Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
15 Feb 2021ANYTIME FITNESS IBERIA, S.L.ANYTIME FITNESS IBERIA, S.L. was fined by the AEPD 15,000 EUR for failing to delete personal data after a request and for sending promotional SMS messages without consent. The case concerns non-compliance with data subject rights and rules on direct marketing.ESAEPDePrivacy€15,000
30 Jun 2020AOK Baden-WürttembergThe Baden-Württemberg data protection authority fined AOK Baden-Württemberg EUR 1.24 million on 2020-06-30. It found that personal data from more than 500 contest participants was processed for advertising purposes without valid consent, and that the technical and organizational measures required under Article 32 GDPR were insufficient.DELandesbeauftragter für den Datenschutz und die Informationsfreiheit Baden-WürttembergGDPR€1,240,000
04 Jan 2023Apă Canal Ilfov SAThe company was fined EUR 3,000 by ANSPDCP for a data security breach. User information was exposed because email addresses were entered in the “To” field instead of “BCC”.ROANSPDCPGDPR€3,000
11 Aug 2025APARELLS ORTOPEDICS CURTO, S.L.APARELLS ORTOPEDICS CURTO, S.L. did not provide complete personal data and medical records in response to an access request. The AEPD found this to be a breach of data protection rules and imposed a fine of 10,000 EUR.ESAEPDGDPR€10,000
11 Jun 2024APARTAMENTOS BUENAVISTA HOMEAPARTAMENTOS BUENAVISTA HOME was fined EUR 1,000 by the AEPD for requesting guests to submit electronic images of their ID documents. The authority found that this practice breached the GDPR data minimization principle.ESAEPDGDPR€1,000
05 Mar 2021APARTAMENTOS PLAYA DE COVACHOS, S.L.The company was fined by the AEPD in the amount of 1,000 EUR for operating video surveillance without the required information for recorded individuals. It did not identify the data controller, explain how rights could be exercised, or state the purpose of the surveillance, which breaches Article 13 GDPR.ESAEPDGDPR€1,000
17 Mar 2016Apcoa Parking Italia spaApcoa Parking Italia spa was fined EUR 4,800 by the Garante for improper use of surveillance images to enforce parking rules and recover debts. The authority also found inadequate data protection information on the company’s website and in its communications with data subjects.ITGaranteGDPR€4,800
29 Aug 2024Apohem, gällande Meta-pixelApohem AB was fined by IMY 8,000,000 SEK for failing to implement appropriate technical and organizational measures to ensure an adequate level of security for personal data when using the Meta-pixel analytics tool. The authority found a breach of Article 32 GDPR.SEIMYGDPR€705,000
31 Mar 2023APOLLONIA TOPCO, S.L.APOLLONIA TOPCO, S.L. was fined by the AEPD EUR 30,000 for improperly requesting copies of clients’ ID documents. The authority also noted a failure to respond to a data protection complaint, in breach of data minimization and purpose limitation principles.ESAEPDGDPR€30,000
29 Aug 2024Apoteket AB, gällande Meta-pixelApoteket AB was fined by IMY for failing to implement appropriate technical and organizational measures to ensure an adequate level of security for personal data when using the Meta-pixel tool. The authority found a breach of Article 32 GDPR.SEIMYGDPR€3,261,000
15 Feb 2018APS Holding S.p.a.APS Holding S.p.a. was fined by the Garante 40,000 EUR for failing to properly notify the data processing activities linked to the geolocation of vehicles used in its car sharing service. The authority found that the notification obligations under the Italian data protection code were not met.ITGaranteGDPR€40,000
01 Jan 2014ARABBESKO MADRILEÑA, S.L.ARABBESKO MADRILEÑA, S.L. was fined by the AEPD EUR 1,200 for sending unsolicited SMS advertising to a user registered on the Robinson List. The authority found a breach of Article 21 of the LSSI.ESAEPDePrivacy€1,200
22 Jun 2020ARANOW PACKAGING MACHINERY, S.L.ARANOW PACKAGING MACHINERY, S.L. was fined by the AEPD for non-compliance of its website with data protection rules. The breach concerned the absence of compliant Privacy and Cookie Policies.ESAEPDePrivacy€3,000
18 Mar 2024Arbeids- og velferdsetaten (NAV)On 18.03.2024, Datatilsynet imposed a NOK 20 million administrative fine and additional orders on Arbeids- og velferdsetaten (NAV). The case concerned inadequate protection of confidentiality through access control and log monitoring, with several serious compliance deficiencies identified.NODatatilsynetGDPR€1,730,000
18 Mar 2024Arbeids- og velferdsetaten (NAV)The Norwegian DPA, Datatilsynet, fined NAV 20,000,000 NOK for inadequate confidentiality safeguards in access control and logging. The authority identified structural and organizational weaknesses in the protection of personal data.NODatatilsynetGDPR€1,730,000
28 Nov 2023Arbeids- og velferdsetaten (NAV)The Norwegian DPA has notified NAV of a planned 20 million NOK fine for serious information security deficiencies in its IT systems. The issues included inadequate access control and a lack of systematic log monitoring, which may have compromised the confidentiality of sensitive personal data.NODatatilsynetGDPR€1,707,000
29 Mar 2018ARC Informazioni s.r.l.ARC Informazioni s.r.l. was fined 20,000 EUR by the Garante. The authority found that the company failed to notify data processing activities as required by the Italian Privacy Code.ITGaranteGDPR€20,000
17 Feb 2025ARCONADA 1932, S.L.ARCONADA 1932, S.L. did not properly handle a data subject request for access to and deletion of personal data. This breached Articles 15 and 17 of the GDPR, and the company was fined for failing to comply with the AEPD's resolution.ESAEPDGDPR€1,500
12 Nov 2014Areacom s.r.l.Areacom s.r.l. was fined by the Garante 16,000 EUR for collecting personal data through its website without providing the required privacy notice. The breach concerned Article 13 of the Italian Data Protection Code.ITGaranteGDPR€16,000
08 Feb 2024AREIA CONSULTING, LTDAREIA CONSULTING, LTD was fined by the AEPD in the amount of 2,000 EUR for sending unsolicited commercial emails without prior recipient consent. The authority found this conduct breached Article 21 of the LSSI.ESAEPDePrivacy€2,000