Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
10 Jun 2011Azienda mobilità trasporti di Bari s.p.a.Azienda mobilità trasporti di Bari s.p.a. was fined by the Garante for processing employees' biometric data without proper notice, consent, or adequate information. The authority found violations of several provisions of the Italian data protection code.ITGaranteGDPR€34,000
02 Dec 2015A.M.A.M. Azienda Meridionale Acque Messina s.p.a.A.M.A.M. Azienda Meridionale Acque Messina s.p.a. was fined by the Garante for processing employees' biometric data without notification and without requesting prior verification. The authority found that the company breached data protection rules.ITGaranteGDPR€34,000
06 Sept 2012Azienda sanitaria provinciale di EnnaAzienda sanitaria provinciale di Enna was fined 34,000 EUR by the Garante. The authority found a breach of notification obligations under data protection rules.ITGaranteGDPR€34,000
29 Apr 2026Pianeta s.r.l.Pianeta s.r.l. was fined by the Garante 34,000 EUR for unlawfully processing personal data linked to a loyalty card program. The data were used to initiate disciplinary action against an employee, which breached GDPR requirements.ITGaranteGDPR€34,000
01 Jan 2012LET’s BONUS, S.L.LET’s BONUS, S.L. was fined EUR 34,001 by the AEPD for sending unsolicited commercial emails to a user. The conduct continued despite multiple requests to stop, which breached Article 21 of the LSSI.ESAEPDePrivacy€34,001
07 Feb 2011EL CORTE INGLES, S.A.EL CORTE INGLES, S.A. was fined 35,000 EUR by the AEPD for sending nine commercial emails without the recipient’s consent. The authority found a breach of Article 21.1 of the LSSI.ESAEPDePrivacy€35,000
22 Jul 2021Azienda sanitaria locale di BariAzienda sanitaria locale di Bari was fined EUR 35,000 by the Garante for failing to adopt minimum security measures. The breach resulted in exposure of health data, creating a significant compliance and privacy risk.ITGaranteGDPR€35,000
09 Apr 2021Miljø- og Kvalitetsledelse ASMiljø- og Kvalitetsledelse AS was fined 35,000 NOK by Datatilsynet for unlawfully sending personal data from camera recordings to an employer without a legal basis. The authority cited breaches of GDPR Articles 6 and 5.NODatatilsynetGDPR€3,461
30 Nov 2023SzkołęUODO imposed an administrative fine of PLN 35,000 on Szkołę. The authority found that the company had not implemented appropriate technical and organizational measures to secure personal data processed in the application. It also noted the absence of regular testing, measurement, and assessment of the effectiveness of those safeguards.PLUODOGDPR€8,048
03 Dec 2019Nusvar ABNusvar AB was fined SEK 35,000 by IMY. The authority found unauthorized processing of personal data relating to criminal offenses and a failure to comply with data minimization principles in credit reporting activities.SEIMYGDPR€3,313
23 Jan 2024CAIXA POPULAR - CAIXA RURAL SOC. COOP. DE CRÉDITO VCAIXA POPULAR was fined EUR 35,000 by the AEPD for a personal data breach. The incident allowed unauthorized third-party access and affected the confidentiality and integrity of the data.ESAEPDGDPR€35,000
21 May 2015BONANZA DIGITAL SERVICES, S.L.BONANZA DIGITAL SERVICES, S.L. was fined EUR 35,000 by the AEPD for sending 20 unsolicited advertising SMS messages without prior consent. The company also failed to provide an opt-out mechanism, breaching the LSSI.ESAEPDePrivacy€35,000
12 Sept 2025A Düsseldorf-based personnel recruitment companyOn 2025-09-12, the LDI NRW announced a data protection fine of over 35,000 EUR against a Düsseldorf-based personnel recruitment company. The authority said the company repeatedly ignored job seekers’ requests for access and deletion and failed to respond to the supervisory authority’s inquiries.DELandesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-WestfalenGDPR€35,000
18 Mar 2025ALVEA SOLUCIONES TECNOLÓGICAS, S.L.ALVEA Soluciones Tecnológicas, S.L. was fined 35,000 EUR by the AEPD for improper handling of personal data. The authority cited sharing data without consent and failing to comply with data retention policies.ESAEPDGDPR€35,000
29 Oct 2013ESPASA CALPE, S.A.ESPASA CALPE, S.A. was fined EUR 35,000 by the AEPD for sending unsolicited commercial emails. The conduct breached Article 21 of the LSSI despite prior requests to be removed from the mailing list.ESAEPDePrivacy€35,000
25 Sept 2025E-Power S.r.l.E-Power S.r.l. was fined EUR 35,000 by the Garante for making promotional calls without a valid legal basis. The authority also found that the company failed to respond to data subject rights requests, which breaches GDPR requirements.ITGaranteGDPR€35,000
27 May 2019VODAFONE ESPAÑA, S.A.U.Vodafone España, S.A.U. was fined 35,000 EUR by the AEPD for processing personal data without consent. The case involved charging a former customer for services not contracted due to a technical error.ESAEPDGDPR€35,000
13 Feb 2026Dane anonimowe (Komitet Wyborczy Kandydata na Prezydenta Rzeczypospolitej Polskiej M. W.)UODO imposed a fine of 35,582 PLN on the Election Committee of Presidential Candidate M. W. The authority found that campaign activities infringed the privacy of other individuals by using their personal data. The right to present truthful information about a candidate does not justify such processing.PLUODOGDPR€8,442
24 Jul 2014Future srlFuture srl was fined EUR 36,000 by the Garante for making unsolicited promotional phone calls without proper consent. The authority found that the company’s conduct breached data protection rules.ITGaranteGDPR€36,000
10 Apr 2019Anonymizováno (ÚOOÚ UOOU-06298/18-38)The entity was fined for repeatedly sending commercial communications without recipients’ consent. This breached § 7(2) of the Czech Act on Certain Information Society Services.CZUOOUePrivacy€1,406