Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
04 Oct 2024DIAMOND FERVA, S.L.DIAMOND FERVA, S.L. was fined by the AEPD 1,000 EUR for installing a surveillance camera without properly informing data subjects and without the required authorization. The authority treated this as a breach of the information obligations under GDPR Article 13.ESAEPDGDPR€1,000
19 Nov 2024CLUB ESPORTIU VILA OLÍMPICAThe club pressured a parent to obtain consent for collecting images of a minor child. AEPD found this to be a breach of data protection rules.ESAEPDGDPR€1,000
28 Mar 2023DENTAL REY-GAR, S.L.DENTAL REY-GAR, S.L. was fined by the AEPD EUR 1,000 for failing to comply with a resolution concerning the right of access to personal data. The authority found a breach of Article 58(2) of the GDPR.ESAEPDGDPR€1,000
24 Nov 2022Dello Russo Giulio ditta individualeThe company was fined for using a biometric fingerprint system to record employee attendance without a valid legal basis. The authority found that the processing did not comply with data protection requirements.ITGaranteGDPR€1,000
09 Sept 2021B.B.B.B.B.B. was fined by the AEPD for installing a CCTV system in a café that recorded public areas without proper signage. The authority found this to be a breach of data protection rules.ESAEPDGDPR€1,000
29 Apr 2021LA ROCA NETWORKS, S.L.LA ROCA NETWORKS, S.L. was fined by the AEPD €1,000 for sending commercial emails to an individual whose email address was included in the Robinson List. The conduct breached Spanish data protection rules governing unsolicited marketing communications.ESAEPDePrivacy€1,000
01 Jan 2023PUNTO ROJO LIBROS, S.L.PUNTO ROJO LIBROS, S.L. was fined by the AEPD 1,000 EUR for failing to adequately respond to a data subject’s request for information about the origin of their personal data. The authority treated this as a breach of GDPR obligations.ESAEPDGDPR€1,000
01 Feb 2023Tensa Art Design SAANSPDCP completed an investigation in January 2023 at Tensa Art Design SA and found violations of GDPR provisions. As a result, the company was fined EUR 1,000.ROANSPDCPGDPR€1,000
03 Aug 2016WOLTERS KLUWER ESPAÑA, S.A.WOLTERS KLUWER ESPAÑA, S.A. was fined by the AEPD EUR 1,000 for sending unsolicited commercial emails to a complainant after confirming the cancellation of their data. The authority found this conduct breached Article 21.1 of the LSSI.ESAEPDePrivacy€1,000
03 Feb 2026Partidul Alianța pentru Unirea Românilor (AUR)The National Supervisory Authority for Personal Data Processing imposed a fine on the political party AUR for GDPR violations. The case concerned non-compliance with personal data protection requirements.ROANSPDCPGDPR€1,000
03 Feb 2022DOOR2DOOR SPAIN, S.L.DOOR2DOOR SPAIN, S.L. did not comply with a decision of the Spanish Data Protection Agency (AEPD) requiring measures to inform individuals whose personal data were collected. The authority treated this as a breach of Article 58(2) GDPR and imposed a fine of EUR 1,000.ESAEPDGDPR€1,000
14 Nov 2014TELEFÓNICA MÓVILES ESPAÑA S.A.U.TELEFÓNICA MÓVILES ESPAÑA S.A.U. was fined by the AEPD 1,000 EUR for sending unsolicited commercial SMS messages to a customer. The recipient had previously requested to opt out of such communications, but the messages continued.ESAEPDePrivacy€1,000
08 Jul 2021Consiglio Regionale della Valle d’AostaConsiglio Regionale della Valle d’Aosta was fined EUR 1,000 by the Garante for failing to remove personal data from its website after a request. The authority found this to be a breach of data protection rights.ITGaranteGDPR€1,000
12 May 2022Minimarket di Alam SaifulThe Garante fined Minimarket di Alam Saiful 1,000 EUR for operating a video surveillance system without the required notice to individuals being recorded. The case concerned a breach of data protection information obligations.ITGaranteGDPR€1,000
24 Jun 2021Comune di FiscianoComune di Fisciano was fined EUR 1,000 by the Garante for improper handling of personal data. The data were removed after the complaint, and the case concerned transparency and data protection obligations.ITGaranteGDPR€1,000
09 May 2024HEADBLUE MARKETING, S.L.HEADBLUE MARKETING, S.L. was fined by the AEPD in the amount of 1,000 EUR for sending unsolicited commercial electronic communications without consent. The authority also found a failure to respond to access requests.ESAEPDePrivacy€1,000
19 Jun 2025SC Diamir SRLIn May 2025, ANSPDCP completed an investigation at SC Diamir SRL and found violations of GDPR provisions. The company received a warning and a fine of EUR 1,000.ROANSPDCPGDPR€1,000
01 Jan 2017NIUNO ESTÉTICA, S.L.NIUNO ESTÉTICA, S.L. was fined by the AEPD 1,000 EUR for sending unsolicited commercial SMS messages. The conduct breached the requirements of Spain’s LSSI governing marketing communications.ESAEPDePrivacy€1,000
07 Apr 2021IMPORTACIONES CRBD, S.L.The entity was fined for sending commercial emails without the recipient's consent, in breach of Article 21 of the LSSI. The case concerns unauthorized direct electronic marketing.ESAEPDePrivacy€1,000
23 Apr 2021B.B.B.The entity was fined for operating a video surveillance system at the workplace without informing employees through the required informational signage. The authority found this to be a breach of Article 13 GDPR.ESAEPDGDPR€1,000