Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
17 Dec 2024ASOCIACIÓN ESCUELA NACIONAL DE EQUITACIÓNASOCIACIÓN ESCUELA NACIONAL DE EQUITACIÓN was fined EUR 750 by the AEPD for failing to comply with a data protection authority resolution. The case concerns Article 58(2) of the GDPR.ESAEPDGDPR€750
01 Jan 2024ASOCIACIÓN ESCUELA NACIONAL DE EQUITACIÓNThe entity was fined €4,000 by the AEPD for processing personal data without a lawful basis and for failing to inform the data subject. The authority found breaches of Articles 6 and 14 of the GDPR.ESAEPDGDPR€4,000
31 Jul 2020ASOCIACIÓN DE VIGILANTES DE SEGURIDAD DEL AEROPUERTO DE BARCELONAThe organization was fined by the AEPD in the amount of 3,000 EUR for sending an electoral census of workers to private phones via WhatsApp. The authority found a breach of data protection principles.ESAEPDGDPR€3,000
03 Oct 2023ASOCIACIÓN DE PROFESIONALES DE LA SEGURIDAD PRIVADA DE ESPAÑAThe association was fined for sending emails from personal email addresses instead of corporate ones. The authority found that this practice breached GDPR confidentiality and security requirements.ESAEPDGDPR€1,500
25 Sept 2019ASOCIACION DE MEDICOS DEMOCRATASASOCIACION DE MEDICOS DEMOCRATAS was fined by the AEPD EUR 10,000 for processing the personal data of medical professionals without their consent. The authority found a breach of Article 6(1)(a) GDPR.ESAEPDGDPR€10,000
19 Feb 2016Asociación de Empresarios de Tecnologías de la Información y Comunicaciones de Andalucía (ETICOM)ETICOM was fined €3,400 by the AEPD for sending unsolicited commercial emails without prior consent from recipients. The authority also found that the messages did not include a simple opt-out mechanism, in breach of Article 21 of the LSSI.ESAEPDePrivacy€3,400
14 Sept 2011Asociación de Comerciantes, Empresarios y Profesionales ACTIVAThe entity was fined by the AEPD for sending unsolicited commercial emails without prior consent from recipients. This conduct breached Article 21 of the LSSI.ESAEPDePrivacy€1,200
15 Feb 2022ASOCIACIÓN DE AFICIONADOS Y PEQUEÑOS ACCIONISTAS UNIDAD HERCULANAThe organization was fined by the AEPD 3,000 EUR for failing to provide a privacy policy compliant with Article 13 of the GDPR on its website. It collected personal data through various forms but did not provide the required information to data subjects.ESAEPDGDPR€3,000
12 Jan 2021ASOCIACIÓN CULTURAL ***ASOCIACIÓN.1The association was fined for sharing images of a minor in WeChat groups without parental consent. The authority found a breach of GDPR Article 6(1)(a).ESAEPDGDPR€3,000
30 May 2022ASOCIACIÓN CONTRA LA CORRUPCION Y EN DEFENSA DE LA ACCIÓN PÚBLICAACODAP was fined EUR 10,000 by the AEPD for publishing complainants’ personal data on its website without anonymization. The authority found this conduct to be contrary to GDPR Article 5(1)(b).ESAEPDGDPR€10,000
22 Nov 2023ASOCIACIÓN COMUNIDAD DE VECINOS R.R.R.The association unlawfully processed personal data by sending all members a letter containing personal details of a person who was not part of the association. The authority found a breach of Article 6(1) GDPR and imposed a fine.ESAEPDGDPR€1,000
22 Jun 2023ASOCIACIÓN CANNÁBICA CLUB 26The entity installed surveillance cameras facing public spaces without prior administrative authorization. This may have infringed third-party rights and data protection rules.ESAEPDGDPR€500
15 Jul 2024ASNEF-EQUIFAX, SERVICIOS DE INFORMACIÓN SOBRE SOLVENCIA Y CRÉDITO, S.L.ASNEF-EQUIFAX was fined by the AEPD 200,000 EUR for failing to properly handle a data subject’s request for deletion and for processing personal data without a legal basis. The case concerns breaches of core data protection obligations.ESAEPDGDPR€200,000
12 Jan 2023ASNEF-EQUIFAX, SERVICIOS DE INFORMACIÓN SOBRE SOLVENCIA Y CRÉDITO, S.L.ASNEF-EQUIFAX was fined by the AEPD EUR 5,000 for including personal data in a credit file without prior notice. The company also failed to respond to access requests, which constitutes a breach of GDPR Article 15.ESAEPDGDPR€5,000
01 Jan 2021ASM PRATASM PRAT was fined EUR 5,000 by the AEPD for requiring recipients to submit photos of their ID cards without consent. The company also failed to provide information about the data processing, which breached data protection rules.ESAEPDGDPR€5,000
01 Jan 2024a small recruitment bureauA small recruitment bureau in the Netherlands was fined EUR 6,000 by the Autoriteit Persoonsgegevens for failing to respond on time to an ex-candidate’s request to delete personal data. The Raad van State upheld the fine in case ECLI:NL:RVS:2024:2221.NLAutoriteit PersoonsgegevensGDPR€6,000
08 Feb 2007Asl Vibo ValentiaThe health authority Asl Vibo Valentia was fined by Garante for improperly handling sensitive personal data, including genetic and biometric data, without proper authorization. The case concerns a breach of data protection rules and the legal basis required for processing such data.ITGaranteGDPR€10,000
14 Sept 2006Asl VercelliAsl Vercelli was fined by the Garante for processing special-category personal data, including genetic and health data, without the required notification. The authority found this to be a breach of the Italian Data Protection Code.ITGaranteGDPR€10,000
13 Sept 2007Asl San Severo (Foggia 1)Asl San Severo (Foggia 1) was fined by the Garante for processing personal data, including genetic and biometric data, without proper compliance with data protection rules. The case indicates insufficient legal basis and safeguards for the handling of sensitive data.ITGaranteGDPR€10,000
13 Sept 2007Asl Salerno 2Asl Salerno 2 was fined EUR 10,000 by the Garante for failing to notify personal data processing activities within the required timeframe. The breach concerned the Italian Data Protection Code.ITGaranteGDPR€10,000