Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-22.8%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
09 Mar 2016PIXMANIA S.A.S.PIXMANIA S.A.S. was fined by the AEPD in the amount of €20,000 for sending unsolicited commercial emails to a user. The company continued sending messages despite multiple unsubscribe requests, which breached the LSSI.ESAEPDePrivacy€20,000
30 Oct 2015VACACIONES EDREAMS SOCIEDAD LIMITADA UNIPERSONALVACACIONES EDREAMS SOCIEDAD LIMITADA UNIPERSONAL was fined by the AEPD 20,000 EUR for sending unsolicited commercial emails. The messages continued despite multiple requests from the recipient to unsubscribe.ESAEPDePrivacy€20,000
09 Jan 2025National Bank of GreeceNational Bank of Greece was fined €20,000 by the HDPA. The authority found that the bank failed to provide data subjects with timely access to their personal data, breaching GDPR Articles 15 and 12.GRHDPAGDPR€20,000
13 Feb 2025D.e.c. soc. coop.The Garante imposed a EUR 20,000 fine on D.e.c. soc. coop. for failing to deactivate an ex-employee's email account after the employment ended. The authority found this conduct breached GDPR principles of fair and transparent processing of personal data.ITGaranteGDPR€20,000
21 Apr 2016Estracom s.p.a.Estracom s.p.a. was fined EUR 20,000 by the Garante for retaining customers’ call data for more than thirty days. The authority found this to be a breach of data protection rules.ITGaranteGDPR€20,000
15 Mar 2018S.P. Selezione Personale s.r.l.S.P. Selezione Personale s.r.l. was fined by the Garante in the amount of EUR 20,000 for violations related to the processing of personal data in head hunting and recruitment activities. The case concerned irregularities in the handling of candidate data.ITGaranteGDPR€20,000
19 Jan 2024GEO ALTERNATIVA, S.L.GEO ALTERNATIVA, S.L. was fined by the AEPD for unlawfully processing personal data. The company included a customer's information in a credit file even though an agreement had already been reached regarding the disputed gas bill.ESAEPDGDPR€20,000
03 Nov 2015VACACIONES EDREAMS SOCIEDAD LIMITADA UNIPERSONALVACACIONES EDREAMS was fined EUR 20,000 by the AEPD for continuing to send newsletters to the complainant despite multiple unsubscribe requests. The authority found this conduct breached Article 21.1 of the LSSI.ESAEPDePrivacy€20,000
03 Sept 2025SOCIETE AYANT POUR ACTIVITE LA PROMOTION IMMOBILIERE DE LOGEMENTS (procédure simplifiée)CNIL imposed an administrative fine of 20,000 EUR on SOCIETE AYANT POUR ACTIVITE LA PROMOTION IMMOBILIERE DE LOGEMENTS. The case was handled under a simplified procedure.FRCNILGDPR€20,000
20 Jul 2017Centro Laser s.r.l.Centro Laser s.r.l. was fined EUR 20,400 by the Garante for using inadequate password procedures and failing to provide required information on data processing to users. The case concerns breaches of data protection rules.ITGaranteGDPR€20,400
21 May 2025Menarini Silicon Biosystems SpAThe Garante imposed a 21,000 EUR fine on Menarini Silicon Biosystems SpA for violations related to personal data processing. The case involved inadequate safeguards in the use of algorithms to identify at-risk patients and online reports accessible to other patients.ITGaranteGDPR€21,000
05 Jan 2021Dane anonimowe (M. Sp. z o.o. z siedzibą w Z. przy)The President of UODO imposed an administrative fine of PLN 21,397 on M. Sp. z o.o. The company failed to cooperate with the authority and did not provide information needed to assess a complaint concerning personal data processing.PLUODOGDPR€4,705
10 Jul 2024Dane anonimowe (Panią A. Z. prowadzącą działalność gospodarczą pod firmą B. z siedzibą w W przy ul.)The President of UODO imposed an administrative fine on an individual conducting business activity. The sanction resulted from failure to cooperate with the authority and from not providing access to personal data and information necessary for supervisory tasks.PLUODOGDPR€5,129
24 Nov 2011Gema s.p.a.Gema s.p.a. was fined by the Italian data protection authority, Garante, for failing to provide the required data protection information to users and entities through its website. The authority also found that the company used a video surveillance system without proper notification, in breach of the Italian Data Protection Code.ITGaranteGDPR€22,000
01 Jan 2025SGKLegalThe Greek data protection authority, ΑΠΔΠΧ, imposed a fine of EUR 22,000 on SGKLegal for a GDPR violation. The case involved recorded conversations and deficiencies in personal data protection compliance.GRΑρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (ΑΠΔΠΧ)GDPR€22,000
11 Apr 2013Travel Factory srl in liquidazioneTravel Factory srl in liquidazione was fined EUR 22,000 by the Garante. The authority found that the company sent promotional faxes and collected data through web forms without providing the required privacy information notice.ITGaranteGDPR€22,000
17 Jul 2024Azienda ULSS n. 14The Garante fined Azienda ULSS n. 14 EUR 22,000 for failing to implement adequate technical and organizational measures to ensure data security. The deficiencies resulted in a data breach involving sensitive health data.ITGaranteGDPR€22,000
21 May 2025NN ΕλληνικήThe Greek Data Protection Authority imposed a €22,000 fine on NN Ελληνική for refusing to provide recorded telephone calls in response to a data subject access request. The case concerns failure to comply with access rights obligations under data protection law.GRΑρχή Προστασίας Δεδομένων Προσωπικού ΧαρακτήραGDPR€22,000
06 Jun 2018Dalmesse Italia s.r.l.Dalmesse Italia s.r.l. was fined €22,000 by the Italian supervisory authority, Garante. The case concerned the processing of personal data, including sensitive health data, without proper compliance with data protection rules.ITGaranteGDPR€22,000
15 Feb 2018Innovastem s.r.l.Innovastem s.r.l. was fined by the Garante for processing personal data without providing the required information notice and for handling health-related data without proper consent. The case indicates breaches of transparency obligations and the rules governing the lawful processing of sensitive data.ITGaranteGDPR€22,400