Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
23 May 2018BELEADER INTERNET MARKETING S.L.BELEADER INTERNET MARKETING S.L. was fined 5,000 EUR by the AEPD. The authority found that the company sent unsolicited emails and did not honor unsubscribe requests.ESAEPDePrivacy€5,000
03 Mar 2025BEKO ROMÂNIA SAIn February 2025, ANSPDCP completed an investigation at BEKO ROMÂNIA SA and found violations of GDPR provisions. As a result, the controller was fined EUR 10,000.ROANSPDCPGDPR€10,000
04 Dec 2020BEINNOVA.ESBEINNOVA.ES was fined by the AEPD EUR 2,000 for sending unsolicited marketing emails without the recipient's consent. This conduct breached Article 21 of the LSSI on electronic commercial communications.ESAEPDePrivacy€2,000
16 Nov 2023BEGIN RESTAURANTES, S.L.BEGIN RESTAURANTES, S.L. was fined by the AEPD EUR 2,000 for deficiencies in its cookie policy. The authority found the use of non-essential third-party cookies without proper consent and insufficient information in the main page banner.ESAEPDePrivacy€2,000
01 Jan 2012BECERRITA, S.L.BECERRITA, S.L. was fined by the AEPD EUR 600 for sending unsolicited commercial emails without proper consent. The conduct breached Article 21 of the LSSI on electronic marketing communications.ESAEPDePrivacy€600
04 Jan 2022BEAUTY & AESTHETIC BALEARIC, SL.BEAUTY & AESTHETIC BALEARIC, SL. was fined by the AEPD €1,000 for sending marketing emails without an opt-out mechanism. The authority found this to be a breach of Article 21 of the LSSI.ESAEPDePrivacy€1,000
12 Dec 2024BDM Banca S.p.A.BDM Banca S.p.A. was fined by the Italian data protection authority, Garante, in the amount of EUR 20,000. The sanction concerned the failure to provide a timely response to a data subject’s access request, which constitutes a breach of GDPR Article 15.ITGaranteGDPR€20,000
07 Mar 2024BdM Banca S.p.a.BdM Banca S.p.a. was fined 10,000 EUR by the Garante for failing to provide an adequate response to a data access request submitted by an heir. The authority found that the response did not meet the requirements of GDPR Article 15.ITGaranteGDPR€10,000
03 Jun 2013BBVA SERVICIOS, S.A.BBVA SERVICIOS, S.A. was fined by the AEPD EUR 30,001 for sending unsolicited commercial emails without prior consent. This conduct breached Article 21.1 of the LSSI.ESAEPDePrivacy€30,001
11 Jan 2023BBVABBVA was fined by the AEPD EUR 1,640,000 for multiple data protection violations. The case involved unauthorized payment operations and improper handling of personal data in credit information systems.ESAEPDGDPR€1,640,000
13 Jun 2013BBJ s.r.l.BBJ s.r.l. was fined by the Garante EUR 64,000 for running SMS and email marketing campaigns without providing the required information to data subjects and without obtaining their consent. The authority found this to be a breach of data protection rules.ITGaranteGDPR€64,000
03 May 2022B.B.B.Y OTRO MAS C.B.The entity installed a video surveillance system without providing the required information to data subjects. The conduct breached Article 13 of the GDPR and resulted in a EUR 300 fine imposed by the AEPD.ESAEPDGDPR€300
23 Oct 2012B.B.B. (VELAS TLC)B.B.B. (VELAS TLC) was fined by the AEPD in the amount of EUR 1,200 for sending unsolicited commercial emails. The conduct breached Article 21.1 of the LSSI, which prohibits such communications without prior consent.ESAEPDePrivacy€1,200
23 Mar 2023B.B.B.B.B.B. was fined 300 EUR by the AEPD for installing surveillance cameras that could capture images of a neighboring property without prior authorization. The authority found this to be a breach of the data minimization principle under Article 5(1)(c) GDPR.ESAEPDGDPR€300
01 Jan 2020B.B.B.B.B.B. was fined by the AEPD in the amount of 1,000 EUR for sending a commercial SMS to the complainant after confirming deletion of the complainant’s personal data. The authority found this conduct to be a breach of Article 21 of the LSSI.ESAEPDePrivacy€1,000
25 Feb 2022B.B.B.B.B.B. was fined by the AEPD in the amount of EUR 300 for installing a surveillance camera that captured a public transit area. The footage was then disseminated without consent, which constituted a breach of data protection rules.ESAEPDGDPR€300
28 May 2024B.B.B.B.B.B., a councilor, unlawfully published the personal data of a complainant and their spouse in a municipal meeting note. The information was shared with a group of about 400 people, causing reputational harm.ESAEPDGDPR€1,000
24 Sept 2021B.B.B.The entity was fined for operating a video surveillance system aimed at public and private spaces without sufficient justification. The authority found this to be a breach of data protection rules.ESAEPDGDPR€2,500
24 Feb 2011B.B.B.B.B.B. was fined EUR 600 by the AEPD for sending an unsolicited commercial email to the complainant without meeting the required legal conditions. The authority found a breach of Article 21 of the LSSI governing electronic commercial communications.ESAEPDePrivacy€600
08 Apr 2022B.B.B.The entity was fined for installing security cameras that recorded audio and covered areas such as the restroom without proper notice to employees or customers. The authority found this breached GDPR rules on data processing and transparency of information.ESAEPDGDPR€3,000