Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
17 Jul 2012FARMACIA INTERNACIONALFARMACIA INTERNACIONAL was fined by the AEPD EUR 1,800 for continuing to send electronic newsletters to a customer after the customer had unsubscribed. The authority found a breach of Article 21.1 of the LSSI.ESAEPDePrivacy€1,800
01 Jan 2014G.L. GISOFT ANALISIS Y DISEÑO S.L.G.L. GISOFT ANALISIS Y DISEÑO S.L. was fined by the AEPD €1,800 for sending unsolicited commercial emails without recipient consent. The conduct breached Article 21 of the LSSI on electronic marketing communications.ESAEPDePrivacy€1,800
25 Mar 2014GRUPO A4 - FORMACIÓN S.C.GRUPO A4 - FORMACIÓN S.C. was fined by the AEPD 1,800 EUR for sending unsolicited commercial emails. The conduct breached Article 21 of the LSSI despite prior requests for data cancellation.ESAEPDePrivacy€1,800
01 Jan 2016GRUPO YAMM COMIDA A DOMICILIO S.L.The entity was fined for sending unsolicited commercial emails and for failing to honor unsubscribe requests. This constituted a breach of Article 21.1 of the LSSI.ESAEPDePrivacy€1,700
13 Dec 2022Anonymisé (CNPD decision-22-fr-2022)The CNPD found that the entity breached GDPR transparency obligations by failing to provide information in a concise, transparent, and easily accessible manner. The infringement concerned Articles 12 and 13 of the GDPR.LUCNPDGDPR€1,700
09 Mar 2023Deca s.r.l.Deca s.r.l. was fined EUR 1,600 by the Garante. The authority found that the company failed to respond to requests for access to personal data relating to work attendance and unlawfully processed data through an incomplete video surveillance system.ITGaranteGDPR€1,600
26 Jul 2018VILAN DATAMINING, S.L.VILAN DATAMINING, S.L. was fined by the AEPD in the amount of 1,600 EUR for sending unsolicited commercial emails without the required consent. The conduct breached article 21.1 of the LSSI.ESAEPDePrivacy€1,600
17 Jan 2025OLALA MNG, S.L.OLALA MNG, S.L. was fined by the AEPD EUR 1,600 for requesting excessive personal data from guests booking through a website. The authority found that asking for images of identity documents constituted a data protection breach.ESAEPDGDPR€1,600
07 Feb 2023Dane anonimowe (Wspólnotę Mieszkaniową „)UODO imposed an administrative fine on a housing community for entrusting personal data processing to an external provider without a written agreement and without verifying adequate technical and organizational safeguards. The authority also cited the failure to notify affected individuals without undue delay about the personal data breach.PLUODOGDPR€327
06 Jul 2006Vascotto RobertoThe sole proprietorship Vascotto Roberto was fined EUR 1,549 by the Garante for breaching data protection rules. The authority found that data subjects were not provided with the information required by law.ITGaranteGDPR€1,549
06 Jul 2006La Locanda dei f.lli Rosafio Gianfranco, Adriano e Mauro s.n.c.The company was fined for sending unsolicited promotional emails without providing recipients with the required information on data processing. The authority found a breach of the information obligation under data protection law.ITGaranteGDPR€1,549
29 May 2008Zampetti PasqualinaZampetti Pasqualina was fined EUR 1,549 by the Garante for sending unsolicited emails. The case concerns a breach of data protection rules in connection with marketing communications sent without a valid legal basis.ITGaranteGDPR€1,549
13 Jul 2006Work Safety Training Italia s.r.l.Work Safety Training Italia s.r.l. was fined by the Garante for sending unsolicited promotional emails. The authority found that the company failed to provide adequate information about data processing, breaching the information duty under data protection rules.ITGaranteGDPR€1,549
06 Jul 2006Filippi Giovanni & C. s.n.c.Filippi Giovanni & C. s.n.c. was fined 1,549 EUR by the Garante. The authority found that personal data were processed to send commercial messages without proper disclosure required under data protection law.ITGaranteGDPR€1,549
06 Jul 2006Mediatec-Mr s.r.l.Mediatec-Mr s.r.l. was fined by the Garante for sending unsolicited promotional emails without providing the required information on data processing. The authority found a breach of the information obligation under data protection law.ITGaranteGDPR€1,549
29 May 2008Target informatica di Rebosio GiancarloThe sole proprietorship Target informatica di Rebosio Giancarlo was fined EUR 1,549 by the Garante. The sanction concerned sending unsolicited promotional emails without providing the required information notice to the data subjects, in breach of Article 13 of the Italian Data Protection Code.ITGaranteGDPR€1,549
03 Oct 2023ASOCIACIÓN DE PROFESIONALES DE LA SEGURIDAD PRIVADA DE ESPAÑAThe association was fined for sending emails from personal email addresses instead of corporate ones. The authority found that this practice breached GDPR confidentiality and security requirements.ESAEPDGDPR€1,500
12 Apr 2024Centrul Medical dr. Furtună DanThe National Supervisory Authority for Personal Data Processing imposed a fine on Centrul Medical dr. Furtună Dan for breaching Article 6 of the GDPR. The infringement concerned the absence of a proper legal basis for personal data processing.ROANSPDCPGDPR€1,500
17 Jan 2023B.B.B.The entity installed surveillance cameras in the common areas of a residential community without proper authorization or the required informational signage. AEPD found a breach of GDPR Articles 6 and 13 and imposed a EUR 1,500 fine.ESAEPDGDPR€1,500
20 Nov 2023Libra Internet Bank SALibra Internet Bank SA was fined EUR 1,500 by ANSPDCP for GDPR violations. The case concerned non-compliance with personal data protection requirements.ROANSPDCPGDPR€1,500