Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
10 Nov 2025Whitedecor SRLThe National Supervisory Authority for Personal Data Processing completed an investigation in October 2025 at Whitedecor SRL and found violations of GDPR provisions. As a result, a fine of 1,000 EUR was imposed.ROANSPDCPGDPR€1,000
06 Aug 2024BEST ELAN ONLINE SRLBEST ELAN ONLINE SRL was fined €1,000 for GDPR violations. The company was also required to provide the ANSPDCP with all requested information and documents.ROANSPDCPGDPR€1,000
24 Apr 2023B.B.B.B.B.B. published the complainant’s image and name on its website without consent. AEPD found this to be a breach of data protection rules and imposed a EUR 1,000 fine.ESAEPDGDPR€1,000
19 Dec 2024Pansiprod Distribuție SRLANSPDCP completed an investigation in November 2024 at Pansiprod Distribuție SRL and found a breach of GDPR provisions. The company was fined EUR 1,000.ROANSPDCPGDPR€1,000
01 Jan 2024MAKING SOLUTIONS, S.L. (MY PERFECT WEDDING)MAKING SOLUTIONS, S.L. (MY PERFECT WEDDING) was fined 1,000 EUR by the AEPD. The authority found a breach of Article 15 GDPR for failing to provide an individual with access to their personal data.ESAEPDGDPR€1,000
20 Jan 2023DELSA ALQUILERES, S.L.DELSA ALQUILERES, S.L. installed a surveillance camera covering common areas without a valid legal basis and without adequate informational signage. The AEPD found this to breach GDPR Articles 6 and 13.ESAEPDGDPR€1,000
17 Mar 2025FEDERACION DE COLUMBICULTURA DE CASTILLA-LA MANCHAThe Federation published a voter list on its website, disclosing members’ personal data without consent. The authority found that adequate security measures were not in place to protect the data.ESAEPDGDPR€1,000
01 Dec 2025Anonimizirano (IP-RS 0609-128/2025/6)A legal entity was fined by IP-RS for failing to implement appropriate technical and organizational measures to secure personal data processing. This failure led to unauthorized access to data stored on a company laptop.SIIP-RSGDPR€1,000
25 Jul 2013Fast-typeThe HDPA imposed a fine of EUR 1,000 on Fast-type for the illegal collection and further processing of personal data. The case concerns a breach of core data processing legality requirements.GRHDPAGDPR€1,000
22 Nov 2021SCF ZHU, S.L.SCF ZHU, S.L. was fined by the AEPD 1,000 EUR for failing to display visible information signs for its video surveillance system and for not maintaining a record of processing activities. The case reflects deficiencies in basic transparency and documentation obligations under data protection rules.ESAEPDGDPR€1,000
01 Jul 2021A.A.A.The entity was fined by the AEPD 1,000 EUR for operating a video surveillance system without proper informational signage and customer information forms. The authority found this to be a breach of Article 13 of the GDPR.ESAEPDGDPR€1,000
24 Jun 2021B.B.B.The entity was fined by the AEPD EUR 1,000 for installing a surveillance camera in a hair salon without informing individuals about the video surveillance area. The authority found this to be a breach of Article 13 of the GDPR.ESAEPDGDPR€1,000
30 Sept 2016UNITECO PROFESIONAL, CORREDURIA DE SEGUROS, S.L.UNITECO PROFESIONAL was fined EUR 1,000 by the AEPD for sending unsolicited commercial emails without providing recipients with an opt-out option. The authority found this to be a breach of Article 21 of the LSSI.ESAEPDePrivacy€1,000
07 Feb 2022DESPACHO IBERFORO MADRID SLPDESPACHO IBERFORO MADRID SLP was fined EUR 1,000 by the AEPD for failing to comply with a decision concerning the right to erasure. The authority found a breach of Article 58(2) GDPR.ESAEPDGDPR€1,000
20 Oct 2023DANTE INTERNAȚIONAL SADANTE INTERNAȚIONAL SA was fined EUR 1,000 by ANSPDCP for processing the complainant's phone number for direct marketing without consent. The case involved sending commercial SMS messages without a valid legal basis.ROANSPDCPGDPR€1,000
12 Feb 2026Provvedimento del 12 febbraio 2026 [10225110]The Garante imposed a EUR 1,000 fine for using a video surveillance system without providing the required information notice to data subjects. The case concerned a breach of GDPR transparency obligations.ITGaranteGDPR€1,000
01 Jan 2021COMUNIDAD.1The entity was fined by the AEPD EUR 1,000 for installing a video surveillance system that captured third parties without adequate data protection measures. The authority found breaches of GDPR Articles 5(1)(c) and 13.ESAEPDGDPR€1,000
17 May 2023M.S.M. Immobiliare s.r.l.M.S.M. Immobiliare s.r.l. was fined €1,000 by the Garante for a video surveillance system that captured areas beyond its property. The authority also found that proper informational signage was missing, in breach of data protection rules.ITGaranteGDPR€1,000
01 Jan 2019MAPEX AGENCIA CONSULTING, S.L.MAPEX AGENCIA CONSULTING, S.L. was fined by the AEPD 1,000 EUR for sending unsolicited emails promoting its services without prior recipient authorization. The conduct breached Article 21.1 of the LSSI on electronic commercial communications.ESAEPDePrivacy€1,000
07 Oct 2019Анонимизирано (CPDP решение-по-жалба-с-рег-№-ппн-01-657-08-0)The Bulgarian data protection authority, CPDP, fined an individual, V.M., BGN 1,000. The sanction concerned failure to provide access to information requested by the authority in connection with a complaint about unlawful dissemination of personal data.BGCPDPGDPR€511