Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
26 May 2022Università Agraria di NettunoUniversità Agraria di Nettuno was fined 4,000 EUR by the Garante for breaching data protection principles. The authority found unlawful handling of personal data, including failures in lawfulness, fairness, transparency, and data minimization, involving information publicly accessible online since 2019.ITGaranteGDPR€4,000
01 Jul 2021UNIVERSIDAD A DISTANCIA DE MADRID, S.A.UNIVERSIDAD A DISTANCIA DE MADRID, S.A. was fined by the AEPD for failing to comply with a request to delete personal data. As a result, the individual received unsolicited marketing emails, indicating a breach of data protection obligations.ESAEPDGDPR€5,000
14 Nov 2025UNIVERSIDADThe university was fined EUR 200,000 by the AEPD for processing special categories of personal data, including biometric data, without proper justification. The authority also found that a data protection impact assessment had not been carried out before implementing online exams.ESAEPDGDPR€200,000
14 Mar 2013Unitelma SapienzaUnitelma Sapienza was fined EUR 8,000 by the Garante for failing to provide information to data subjects and for not obtaining consent to process sensitive data. The violations occurred during online registration for university courses.ITGaranteGDPR€8,000
24 Jan 2013United Music s.r.l.United Music s.r.l. was fined for failing to notify the cessation of personal data processing activities related to profiling and personality definition through its websites. The authority found this to be a breach of the Italian Data Protection Code.ITGaranteGDPR€20,000
15 Apr 2025United Business Solutions SRLANSPDCP completed an investigation at United Business Solutions SRL and found a violation of GDPR provisions. As a result, a fine of EUR 2,000 was imposed.ROANSPDCPGDPR€2,000
30 Sept 2016UNITECO PROFESIONAL, CORREDURIA DE SEGUROS, S.L.UNITECO PROFESIONAL was fined EUR 1,000 by the AEPD for sending unsolicited commercial emails without providing recipients with an opt-out option. The authority found this to be a breach of Article 21 of the LSSI.ESAEPDePrivacy€1,000
31 May 2017Unit Contact s.r.l.Unit Contact s.r.l. was fined €32,000 by the Italian authority Garante. The case concerned unsolicited promotional calls made without the required information notice and without obtaining consent, in breach of data protection rules.ITGaranteGDPR€32,000
31 May 2017Unit Contact s.r.l.Unit Contact s.r.l. was fined by the Garante EUR 10,000 for making unsolicited promotional calls to a number listed in the public opt-out register. The conduct breached data protection rules and telephone marketing requirements.ITGaranteGDPR€10,000
09 Sept 2025Unita Turism Holding S.A.In August 2025, the National Supervisory Authority for Personal Data Processing completed an investigation at Unita Turism Holding S.A. and found violations of GDPR provisions. As a result, the operator was fined EUR 5,000.ROANSPDCPGDPR€5,000
01 Jan 2023UNIQUE HOTEL APARTMENT. S.LThe hotel improperly managed guest registration records, breaching data protection principles. It failed to maintain numerical order and did not communicate the records to the competent security forces.ESAEPDGDPR€2,000
01 Jan 2022UNIQUEDESIGN & DECOR, S.L.UNIQUEDESIGN & DECOR, S.L. was fined by the AEPD 5,000 EUR for not having an accessible privacy policy on its website. The authority found a breach of Article 13 GDPR because users were not properly provided with the required information.ESAEPDGDPR€5,000
01 Jan 2013UNIQ IT CONSULTORS S.L.UNIQ IT CONSULTORS S.L. was fined by the AEPD EUR 600 for sending unsolicited commercial emails without prior consent from recipients. The conduct breached Article 21 of the LSSI on marketing communications.ESAEPDePrivacy€600
24 Oct 2023UNIPREX, S.A.UNIPREX, S.A. was fined 50,000 EUR by the AEPD for processing an excessive amount of personal data. The authority found that the data collected went beyond what was necessary for the intended purpose.ESAEPDGDPR€50,000
01 Jan 2022UNION SINDICAL OBRERAThe labor union UNION SINDICAL OBRERA was fined by the AEPD for failing to comply with a prior decision on the complainant’s right to data deletion. Despite being notified of the obligation to stop, it continued sending emails.ESAEPDGDPR€3,000
24 Feb 2021UNIÓN FINANCIERA ASTURIANA S.A. E.F.C.UNIÓN FINANCIERA ASTURIANA S.A. E.F.C. was fined by the AEPD 15,000 EUR for consulting personal data in the Asnef file without a contractual relationship. The authority found this breached GDPR Article 6.1.ESAEPDGDPR€15,000
13 Apr 2023Unione PilotiUnione Piloti was fined by the Garante in the amount of 4,000 EUR for violations related to the processing of personal data. The authority found that the company failed to ensure lawful, fair, and transparent data handling.ITGaranteGDPR€4,000
10 Apr 2025Unione Montana Appennino Parma EstUnione Montana Appennino Parma Est was fined by the Italian supervisory authority, Garante, in the amount of EUR 8,000. The authority found a lack of required transparency in data processing and failure to carry out a data protection impact assessment for workplace video surveillance.ITGaranteGDPR€8,000
25 Mar 2021Unione dei Comuni Valli del Reno, Lavino e SamoggiaUnione dei Comuni Valli del Reno, Lavino e Samoggia was fined by the Garante EUR 13,000 for improperly publishing personal data on the web. The authority found a breach of GDPR principles on lawfulness and data processing.ITGaranteGDPR€13,000
24 Nov 2016Unione Comunale del Chianti fiorentinoUnione Comunale del Chianti fiorentino was fined by the Garante 10,000 EUR for publishing on its website the personal data of individuals who were not admitted to a financial benefit. The conduct breached data protection rules.ITGaranteGDPR€10,000