Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.6%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
02 Oct 2020INSTITUTO DEL DAÑO CEREBRAL Y PSÍQUICO, S.L.The entity did not provide timely access to clinical records, which constituted a breach of data protection obligations. Deficiencies were also identified in the website's cookie policy, leading the AEPD to impose a fine.ESAEPDePrivacy€3,000
24 Oct 2023Mensajero SRLMensajero SRL was fined EUR 3,000 by ANSPDCP for a data security breach on its website. A link allowed access to downloadable files containing customer invoices and product warranty certificates.ROANSPDCPGDPR€3,000
09 May 2024Polisportiva Mimmo Ferrito s.r.l.The Garante fined Polisportiva Mimmo Ferrito s.r.l. EUR 3,000 for failing to respond to a data subject's request to exercise their rights. The case concerns non-compliance with data protection obligations.ITGaranteGDPR€3,000
11 Dec 2008Comune di PontenureComune di Pontenure was fined EUR 3,000 by the Garante for failing to provide the required data protection notice when sending a questionnaire about waste management tariffs. The authority found a breach of Article 13 of the Italian Data Protection Code.ITGaranteGDPR€3,000
18 Sept 2008Scip ItaliaScip Italia was fined EUR 3,000 by the Garante for sending unsolicited commercial material by mail. The authority found that the company did not provide the data subject with adequate information required under the Italian Data Protection Code.ITGaranteGDPR€3,000
12 Aug 2025Asociația Casa de Ajutor Reciproc „FLEXICREDIT”In June 2025, ANSPDCP completed an investigation at Asociația Casa de Ajutor Reciproc „FLEXICREDIT” and found violations of GDPR provisions. The entity was fined EUR 3,000.ROANSPDCPGDPR€3,000
08 Aug 2014RANNER ETAIREIA SYLLOGIS KAI DIACHEIRISIS PLIROFORION E.P.E.RANNER ETAIREIA SYLLOGIS KAI DIACHEIRISIS PLIROFORION E.P.E. was fined by the HDPA in the amount of EUR 3,000. The authority found processing of personal data without consent and the sending of unsolicited electronic messages for marketing purposes.GRHDPAGDPR€3,000
23 Jun 2020B.B.B.B.B.B. was fined by the AEPD EUR 3,000 for improperly identifying an individual as the author of a traffic violation. The authority found that this conduct breached GDPR data protection principles.ESAEPDGDPR€3,000
01 Jan 2015LIWE ESPAÑOLA, S.A.LIWE ESPAÑOLA, S.A. was fined by the AEPD EUR 3,000 for sending unsolicited commercial emails despite the recipient’s attempts to unsubscribe. The authority found a breach of Article 21.1 of the LSSI.ESAEPDePrivacy€3,000
01 Jan 2014CTI WEB SERVICIOS INFORMATICOS S.L.CTI WEB SERVICIOS INFORMATICOS S.L. was fined by the AEPD in the amount of 3,000 EUR for sending unsolicited commercial emails. This conduct breached Article 21.1 of the LSSI.ESAEPDePrivacy€3,000
26 May 2022PREICO JURIDICOS, S.L.PREICO JURIDICOS, S.L. was fined by the AEPD 3,000 EUR for failing to respond to information requests linked to a data breach investigation. The authority found a breach of Article 58(1) GDPR.ESAEPDGDPR€3,000
25 Apr 2024ALL IN DIGITAL MARKETING, S.L.ALL IN DIGITAL MARKETING, S.L. was fined by the AEPD EUR 3,000 for sending unsolicited commercial emails without prior consent from recipients. The authority found this conduct to be in breach of Article 21 of the LSSI.ESAEPDePrivacy€3,000
31 Mar 2023LODEJU, S.L.LODEJU, S.L. was fined by the AEPD EUR 3,000 for improperly directing surveillance cameras toward public spaces without authorization. The authority also found inadequate informational signage, in breach of GDPR Articles 5(1)(c) and 13.ESAEPDGDPR€3,000
11 Mar 2022SHOPERY NETWORKS SPAIN, S.L.SHOPERY NETWORKS SPAIN, S.L. was fined 3,000 EUR by the AEPD for a security breach. The authority found a violation of Article 32 GDPR, which requires appropriate technical and organizational measures.ESAEPDGDPR€3,000
12 Jan 2021ASOCIACIÓN CULTURAL ***ASOCIACIÓN.1The association was fined for sharing images of a minor in WeChat groups without parental consent. The authority found a breach of GDPR Article 6(1)(a).ESAEPDGDPR€3,000
22 Sept 2020VENU SANZ CHEF, S.L.VENU SANZ CHEF, S.L. used a client's personal data, including full name, profile photo, and health information, for advertising purposes without consent. The AEPD found this conduct to be a breach of data protection rules.ESAEPDGDPR€3,000
30 Jan 2026un operator persoană fizicăAn individual operator was fined 3,000 EUR for GDPR violations. The case concerned non-compliant processing of personal data and was handled by ANSPDCP.ROANSPDCPGDPR€3,000
01 Mar 2017PACSOLUTOR S.L.U.PACSOLUTOR S.L.U. was fined by the AEPD in the amount of 3,000 EUR for failing to provide adequate information about cookies on its website. The breach concerned Article 22.2 of the LSSI.ESAEPDePrivacy€3,000
09 Jul 2025SC Tremend Software Consulting SRLSC Tremend Software Consulting SRL was fined by ANSPDCP for GDPR violations. The penalty amounted to EUR 3,000.ROANSPDCPGDPR€3,000
01 Jan 2022FEDERACIÓN DE SERVICIOS A LA CIUDADANÍA DE CCOOThe entity was fined by the AEPD €3,000 for breaching data protection principles. The case involved the improper disclosure of personal data related to a COVID-19 case among employees.ESAEPDGDPR€3,000