Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
12 Apr 2021INSTAPACK, S.L.INSTAPACK, S.L. was fined by the AEPD for sending unsolicited SMS messages without valid consent. The authority also found that the company failed to respond to a deletion request, constituting a breach of GDPR Article 6(1)(a).ESAEPDGDPR€3,000
01 May 2025SC Piramida Trade Invest SRLThe Romanian DPA ANSPDCP imposed a total fine of EUR 3,000 on SC Piramida Trade Invest SRL for unlawful audio-video monitoring of employees and inadequate staff information. It also found that the company failed to respond to access, erasure, and objection requests within the legal deadline; a separate email-forwarding issue resulted only in a warning.ROAutoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter PersonalGDPR€3,000
28 Sept 2023Palombaro s.r.l.Palombaro s.r.l. was fined by the Garante in the amount of 3,000 EUR for operating a video surveillance system without adequate informational signage. The authority found a breach of GDPR transparency requirements toward individuals being recorded.ITGaranteGDPR€3,000
30 Sept 2024ASSOCIATION AYANT POUR OBJET LA CREATION D'UN RESEAU DE SANTE PSYCHIATRIQUE (procédure simplifiée)CNIL imposed an administrative fine of EUR 3,000 on ASSOCIATION AYANT POUR OBJET LA CREATION D'UN RESEAU DE SANTE PSYCHIATRIQUE. The case concerns a breach of personal data protection rules under a simplified procedure.FRCNILGDPR€3,000
24 Mar 2022Anonymised (HDPA 17/2022)A fine of EUR 3,000 was imposed for sending unsolicited political communication by SMS without prior consent. The conduct was found to breach Article 11 of Law 3471/2006.GRHDPAePrivacy€3,000
11 Apr 2024Comune di MadignanoThe Garante fined Comune di Madignano EUR 3,000 for unlawfully using surveillance data in a disciplinary proceeding against an employee. The authority found breaches of data protection and transparency principles.ITGaranteGDPR€3,000
29 Jan 2019LOS SEIS MAESTROS S.L.LOS SEIS MAESTROS S.L. was fined by the AEPD EUR 3,000 for processing personal data without consent. The breach involved sending an email offering a discount for an event, contrary to Article 6.1 of the LOPD.ESAEPDePrivacy€3,000
02 Dec 2019IMNOVA RESORT, S.L.IMNOVA RESORT, S.L. was fined by the AEPD EUR 3,000 for installing cookies on its online store without obtaining user consent. The authority found this conduct to be in breach of the LSSI.ESAEPDePrivacy€3,000
01 Apr 2024Your Consulting SRLANSPDCP imposed a fine on Your Consulting SRL for GDPR violations related to insufficient technical and organizational security measures. The security gap allowed unauthorized access to personal data through one of the company’s applications.ROANSPDCPGDPR€3,000
21 Jul 2022Azienda Socio Sanitaria Territoriale RhodenseAzienda Socio Sanitaria Territoriale Rhodense was fined by the Garante EUR 3,000 for violations of data protection rules. The case concerned data breaches and inadequate security measures.ITGaranteGDPR€3,000
06 Apr 2020PETROLIS INDEPENDENTS, S.L.PETROLIS INDEPENDENTS, S.L. was fined by the AEPD in the amount of 3,000 EUR for failing to comply with data protection rules regarding cookie policies on its website. The case concerned information requirements and the compliance of cookie mechanisms with privacy rules.ESAEPDePrivacy€3,000
26 Nov 2020Charly Mike s.r.l.Charly Mike s.r.l. was fined by the Garante EUR 3,000 for improper use of a video surveillance system at Hotel Olimpo. The system was used for continuous monitoring and remote viewing of employees, in breach of data protection rules.ITGaranteGDPR€3,000
03 Nov 2023OTP BANK ROMANIA SAThe National Supervisory Authority for Personal Data Processing imposed a fine of EUR 3,000 on OTP BANK ROMANIA SA for GDPR violations. The case concerned non-compliance with personal data protection requirements.ROANSPDCPGDPR€3,000
13 Apr 2023Comune di Cogollo del CengioThe Garante fined Comune di Cogollo del Cengio EUR 3,000 for breaches of GDPR Articles 5, 6 and 9, as well as Articles 2-ter and 2-septies of the Italian Privacy Code. The case concerned the processing of an employee’s personal data without an adequate legal basis and in breach of data protection rules.ITGaranteGDPR€3,000
14 Sept 2006Pasquadibisceglie PaoloPasquadibisceglie Paolo was fined by the Garante 3,000 EUR for failing to provide adequate information to individuals recorded by a video surveillance system in a commercial establishment. The authority found a breach of privacy rules.ITGaranteGDPR€3,000
15 Sept 2022Comune di ThieneComune di Thiene was fined EUR 3,000 by the Garante for violating data protection principles. The authority found that personal data related to a disciplinary dismissal case was improperly disclosed online.ITGaranteGDPR€3,000
03 Feb 2022FLORAQUEEN FLOWERING THE WORLD S.L.FLORAQUEEN FLOWERING THE WORLD S.L. was fined 3,000 EUR by the AEPD for failing to provide requested information. The case concerned the duty to cooperate with the Spanish data protection authority under GDPR Article 58(1).ESAEPDGDPR€3,000
06 Feb 2025Omniasig Vienna Insurance Group S.A.A fine of 3,000 EUR was imposed for unauthorized access to personal data of a significant number of data subjects over a defined period. The case concerns a data security breach requiring appropriate access controls and protective measures.ROANSPDCPGDPR€3,000
01 Oct 2020Megareduceri TV S.R.L.Megareduceri TV S.R.L. was fined EUR 3,000 by ANSPDCP for violating GDPR provisions. The case concerned non-compliance with certain personal data protection obligations.ROANSPDCPGDPR€3,000
09 May 2024Caffetteria 77 di Dughetti BarbaraThe Garante fined Caffetteria 77 di Dughetti Barbara EUR 3,000 for operating a video surveillance system without meeting the legal requirements. The system captured both customers and employees, creating a data protection compliance breach.ITGaranteGDPR€3,000