Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.6%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
21 Apr 2021Ministero dell’Istruzione, dell’Università e della Ricerca, Ufficio Scolastico Regionale per la Toscana, Ufficio VIII Ambito territoriale della provincia di LivornoThe Italian Ministry of Education was fined 3,000 EUR by the Garante. The case concerned personal data of teachers remaining accessible online in breach of GDPR principles of lawfulness, fairness, transparency, and data minimization.ITGaranteGDPR€3,000
12 Feb 2021A*** GmbHA*** GmbH was fined by the Austrian Data Protection Authority for failing to cooperate in three separate complaint procedures. The authority found a breach of Article 31 GDPR, which requires cooperation with the supervisory authority.ATDSBGDPR€3,000
18 Sept 2008Eurolaurea Caserta s.r.l.Eurolaurea Caserta s.r.l. was fined EUR 3,000 by the Garante. The authority found that the company failed to provide data subjects with the information required under Article 13 of the Italian Data Protection Code.ITGaranteGDPR€3,000
01 Jan 2015JYCTEL ESPAÑA SLJYCTEL ESPAÑA SL was fined by the AEPD in the amount of 3,000 EUR for sending unsolicited SMS and WhatsApp messages. The company did not provide information on how to exercise the right to object, which breaches Article 21 of the LSSI.ESAEPDePrivacy€3,000
12 May 2022Zito Auto di Gianfranco ZitoThe company was fined for operating a video surveillance system that did not meet the information requirements under GDPR Article 13 and Article 114 of the Italian Privacy Code. The authority found that the required notices for monitored individuals were not properly provided.ITGaranteGDPR€3,000
16 May 2012CONFORAMA ESPAÑA S.A.CONFORAMA ESPAÑA S.A. was fined by the AEPD in the amount of 3,000 EUR for sending unsolicited advertising SMS messages to customers. The conduct breached Article 21 of the LSSI on marketing communications without prior consent.ESAEPDePrivacy€3,000
16 Nov 2022Raiffeisen Bank SARaiffeisen Bank SA was fined EUR 3,000 by ANSPDCP for GDPR violations related to data security incidents. The case concerned shortcomings in the protection of personal data and the handling of security events.ROANSPDCPGDPR€3,000
18 Jun 2025SOCIETE AYANT POUR ACTIVITE LA VENTE A DISTANCE SUR CATALOGUE GENERAL (procédure simplifiée)The CNIL imposed an administrative fine of 3,000 EUR on SOCIETE AYANT POUR ACTIVITE LA VENTE A DISTANCE SUR CATALOGUE GENERAL. The case was handled under a simplified procedure.FRCNILGDPR€3,000
31 Jan 2023PRESTAMER, S.L.PRESTAMER, S.L. sent an email to 472 recipients without using BCC, which exposed recipients’ personal data. The AEPD imposed a 3,000 EUR fine for breaching data protection rules.ESAEPDGDPR€3,000
16 Dec 2022NORDETIA CLINICS IBERIA, S.L.NORDETIA CLINICS IBERIA, S.L. was fined 3,000 EUR by the AEPD. The authority found that the company obstructed an inspection by failing to provide access required under Article 58(1) GDPR.ESAEPDGDPR€3,000
23 Mar 2023Tehnoplus Industry SRLANSPDCP imposed a fine of EUR 3,000 on Tehnoplus Industry SRL for violating GDPR provisions. The case concerned non-compliance with personal data protection requirements.ROANSPDCPGDPR€3,000
22 Jan 2022SOCIETE D'ENTRETIEN ET DE REPARATION DE VEHICULES AUTOMOBILESCNIL imposed a fine of 3,000 EUR on SOCIETE D'ENTRETIEN ET DE REPARATION DE VEHICULES AUTOMOBILES and issued an injunction under penalty. The case concerns a confirmed compliance breach.FRCNILGDPR€3,000
20 Feb 2021FLEXOGRÁFICA DEL MEDITERRÁNEO, S.L.The company was fined by the AEPD for failing to provide a privacy policy and cookie management on its websites. The authority also found that user consent was collected in a generic manner, which did not meet data protection requirements.ESAEPDGDPR€3,000
16 Sept 2024Vodafone România SAVodafone România SA was fined EUR 3,000 by ANSPDCP. The authority found that the company failed to respond to a request to exercise the GDPR rights of access and erasure.ROANSPDCPGDPR€3,000
12 Jul 2024CLIDEA DESARROLLO, S.A.CLIDEA DESARROLLO, S.A. was fined by the AEPD 3,000 EUR for sending an email to 349 recipients without using the BCC field. This exposed the personal email addresses of all recipients.ESAEPDGDPR€3,000
11 Sept 2025MEDECIN GENERALISTE (procédure simplifiée)CNIL imposed an administrative fine of 3,000 EUR on MEDECIN GENERALISTE and issued an injunction. The case was handled under a simplified procedure.FRCNILGDPR€3,000
24 Jun 2020MIGUEL IBÁÑEZ BEZANILLA S.L.The entity was fined for failing to implement adequate security measures on its website and for providing insufficient privacy policy information. Non-compliance with cookie policy requirements was also identified.ESAEPDGDPR€3,000
06 Mar 2023Integral Collection SRLIntegral Collection SRL was fined EUR 3,000 by ANSPDCP after a ransomware incident. The attack led to unauthorized access and loss of integrity and availability of personal data.ROANSPDCPGDPR€3,000
26 Feb 2024VESTAS CEU ROMÂNIA SRLThe company was fined EUR 3,000 by ANSPDCP for unauthorized disclosure of personal data. The breach included names, place of residence, salary, and CV details.ROANSPDCPGDPR€3,000
13 Feb 2015COMERCIAL POLINDUS, 21, S.L.COMERCIAL POLINDUS, 21, S.L. was fined by the AEPD 3,000 EUR for sending unsolicited commercial communications. The case concerned Article 21 of the LSSI, which prohibits such messages without prior recipient consent.ESAEPDePrivacy€3,000