Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
30 Jan 2026un operator persoană fizicăA 1,000 EUR fine was imposed on an individual operator for GDPR violations. The case concerned non-compliance with personal data protection requirements.ROANSPDCPGDPR€1,000
04 Apr 2022B.B.B.B.B.B. was fined 1,000 EUR by the AEPD for failing to comply with Article 13 of the GDPR. The authority found that the privacy policy did not provide adequate information on data retention periods and transfers to third parties.ESAEPDGDPR€1,000
13 Dec 2022Anonymisé (CNPD decision-19-fr-2022)The company failed to meet GDPR transparency obligations by not providing the required information in a concise, transparent, and easily accessible manner. CNPD imposed a fine of 1,000 EUR.LUCNPDGDPR€1,000
28 Jun 2023FESTINA LOTUS S.A.FESTINA LOTUS S.A. did not respond to requests to delete a user's account and personal data. The authority found a breach of Article 17 GDPR and imposed a fine of EUR 1,000.ESAEPDGDPR€1,000
23 Nov 2022Linee Stampalibera Società Cooperativa S.r.l.Linee Stampalibera Società Cooperativa S.r.l. was fined 1,000 EUR by the Garante for publishing personal data on its website without consent. The case also involved the full text of a property purchase contract, which breached data protection rules.ITGaranteGDPR€1,000
22 Jun 2023Spaziani FabrizioThe Garante fined Spaziani Fabrizio EUR 1,000 for non-compliant video surveillance practices. The case involved cameras that were not properly signposted and may have captured public areas.ITGaranteGDPR€1,000
10 Sept 2024Fundația Pro Economica – Pro Economica AlapítványThe foundation was fined EUR 1,000 by ANSPDCP after a data security incident caused by a cyberattack. The attack led to the deletion of personal data from its server, affecting data availability.ROANSPDCPGDPR€1,000
30 Jul 2018А.С.К. УМБАЛ ЕООДThe CPDP found that “А.С.К. УМБАЛ ЕООD” unlawfully processed personal data by providing it to “МБАЛ-В. ЕООD” without consent. This breached data protection rules and resulted in a fine of BGN 1,000.BGCPDPGDPR€511
18 Dec 2025Provvedimento del 18 dicembre 2025 [10210431]A professional sent a communication containing personal data to an institutional email address, which breached data protection rules. The Garante imposed a fine of EUR 1,000.ITGaranteGDPR€1,000
07 Sept 2022LEGAL TRAINING GROUP, S.L.LEGAL TRAINING GROUP, S.L. was fined by the AEPD €1,000 for sending unsolicited commercial communications. The conduct occurred after the complainant had exercised the right to data deletion.ESAEPDePrivacy€1,000
01 Jan 2018ZARA LIBRO S.L. (DIFUSIÓN DEL LIBRO)ZARA LIBRO S.L. was fined by the AEPD in the amount of 1,000 EUR for sending a commercial email without a prior commercial relationship. The authority found a breach of Article 21.1 of the LSSI.ESAEPDePrivacy€1,000
05 Feb 2021NEXTSTEPAGENCY, S.L.NEXTSTEPAGENCY, S.L. was fined by the AEPD in the amount of 1,000 EUR for failing to provide reliable ownership information and details about data transfers to China on its website. The authority found a breach of the information obligations under Article 13 GDPR.ESAEPDGDPR€1,000
09 May 2024MEDICOVER SRLMEDICOVER SRL was fined EUR 1,000 by ANSPDCP for the unauthorized disclosure of personal data from a medical consultation report to an unintended patient. The case concerns a breach of confidentiality involving special-category data and indicates a need to strengthen access controls and recipient verification procedures.ROANSPDCPGDPR€1,000
22 Feb 2022Societatea Civilă Profesională de Avocați „Sabou, Burz & Cuc”The law firm Societatea Civilă Profesională de Avocați „Sabou, Burz & Cuc” was fined by ANSPDCP for violating GDPR provisions. The penalty amounted to EUR 1,000.ROANSPDCPGDPR€1,000
26 Feb 2026Ciemme S.r.l.sThe Italian Data Protection Authority fined Ciemme S.r.l.s EUR 1,000 for failing to respond to a data subject request to exercise rights of access, erasure, and objection. The case arose after unsolicited marketing calls.ITGaranteGDPR€1,000
07 Jun 2024Club Balonmano GijónClub Balonmano Gijón was fined EUR 1,000 by the AEPD for unlawfully processing personal data by publishing images of minors on its website without a legal basis. The case indicates a breach of the lawfulness principle and the protection of children's image rights.ESAEPDGDPR€1,000
18 Sept 2025Dr.Max SRLIn August of the current year, ANSPDCP completed an investigation at Dr.Max SRL and found a breach of GDPR provisions. As a result, the operator was fined EUR 1,000.ROANSPDCPGDPR€1,000
25 Oct 2024IA BILET SRLThe operator was fined EUR 1,000 by ANSPDCP for violating GDPR provisions. The case concerns non-compliant processing of personal data.ROANSPDCPGDPR€1,000
20 May 2022THUNDER HUNTER ENERGY ADVISORS, S.L.THUNDER HUNTER ENERGY ADVISORS, S.L. was fined by the AEPD 1,000 EUR for sending unsolicited commercial emails without prior consent. The authority found this conduct breached Article 21.1 of the LSSI.ESAEPDePrivacy€1,000
20 Mar 2026Domeniul Public și Privat SADomeniul Public și Privat SA was fined EUR 1,000 for breaching Article 15 of the GDPR. The case concerned improper handling of data subject access rights.ROANSPDCPGDPR€1,000