Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
13 Jul 2006Ministero dell'istruzione (Ufficio regionale per la Campania)The Campania Regional Office of the Ministry of Education was fined by the Garante for failing to provide requested information and documents. The authority found this to be a breach of data protection rules.ITGaranteGDPR€2,582
29 Apr 2009Altea Servizi s.r.l.Altea Servizi s.r.l. was fined by the Garante 2,580 EUR for sending promotional faxes without obtaining specific and informed consent from consumers. The conduct breached the consumer code and data protection rules.ITGaranteGDPR€2,580
29 Nov 2019GRUPO VALSOR Y LOSAN, S.L.The real estate management company improperly disclosed personal data of third parties during a property purchase process. This constituted a breach of data protection rules and led to a fine imposed by the AEPD.ESAEPDGDPR€2,500
24 Sept 2021B.B.B.The entity was fined for operating a video surveillance system aimed at public and private spaces without sufficient justification. The authority found this to be a breach of data protection rules.ESAEPDGDPR€2,500
01 Jan 2019ELECTRIC RENTING GROUP, S.L.ELECTRIC RENTING GROUP, S.L. was fined by the AEPD EUR 2,500 for sending a promotional email without using BCC. This exposed recipients’ email addresses and breached data protection rules.ESAEPDGDPR€2,500
28 Apr 2022Liceo Statale “Isabella Gonzaga”Liceo Statale “Isabella Gonzaga” was fined by the Garante 2,500 EUR for publishing information on teachers' Law 104 benefits in an electronic register. The register was accessible to other teachers, which breached the GDPR and national privacy code provisions.ITGaranteGDPR€2,500
13 Dec 2022Anonymisé (CNPD decision-18-fr-2022)The company unlawfully transmitted personal data to third parties without prior authorization. The authority also found breaches of GDPR data processing principles and data subject rights.LUCNPDGDPR€2,500
01 Jan 2019VODAFONE ESPAÑA, S.A.UVodafone España, S.A.U was fined by the AEPD in the amount of 2,500 EUR for sending unsolicited advertising messages to a business phone number without consent. The case concerned Article 21 of the LSSI, which governs marketing communications without prior recipient consent.ESAEPDePrivacy€2,500
11 Jan 2023Azienda Sanitaria Locale di BrindisiAzienda Sanitaria Locale di Brindisi was fined by the Garante 2,500 EUR for failing to respond to a data access request. The authority found a breach of GDPR Article 15.ITGaranteGDPR€2,500
27 Feb 2025Comune di SciaccaThe Garante fined Comune di Sciacca EUR 2,500 for violations related to the processing of personal data. The case concerned the communication of data to third parties without a proper legal basis.ITGaranteGDPR€2,500
27 Mar 2025Comune di PolinoComune di Polino was fined by the Garante for breaches of transparency and information obligations in data processing under GDPR Articles 6, 12, 13, and 14. The case concerned insufficient information provided to data subjects about how their personal data was processed.ITGaranteGDPR€2,500
30 Apr 2026BLUE PROJECTS INDUSTRIES S.R.L.ANSPDCP completed an investigation in April 2026 into BLUE PROJECTS INDUSTRIES S.R.L. and found a GDPR violation. A fine of EUR 2,500 was imposed.ROANSPDCPGDPR€2,500
22 Feb 2019VODAFONE ONO, S.A.U.VODAFONE ONO, S.A.U. was fined by the AEPD €2,500 for sending commercial communications by phone and SMS without the complainant’s consent. This breached Article 21 of the LSSI.ESAEPDePrivacy€2,500
13 Apr 2023Suditaly Imprese Meridionali Soc. coop.The Garante imposed a 2,500 EUR fine on Suditaly Imprese Meridionali Soc. coop. for publishing detailed health data without the data subjects' consent. The case concerned Article 9 of the GDPR, which restricts processing of special categories of personal data.ITGaranteGDPR€2,500
01 Mar 2017ESPASA CALPE, S.A.ESPASA CALPE, S.A. was fined EUR 2,500 by the AEPD for continuing to send commercial emails to a customer after confirming deletion of the customer’s personal data. The authority found this to be a breach of electronic communications and data protection rules.ESAEPDePrivacy€2,500
25 Jul 2019CONTAPUBLI RIOJA, S.L. (GESTIRIOJA)CONTAPUBLI RIOJA, S.L. was fined by the AEPD 2,500 EUR for sending unsolicited commercial emails. The conduct continued despite the recipient's objection and request for data deletion.ESAEPDePrivacy€2,500
27 Jun 2023Farmacia Ardealul SRLFarmacia Ardealul SRL was fined by ANSPDCP EUR 2,500 for a data security breach on its website. Unauthorized malware installation led to the compromise of personal data confidentiality, including banking data, of a significant number of clients.ROANSPDCPGDPR€2,500
01 Jan 2017MAS MOVIL TELECOM 3.0 S.A.U. (actualmente XFERA MOVILES, S.A.)The entity was fined by the AEPD in the amount of 2,500 EUR for sending unsolicited marketing messages without providing an opt-out option. This conduct breached article 21.2 of the LSSI, which requires recipients to be able to refuse such communications.ESAEPDePrivacy€2,500
03 Apr 2026BLUE PROJECTS S.R.L.In March 2026, the Romanian supervisory authority ANSPDCP completed an investigation into BLUE PROJECTS S.R.L. and found a GDPR violation. The company was fined EUR 2,500.ROANSPDCPGDPR€2,500
03 Feb 2017CAIXABANK, S.A.CAIXABANK, S.A. was fined by the AEPD EUR 2,500 for sending a customer an unsolicited advertising SMS. The recipient had not consented to receive commercial communications, which breached Article 21.1 of the LSSI.ESAEPDePrivacy€2,500