Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
01 Jan 2013SEARCH TASK S.L.U.SEARCH TASK S.L.U. was fined EUR 40,000 by the AEPD for sending commercial communications without the required consent. The case concerned a breach of Article 21 of the LSSI and unlawful use of personal data for marketing purposes.ESAEPDePrivacy€40,000
10 Jun 2021Aeroporto Guglielmo Marconi di Bologna S.p.a.Aeroporto Guglielmo Marconi di Bologna S.p.a. was fined by the Garante EUR 40,000 for violations related to the protection of whistleblower identities. The case indicates insufficient personal data safeguards in the handling of reports.ITGaranteGDPR€40,000
17 Dec 2020Miropass S.r.l.Miropass S.r.l. was fined EUR 40,000 by the Italian supervisory authority Garante. The case concerned violations related to data processing activities.ITGaranteGDPR€40,000
18 Oct 2019Dane anonimowe (Burmistrza G. karę pieniężną w kwocie 40.000 zł)UODO found a breach of the principles of lawful processing and confidentiality. A fine of PLN 40,000 was imposed, together with an order to bring processing operations into compliance with data protection rules.PLUODOGDPR€9,336
01 Jan 2022INMOBILIARIA MESLLOC, S.L.INMOBILIARIA MESLLOC, S.L. was fined by the AEPD for unlawfully sharing tenants’ personal data with third-party companies without authorization. The authority found this conduct violated Article 6(1) of the GDPR.ESAEPDGDPR€40,000
21 Mar 2018Ditta individuale Smile di Remmert OriettaThe company was fined for processing the personal data of 36 individuals without consent in connection with training enrollments. It also submitted false documents to the Province of Turin to account for courses that were never conducted.ITGaranteGDPR€40,000
30 Mar 2023Vodafone-PanafonVodafone-Panafon was fined by the HDPA for failing to respond to a data subject access request concerning recorded calls. The authority also found that the company did not notify a personal data breach to the regulator.GRHDPAGDPR€40,000
28 Oct 2015MUTUA MADRILEÑA AUTOMOVILISTA SOCIEDAD DE SEGUROS A PRIMA FIJAMutua Madrileña was fined 40,001 EUR by the AEPD for sending unsolicited commercial emails despite the recipient’s objection. The case concerns a breach of data protection and direct marketing rules.ESAEPDePrivacy€40,001
15 Oct 2025Dane anonimowe (B. Sp. z o.o. z siedzibą w M. za naruszenie przepisu art. 33 ust. 1 rozporządzenia 2016/679)UODO imposed an administrative fine on B. Sp. z o.o. for failing to notify the President of the Personal Data Protection Office of a personal data breach without undue delay and, at the latest, within 72 hours of becoming aware of it. The case concerns the reporting obligation under Article 33(1) GDPR.PLUODOGDPR€9,519
08 Jun 2023RCS Mediagroup S.p.a.RCS Mediagroup S.p.a. was fined EUR 40,660 by the Italian Garante. The case concerned the publication of unauthorized photographs of a private individual taken inside her home, which infringed her privacy rights.ITGaranteGDPR€40,660
16 Jan 2014VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD 41,000 EUR for sending commercial communications by email and SMS without the recipients’ consent. The conduct breached Article 21.1 of the LSSI, which requires prior consent for such messages.ESAEPDePrivacy€41,000
29 Nov 2012Enterprise Work s.r.l.Enterprise Work s.r.l. was fined by the Garante in the amount of 41,600 EUR. The case concerned the sending of unsolicited promotional faxes without valid recipient consent.ITGaranteGDPR€41,600
09 May 2018Telefonika s.r.l.sTelefonika s.r.l.s was fined by the Italian data protection authority, Garante, in the amount of EUR 42,000. The sanction concerned numerous unsolicited promotional phone calls made without proper consent.ITGaranteGDPR€42,000
14 Sept 2023Intesa Sanpaolo S.p.a.Intesa Sanpaolo S.p.a. was fined 42,000 EUR by the Garante for failing to provide timely access to personal data requested by a parent under GDPR Article 15. The authority said the delay resulted from an operational error that prevented timely handling of the request.ITGaranteGDPR€42,000
22 Jan 2015Istituto Nazionale Previdenza SocialeIstituto Nazionale Previdenza Sociale was fined EUR 44,000 by the Garante. The authority found that the required privacy notice was not provided to users, in breach of Article 13 of the Italian Data Protection Code.ITGaranteGDPR€44,000
01 Jan 2012VODAFONE ESPAÑA, S.A.U.Vodafone España, S.A.U. was fined by the AEPD in the amount of EUR 44,001 for sending unsolicited commercial communications to a non-customer. The authority found this conduct to be in breach of Article 21.1 of the LSSI.ESAEPDePrivacy€44,001
07 Jul 2022Senseonics Inc.Senseonics Inc. was fined EUR 45,000 by the Garante for violations related to the processing of personal data. The authority cited issues with data integrity and confidentiality, including health data.ITGaranteGDPR€45,000
12 Mar 2019VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined 45,000 EUR by the AEPD for sending continuous SMS messages to a complainant despite a prior request to cancel personal data. The authority found this conduct to be a breach of data protection principles.ESAEPDGDPR€45,000
11 Feb 2021Istituti ospedalieri bergamaschiThe Garante fined Istituti ospedalieri bergamaschi EUR 45,000 for a data protection breach. Online medical reports were accessible to other patients, exposing sensitive personal data.ITGaranteGDPR€45,000
28 Nov 2017VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined 45,000 EUR by the AEPD for sending commercial emails without providing a valid electronic address for exercising the right to object. The authority found this to be a breach of LSSI rules on commercial communications.ESAEPDePrivacy€45,000