection rules because consent was not separated by purpose.ITGaranteGDPR€4,000
03 Sept 2014Anonymised (HDPA 119/2014)A fine was imposed for the unlawful collection and processing of personal data, including email addresses, and for sending unsolicited marketing emails without subscriber consent. The case concerns breaches of lawful processing requirements and the need for prior consent for marketing communications.GRHDPAePrivacy€4,000
02 Jul 2021PODEMOS PARTIDO POLÍTICOPODEMOS PARTIDO POLÍTICO was fined by the AEPD for irregularities in its video surveillance system. The cameras excessively captured public space without justification, and proper signage was missing.ESAEPDGDPR€4,000
23 Oct 2024SNOW INK SIERRA NEVADA, S.L.SNOW INK SIERRA NEVADA, S.L. was fined by the AEPD 4,000 EUR for using surveillance cameras that captured public areas, which breached data protection principles. Privacy masks were implemented during the sanctioning process.ESAEPDGDPR€4,000
01 Feb 2024HOGAR LUZ Y GAS S.L.HOGAR LUZ Y GAS S.L. was fined EUR 4,000 by the Spanish Data Protection Agency (AEPD). The case concerned the failure to provide requested information, which breaches Article 58.1 of the GDPR.ESAEPDGDPR€4,000
20 Jun 2024Provvedimento del 20 giugno 2024 [10037411]The Garante imposed a fine on a healthcare entity for delays in providing preoperative photographs. The delay affected the complainant's legal position in ongoing proceedings.ITGaranteGDPR€4,000
02 Apr 2015Comune di MontefrancoComune di Montefranco was fined EUR 4,000 by the Garante. The authority found that the role of Mercurio service s.r.l. was not properly regulated, although it processed personal data relating to traffic violations without proper authorization.ITGaranteGDPR€4,000
01 Jan 2022FUNDACIÓN CIPRI GÓMESFUNDACIÓN CIPRI GÓMES was fined EUR 4,000 by the AEPD for failing to provide information on personal data processing to athletes or their guardians. The authority also found unlawful processing of a minor's personal data after the parents had withdrawn him from the gym.ESAEPDGDPR€4,000
27 May 2021Società Cavourese S.p.A.Società Cavourese S.p.A. was fined EUR 4,000 by the Italian data protection authority, Garante. The case concerned improper handling of personal data related to employee disciplinary proceedings, in breach of the GDPR and national privacy rules.ITGaranteGDPR€4,000
26 Mar 2015Comune di Santa NinfaComune di Santa Ninfa was fined EUR 4,000 by the Garante for unlawfully publishing personal data on its institutional website. The data remained available for longer than the legally permitted 15 days, constituting a data protection breach.ITGaranteGDPR€4,000
23 Oct 2024ASSOCIATION PARTICIPANT AUX ACTIVITES DES ORGANISATIONS POLITIQUES (procédure simplifiée)CNIL imposed a EUR 4,000 penalty on ASSOCIATION PARTICIPANT AUX ACTIVITES DES ORGANISATIONS POLITIQUES under a simplified procedure. The case concerns liquidation of an astreinte, indicating that a prior obligation was not fulfilled on time.FRCNILGDPR€4,000
30 Jan 2020Liceo Nobel di Torre del GrecoLiceo Nobel di Torre del Greco was fined EUR 4,000 by the Garante for publishing a teacher ranking list on its website. The conduct breached GDPR principles of lawfulness, fairness, transparency, and data minimization.ITGaranteGDPR€4,000
27 Jan 2021Istituto Comprensivo Villanova D’AstiIstituto Comprensivo Villanova D’Asti was fined EUR 4,000 by the Garante for publishing personal data online. The disclosed information could reveal health status and economic-social conditions, breaching data minimization and transparency principles.ITGaranteGDPR€4,000