Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
01 Jan 2023CARSO TRADING, S.L.CARSO TRADING, S.L. was fined by the AEPD in the amount of 1,000 EUR for sending unsolicited commercial emails. The company also failed to respond to a data access request, which constitutes a breach of Article 15 GDPR.ESAEPDGDPR€1,000
30 Nov 2022INMARAN ASESORES S.L.INMARAN ASESORES S.L. was fined by the AEPD 1,000 EUR for failing to comply with data protection authority resolutions. The breach concerned the obligation to inform data subjects under Article 13 of the GDPR.ESAEPDGDPR€1,000
01 May 2026Anonymised (IDPC 0583_001)The Commissioner found that the insurance company continued to process the complainant’s personal data for direct marketing despite his objection. The authority also identified inadequate safeguards, weak accountability measures, and non-compliant arrangements with third-party processors. A reprimand was issued, corrective measures were ordered within 20 days, and administrative fines totalling EUR 1,000 were imposed.MTIDPCGDPR€1,000
04 Dec 2023CARSO TRADING, S.L.CARSO TRADING, S.L. was fined by the AEPD for sending unsolicited commercial emails without prior consent from recipients. The company also failed to respond to a request to stop such communications, which constitutes a breach of the LSSI.ESAEPDePrivacy€1,000
26 Jun 2025SC Piramida Trade Invest SRLSC Piramida Trade Invest SRL received a fine of EUR 1,000 from ANSPDCP. The sanction concerns a breach of Article 6 GDPR, meaning personal data were processed without a valid legal basis.ROANSPDCPGDPR€1,000
16 Jun 2023Anonymisiert (DSB 2023-0.404.421)An individual processed personal data without a legal basis by storing contact details on a private phone for political advertising. The DSB imposed a EUR 1,000 fine for breaching GDPR lawfulness requirements.ATDSBGDPR€1,000
31 Jan 2023Dent Estet Clinic SADent Estet Clinic SA was fined EUR 1,000 by ANSPDCP for failing to notify the supervisory authority within 72 hours of becoming aware of a personal data breach. The incident involved unauthorized disclosure of health data, which required prompt reporting under GDPR rules.ROANSPDCPGDPR€1,000
01 Jan 2021ASOCIACIÓN JEREZ CAPITALThe entity was fined by the AEPD for failing to comply with data protection rules in relation to its website cookie policy. Non-essential cookies were placed on the site without prior user consent.ESAEPDGDPR€1,000
19 Dec 2024CLUB RÁPIDO DE BOUZASThe club was fined by the AEPD for leaving documents containing players’ personal data, including minors’ data, in a public trash container. The authority found this breached data protection principles, especially confidentiality and security.ESAEPDGDPR€1,000
16 Sept 2024SC Class IT Outsourcing SRLSC Class IT Outsourcing SRL was fined EUR 1,000 by ANSPDCP for GDPR violations. The case concerned non-compliance with personal data protection requirements.ROANSPDCPGDPR€1,000
26 Feb 2015Anonymised (HDPA 26/2015)The company was fined for unlawful collection and processing of personal data, and for sending unsolicited marketing emails without recipients’ consent. The case concerns breaches of core data protection principles and the requirement to obtain prior consent for marketing communications.GRHDPAePrivacy€1,000
07 Jun 2021EFS MANTENIMIENTO Y SERVICIOS TÉCNICOS, S.L.EFS MANTENIMIENTO Y SERVICIOS TÉCNICOS, S.L. was fined EUR 1,000 by the AEPD for improperly sharing an employee’s personal data with the company committee. The authority found a breach of data protection rules.ESAEPDGDPR€1,000
22 Jun 2017Bolos & SynergatesThe law firm Bolos & Synergates was fined EUR 1,000 by the HDPA for unlawfully collecting and using personal data for direct marketing. The violation involved unsolicited electronic communications sent without prior consent from the data subjects.GRHDPAePrivacy€1,000
05 Aug 2025Ordinul Biochimiștilor, Biologilor și Chimiștilor în Sistemul Sanitar din RomâniaANSPDCP imposed a EUR 1,000 fine on the Order of Biochemists, Biologists and Chemists in the Romanian Healthcare System for breaching Article 15 of the GDPR. The case concerned improper handling of a data subject access request.ROANSPDCPGDPR€1,000
10 Jul 2020COMUNIDAD.1The entity was fined for installing surveillance cameras with audio in common areas without proper notice to affected persons. The authority found this to be a breach of data protection rules.ESAEPDGDPR€1,000
05 Mar 2021APARTAMENTOS PLAYA DE COVACHOS, S.L.The company was fined by the AEPD in the amount of 1,000 EUR for operating video surveillance without the required information for recorded individuals. It did not identify the data controller, explain how rights could be exercised, or state the purpose of the surveillance, which breaches Article 13 GDPR.ESAEPDGDPR€1,000
26 May 2014General Hospital PapageorgiouGeneral Hospital Papageorgiou was fined EUR 1,000 by the HDPA for transferring sensitive health data without prior authorization. The hospital also failed to inform the data subject, breaching Greek data protection law.GRHDPAGDPR€1,000
01 Jan 2014EL CORTE INGLES, S.A.EL CORTE INGLES, S.A. was fined by the AEPD 1,000 EUR for sending unsolicited commercial emails. The conduct breached Article 21.1 of Spain’s LSSI, which restricts marketing communications without recipient consent.ESAEPDePrivacy€1,000
01 Aug 2025Dr. Max SRLANSPDCP fined Dr. Max SRL EUR 1,000 after an investigation concluded in August 2025. The authority found breaches of GDPR Articles 12 and 17, including failure to respond to a deletion request and unlawful retention of an identity card copy without consent.ROAutoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter PersonalGDPR€1,000
24 Nov 2022STS Di Prisinzano s.r.l.STS Di Prisinzano s.r.l. was fined EUR 1,000 by the Garante for failing to provide a data subject with an adequate privacy notice during roadside assistance. The authority found a breach of Article 13 GDPR.ITGaranteGDPR€1,000