Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
14 Mar 2013PONTE EN FORMA ONLINE, S.L.PONTE EN FORMA ONLINE, S.L. was fined by the AEPD EUR 50,000 for sending unsolicited commercial email communications. The conduct breached Article 21 of the LSSI, which restricts marketing emails sent without prior consent.ESAEPDePrivacy€50,000
01 Jan 2025PROYECTOS VISUALES ZARAGOZA SLPROYECTOS VISUALES ZARAGOZA SL was fined by the AEPD 50,000 EUR for a personal data breach. The authority found that the company failed to ensure data integrity and confidentiality under Article 5(1)(f) GDPR.ESAEPDGDPR€50,000
24 Mar 2021Ålesund kommuneÅlesund kommune was fined by Datatilsynet for using the Strava app in schools without conducting a risk assessment. As a result, students’ personal data was processed without adequate controls and safeguards.NODatatilsynetGDPR€4,923
22 Feb 2024Trasporto Passeggeri Emilia-Romagna S.p.A.The Garante fined Trasporto Passeggeri Emilia-Romagna S.p.A. 50,000 EUR for improper data processing and a lack of transparency in collecting consent for marketing purposes. The case concerned failures to properly inform data subjects and to meet consent requirements.ITGaranteGDPR€50,000
06 May 2021YThe APD Litigation Chamber imposed a 50,000 EUR fine on Y. The authority found that the privacy policy lacked transparency and breached several GDPR provisions.BEAPDGDPR€50,000
13 Jul 2023EUROPA PRESS DE CATALUNYA, S.A.EUROPA PRESS DE CATALUNYA, S.A. was fined by the AEPD 50,000 EUR for publishing audio of a victim's court statement in a high-profile case. The authority found that the company processed excessive personal data in breach of GDPR Article 5(1)(c).ESAEPDGDPR€50,000
01 Jul 2010TELEFONICA MOVILES ESPAÑA S.A.U.TELEFONICA MOVILES ESPAÑA S.A.U. was fined by the AEPD EUR 50,000 for sending unsolicited SMS advertisements without proper consent. The conduct breached Article 21.2 of the LSSI on electronic marketing communications.ESAEPDePrivacy€50,000
29 Apr 2022RADIO TELEVISION MADRID, S.A.RADIO TELEVISION MADRID, S.A. was fined by the AEPD 50,000 EUR for processing excessive personal data. The case concerned the publication of audio of a victim's court statement in a high-profile case, which breached the data minimization principle.ESAEPDGDPR€50,000
29 Apr 2025Regione LombardiaThe Garante fined Regione Lombardia 50,000 EUR for violations related to the processing of personal data. The authority cited inadequate technical and organizational measures to protect data, as well as improper handling of employee metadata and internet navigation logs.ITGaranteGDPR€50,000
21 Aug 2020ZSOUODO imposed a PLN 50,000 fine on ZSO for breaching personal data protection rules. The case concerned non-compliance with requirements under data protection regulations.PLUODOGDPR€11,369
27 Jan 2021De Nationale Dienst voor Promotie van Kinderartikelen, NVThe company was fined for unlawfully sharing personal data of (expectant) mothers with third parties for direct marketing without valid consent. The authority found breaches of GDPR transparency and information obligations.BEAPDGDPR€50,000
23 Jun 2025Piraeus Bank S.A.Piraeus Bank S.A. was fined by the HDPA 50,000 EUR for unlawfully transferring personal data to third parties without the data subject's consent. The authority found breaches of GDPR principles of lawfulness and accuracy.GRHDPAGDPR€50,000
05 Aug 2020BANKIA, S.A.BANKIA, S.A. was fined by the AEPD 50,000 EUR for retaining a former client’s personal data for more than 16 years without a valid basis. The authority found this to be a breach of data protection principles, especially storage limitation.ESAEPDGDPR€50,000
14 Oct 2022VODAFONE ONO, S.A.U.The AEPD fined VODAFONE ONO, S.A.U. 50,000 EUR for consulting a credit information system without the individual's consent. The company had no contractual relationship with the person, so there was no valid basis for the inquiry.ESAEPDGDPR€50,000
25 May 2022RoulartaThe Belgian data protection authority, APD, sanctioned Roularta in decision 85/2022 of 25 May 2022. The case concerned the placement of non-essential cookies on its press websites without prior user consent. The fine was EUR 50,000.BEAutorité de protection des donnéesGDPR€50,000
24 Oct 2023UNIPREX, S.A.UNIPREX, S.A. was fined 50,000 EUR by the AEPD for processing an excessive amount of personal data. The authority found that the data collected went beyond what was necessary for the intended purpose.ESAEPDGDPR€50,000
29 Nov 2019VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD 50,000 EUR for sending a customer's personal data to the wrong address. The authority found this to be a breach of data security requirements under GDPR Article 5(1)(f).ESAEPDGDPR€50,000
26 Apr 2024SANTANDER CONSUMER, S.A.SANTANDER CONSUMER, S.A. was fined by the AEPD in the amount of 50,000 EUR for sending postal advertising after the complainant had exercised the right to object to processing for marketing purposes. The case concerns failure to respect the data subject’s objection to commercial use of personal data.ESAEPDGDPR€50,000
29 Apr 2022EDITORIAL PRENSA CANARIA, S.A.The company was fined by the AEPD 50,000 EUR for publishing audio of a victim's testimony in a high-profile court case. The authority found a breach of data protection principles.ESAEPDGDPR€50,000
30 Jan 2026deținătorul site-ului evita-teparii.roANSPDCP imposed total fines of 51,000 lei, about 10,000 euro, on the operator, a natural person who runs the site evita-teparii.ro. The case involved multiple GDPR breaches, including the unlawful publication of identity, contact, sensitive, and alleged criminal data without a legal basis.ROANSPDCPGDPR€10,007