Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
06 Mar 2025SERVICIOS DE INTEGRACIÓN DE ANDALUCÍASERVICIOS DE INTEGRACIÓN DE ANDALUCÍA was fined €2,000 by the AEPD for adding an employee’s personal phone number to a work WhatsApp group without consent. The authority found a breach of the GDPR lawful-basis requirement under Article 6(1).ESAEPDGDPR€2,000
06 Mar 2025SHOPBAG GROUP ONLINE SRLSHOPBAG GROUP ONLINE SRL was fined EUR 2,000 by ANSPDCP. The authority found that the company failed to provide information requested for the performance of its supervisory tasks.ROANSPDCPGDPR€2,000
06 Mar 2025CUBILLO GALLEGO, S.L.CUBILLO GALLEGO, S.L. was fined by the AEPD in the amount of 900 EUR for failing to comply with data protection authority resolutions. The breach concerned the absence of required privacy information on the company website and in contracts.ESAEPDGDPR€900
06 Mar 2025Dane anonimowe (J.)UODO imposed an administrative fine of PLN 56,824 on Anonymous data (J.) for failing to implement appropriate technical and organizational measures to ensure processing security. The case concerned a breach of personal data protection obligations.PLUODOGDPR€13,604
06 Mar 2025AVENTURA EN TRAMPOLINES S.L.AVENTURA EN TRAMPOLINES S.L. was fined 900 EUR by the AEPD for failing to comply with data protection authority resolutions. The case concerned Article 58(2) GDPR, which requires cooperation with the supervisory authority.ESAEPDGDPR€900
07 Mar 2025SENDING TRANSPORTE Y COMUNICACIÓN, S.A.SENDING TRANSPORTE Y COMUNICACIÓN, S.A. was fined EUR 80,000 by the AEPD for breaching GDPR Articles 28(2) and 28(4). The company subcontracted data processing without the required authorization.ESAEPDGDPR€80,000
10 Mar 2025Οργανισμός Χρηματοδοτήσεως ΣτέγηςThe Housing Finance Corporation was fined by the CyDPC in the amount of €10,000 for retaining personal data beyond the legal retention period. The authority found this breached GDPR storage limitation and data accuracy requirements.CYCyDPCGDPR€10,000
11 Mar 2025UNIÓN DE CRÉDITO PARA LA FINANC. MOB. E INMOB., CREDIFIMO, E.F.C., SAUCREDIFIMO was fined by the AEPD for unlawfully processing personal data by including an individual's data in a credit file without a lawful basis. The authority found a breach of Article 6 of the GDPR.ESAEPDGDPR€200,000
11 Mar 2025Noy Business Tranzactions SRLANSPDCP completed an investigation in February 2025 at Noy Business Tranzactions SRL and found a breach of Article 17 of the GDPR. As a result, the controller was fined EUR 1,000.ROANSPDCPGDPR€1,000
11 Mar 2025LÁSER METALPRINT 3D, S.L.LÁSER METALPRINT 3D, S.L. was fined by the AEPD 10,000 EUR for deploying a video surveillance system without proper data processing agreements. The authority found a breach of GDPR Article 28.ESAEPDGDPR€10,000
12 Mar 2025Automobilus International S.R.L.The company was fined for failing to implement appropriate technical and organizational measures to ensure an adequate level of security. The authority found this to be a breach of Article 32 of the GDPR.ROANSPDCPGDPR€5,000
13 Mar 2025IV Casa Firenze Sud di Benedetti Francesco & C. S.a.s.IV Casa Firenze Sud di Benedetti Francesco & C. S.a.s. was fined by the Garante EUR 10,000 for making unsolicited marketing calls without proper consent. The authority found a breach of GDPR rules on data processing and consent.ITGaranteGDPR€10,000
13 Mar 2025ImmosanremoImmosanremo was fined EUR 3,000 by the Garante for sending unsolicited marketing messages via WhatsApp without valid consent. The authority found that the conduct breached GDPR rules on processing personal data for promotional purposes.ITGaranteGDPR€3,000
13 Mar 2025G@S Telecomunicazioni di Losito LuciaG@S Telecomunicazioni di Losito Lucia was fined EUR 15,000 by the Garante. The case concerned the unauthorized activation of a fixed-line telephone offer, which breached data protection rules.ITGaranteGDPR€15,000
13 Mar 2025Encore Thermoengineering s.r.l.Encore Thermoengineering s.r.l. was fined EUR 20,000 by the Garante. The case concerned an inadequate response to former employees’ requests about the status and deletion of their email accounts, which infringed data protection rights.ITGaranteGDPR€20,000
13 Mar 2025Interflora Italia S.p.A.Interflora Italia S.p.A. was fined EUR 40,000 by the Garante for sending promotional SMS messages without providing an opt-out option. The case indicates a breach of GDPR requirements for marketing communications and data subject rights.ITGaranteGDPR€40,000
13 Mar 2025Comune di RoccarasoThe Garante fined Comune di Roccaraso EUR 2,000 for publishing personal data on a public notice board. The authority found breaches of GDPR Articles 5, 6 and 12, as well as Article 2-ter of the Italian Privacy Code.ITGaranteGDPR€2,000
13 Mar 2025Istituto Alberghiero Mediterraneo di Pulsano (TA)Istituto Alberghiero Mediterraneo di Pulsano was fined EUR 2,000 by the Garante. The authority found breaches of the principles of lawfulness, fairness, and transparency in personal data processing.ITGaranteGDPR€2,000
13 Mar 2025Casatua S.r.l.Casatua S.r.l. was fined by the Garante 10,000 EUR for sending unsolicited communications via WhatsApp without obtaining proper recipient consent. The company also failed to implement adequate procedures to ensure compliance with data protection rules.ITGaranteGDPR€10,000
17 Mar 2025FEDERACION DE COLUMBICULTURA DE CASTILLA-LA MANCHAThe Federation published a voter list on its website, disclosing members’ personal data without consent. The authority found that adequate security measures were not in place to protect the data.ESAEPDGDPR€1,000