Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
01 Jan 2018CANARY ISLANDS CAR S.L.CANARY ISLANDS CAR S.L. was fined by the AEPD 45,000 EUR for inaccurate processing of personal data. As a result, a traffic violation was incorrectly attributed to a person who had not rented the vehicle.ESAEPDGDPR€45,000
18 Sept 2008Suzuki Italia S.p.A.Suzuki Italia S.p.A. was fined for failing to provide the required privacy notice to individuals whose personal data was obtained from a third party. The breach was found under the Italian Data Protection Code.ITGaranteGDPR€45,000
09 Jan 202420 MINUTOS EDITORA, S.L.20 MINUTOS EDITORA, S.L. was fined 45,000 EUR by the AEPD for publicly exposing the image of a victim of an alleged crime. The authority found that this constituted a breach of data protection rules.ESAEPDGDPR€45,000
18 Jul 2023Comune di ModicaThe Garante fined Comune di Modica EUR 45,000 for inadequate data protection measures linked to video surveillance in public areas. The issues affected a large number of individuals over an extended period, and those recorded were not properly informed.ITGaranteGDPR€45,000
07 May 2015Nappo Nicola JolandaNappo Nicola Jolanda was fined EUR 45,000 by the Garante for activating 37 phone cards in the names of 15 individuals without their knowledge. The conduct breached data protection rules.ITGaranteGDPR€45,000
29 Apr 2021Comune di TriesteComune di Trieste was fined for the unauthorized disclosure of personal data relating to individuals involved in accidents, including names, damage details, and compensation amounts. The data was improperly accessible, constituting a breach of GDPR requirements.ITGaranteGDPR€45,000
10 Apr 2025Stefanelli FedericaThe Garante imposed a 45,000 EUR fine on Stefanelli Federica for processing personal data without proper consent in unauthorized call-center operations. The case also involved sensitive data, including payment method information, which could have led to unauthorized contract activations.ITGaranteGDPR€45,000
04 Jun 2025Noi Compriamo Auto.it S.r.l.The Italian Supervisory Authority fined Noi Compriamo Auto.it S.r.l. 45,000 EUR for sending unsolicited promotional emails without proper consent documentation. The case indicates a breach of GDPR requirements for lawful direct marketing.ITGaranteGDPR€45,000
30 Nov 2022Dane anonimowe (N. B. oraz T. M., wspólników spółki cywilnej Kancelaria)UODO imposed an administrative fine on N. B. and T. M., partners in the civil-law partnership Kancelaria. The authority found that they processed personal data of clients and prospective clients without a legal basis.PLUODOGDPR€9,799
26 May 2022Azienda Sanitaria Locale Roma 1The Garante fined Azienda Sanitaria Locale Roma 1 EUR 46,000 for the unauthorized publication of health-related personal data on its institutional website. The case concerned a breach of data protection rules through the disclosure of sensitive information without a lawful basis.ITGaranteGDPR€46,000
28 Nov 2013Axa società cooperativa a responsabilità limitataAxa società cooperativa a responsabilità limitata was fined by the Garante 46,000 EUR for using biometric systems to monitor employee attendance and working hours. The authority found that the processing took place without proper consent and required notifications, in breach of data protection rules.ITGaranteGDPR€46,000
22 Feb 2018Bar La Piazzetta s.a.s.Bar La Piazzetta s.a.s. was fined EUR 46,000 by the Italian Garante. The authority found that surveillance footage was kept longer than permitted, access was not password-protected, and the required privacy notices were not provided.ITGaranteGDPR€46,000
15 Feb 2018Genova Car Sharing SrlGenova Car Sharing Srl was fined EUR 46,000 by the Garante. The authority found that customers were not fully informed about vehicle geolocation and that separate consent was not obtained for newsletter communications.ITGaranteGDPR€46,000
13 Sept 2012YVES ROCHER ESPAÑA, S.A.YVES ROCHER ESPAÑA, S.A. was fined EUR 47,001 by the AEPD for continuing to send advertising emails to an individual who had requested data deletion and confirmation of that deletion. The authority found that marketing communications continued despite the request.ESAEPDePrivacy€47,001
31 May 2023Dane anonimowe (P. Sp. z o.o. z siedzibą w W. przy ul.)UODO imposed a PLN 47,160 fine on the anonymous company for failing to implement appropriate technical and organizational measures to secure personal data processing in IT systems. The authority also found a lack of regular testing, measuring, and evaluation of the effectiveness of those measures, as well as failure to report the personal data breach without undue delay. In addition, the company did not notify affected individuals without undue delay despite a high risk to their rights and freedoms.PLUODOGDPR€10,395
09 Aug 2018InsingerGilissen Bankiers N.V.Theodoor Gilissen Bankiers N.V. failed to provide a complete overview of personal data processing upon request, which breached data protection rules. Its successor, InsingerGilissen Bankiers N.V., was fined EUR 48,000.NLAPGDPR€48,000
02 Mar 2017Trilogy s.r.l.Trilogy s.r.l. was fined EUR 48,000 by the Garante for making unsolicited marketing calls. The authority found that the company failed to provide the required information and did not obtain consent, in breach of the Italian Data Protection Code.ITGaranteGDPR€48,000
25 Mar 2021Centro diagnostico italiano di MilanoThe Italian Data Protection Authority imposed a fine of EUR 50,000 on Centro diagnostico italiano di Milano. The sanction concerned violations of data protection rules.ITGaranteGDPR€50,000
24 Apr 2025Darian Bishop trading as ECO4UBetween 9 January 2023 and 9 October 2023, 194,110 unsolicited direct marketing calls were made to subscribers registered with the TPS who had not indicated consent to receive such calls. The conduct generated 21 complaints to the Commissioner and the TPS, leading to an ICO fine.GBICOGDPR€58,480
05 Jun 2020EDP Energía, S.A.U.EDP Energía, S.A.U. was fined €50,000 by the AEPD for processing personal data without consent. The authority found this conduct to be in breach of Article 6(1) of the GDPR.ESAEPDGDPR€50,000