Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
26 Mar 2026Provvedimento del 26 marzo 2026 [10246060]The entity was fined for operating a video surveillance system without providing adequate informational signage. The authority found this to be a breach of GDPR Article 13 on the duty to inform data subjects.ITGaranteGDPR€2,000
04 Aug 2017STAPLES PRODUCTOS DE OFICINA S.L.U.STAPLES PRODUCTOS DE OFICINA S.L.U. was fined EUR 2,000 by the AEPD for sending unsolicited commercial emails. The breach involved continuing to contact recipients despite requests to cancel consent.ESAEPDePrivacy€2,000
09 Sept 2022COMUNIDAD DE PROPIETARIOS R.R.R.COMUNIDAD DE PROPIETARIOS R.R.R. was fined by the AEPD 2,000 EUR for unauthorized access to and dissemination of video surveillance recordings. The case concerns a breach of data protection rules.ESAEPDGDPR€2,000
20 Feb 2025Medstar S.R.L.Medstar S.R.L. was fined by ANSPDCP for failing to notify the data breach to the supervisory authority. The company also did not inform the affected individuals about the unauthorized disclosure of their personal data.ROANSPDCPGDPR€2,000
01 Jan 2021RECLAMADOR, S.L.RECLAMADOR, S.L. was fined €2,000 by the AEPD for sending a commercial electronic communication after the recipient had exercised the right to erasure. The authority found this conduct breached GDPR and LSSI requirements.ESAEPDGDPR€2,000
01 Jan 2017Happy Social Media LTD.Happy Social Media LTD. was fined by the AEPD EUR 2,000 for sending advertising emails to individuals who had opted out of receiving them. The case concerned Article 21.1 of the LSSI and the obligation to respect objections to marketing communications.ESAEPDePrivacy€2,000
29 Jun 2023FORKMERGE S.L.FORKMERGE S.L. was fined by the AEPD EUR 2,000 for failing to comply with a data subject’s request to remove personal data from search engine results. The authority found this to be a breach of Article 17 GDPR.ESAEPDGDPR€2,000
18 Jan 2021INDUSTRIAS METÁLICAS ANRO, S.L.INDUSTRIAS METÁLICAS ANRO, S.L. was fined by the AEPD for failing to comply with cookie policy requirements on its website. The breach concerned Article 22.2 of the LSSI.ESAEPDePrivacy€2,000
04 Aug 2022Sephora Cosmetics România SASephora Cosmetics România SA was fined EUR 2,000 by ANSPDCP for violating GDPR provisions. The case concerned non-compliance with personal data protection requirements.ROANSPDCPGDPR€2,000
04 Dec 2020BEINNOVA.ESBEINNOVA.ES was fined by the AEPD EUR 2,000 for sending unsolicited marketing emails without the recipient's consent. This conduct breached Article 21 of the LSSI on electronic commercial communications.ESAEPDePrivacy€2,000
28 Jun 2021ELEGA ENERGÍA, S.L.ELEGA ENERGÍA, S.L. was fined EUR 2,000 by the AEPD for failing to provide information about cookies and for not obtaining user consent before placing them. The authority found a breach of Article 22.2 of the LSSI.ESAEPDePrivacy€2,000
27 Sept 2022Anonymised (HDPA 18/2022)A fine was imposed for sending unsolicited political communication via SMS without prior consent. The case concerns a breach of consent requirements for political and marketing communications.GRHDPAePrivacy€2,000
16 Feb 2022FEDERACION CASTELLANO-LEONESA DE SALVAMENTO Y SOCORRISMOThe organization was fined EUR 2,000 by the AEPD for requiring participants to consent to data processing and image rights transfers without any option to refuse. The authority found this incompatible with Article 6(1) GDPR.ESAEPDGDPR€2,000
13 Dec 2021SC Nobiotic Pharma SRLSC Nobiotic Pharma SRL was fined €2,000 by ANSPDCP for failing to respond to information requests. The authority treated this as a breach of GDPR obligations.ROANSPDCPGDPR€2,000
14 Feb 2023MENZIES AVIATION SPAIN S.L.MENZIES AVIATION SPAIN S.L. was fined by the AEPD 2,000 EUR for sending emails to multiple recipients without using BCC. This exposed employees’ personal data to other recipients.ESAEPDGDPR€2,000
16 Jan 2026Liceo Classico e Scientifico Alessandro VoltaLiceo Classico e Scientifico Alessandro Volta was fined 2,000 EUR by the Garante for publishing personal data on its institutional website without a proper legal basis. The authority found breaches of lawfulness, fairness, and transparency principles.ITGaranteGDPR€2,000
18 Dec 2025Elba Catering Distribuzioni s.r.l.s.Elba Catering Distribuzioni s.r.l.s. was fined EUR 2,000 by the Garante for installing a video surveillance system that primarily captured public streets. The authority found that this processing breached data protection rules.ITGaranteGDPR€2,000
25 Nov 2019YA candidate in municipal elections was fined for using a customer list to send election propaganda. The authority found a breach of the GDPR purpose limitation principle.BEAPDGDPR€2,000
01 Sept 2020Geanonimiseerd (APD 53/2020)A politician was fined for sending an election propaganda email without consent. The authority found unlawful processing of personal data and a failure to implement appropriate technical and organizational measures.BEAPDGDPR€2,000
22 May 2024TRADING INTERNATIONAL TOURIST, S.L.TRADING INTERNATIONAL TOURIST, S.L. was fined 2,000 EUR by the AEPD for adding the complainant’s phone number to a WhatsApp group with more than 500 members without consent. The authority found a breach of Article 6(1) GDPR, which requires a lawful basis for processing personal data.ESAEPDGDPR€2,000