Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-24%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
28 Jul 2025KINYO, S.L.KINYO, S.L. was fined by the AEPD in the amount of 15,000 EUR for sending unsolicited commercial emails. The authority also found that recipients were not provided with an effective mechanism to opt out of future communications.ESAEPDePrivacy€15,000
29 Jul 2025Anonimizirano (IP-RS 0609-18/2025/7)The legal entity was fined by IP-RS for unlawfully processing personal data by redirecting emails without a legal basis. The authority found a breach of the GDPR principle of lawfulness.SIIP-RSGDPR€10,614
30 Jul 2025ONEY SERVICIOS FINANCIEROS EFC, S.A.The AEPD fined ONEY Servicios Financieros EFC, S.A. 150,000 EUR for failing to adequately protect personal data. The breach led to a security incident in which a third party accessed a customer's account through a vishing attack.ESAEPDGDPR€150,000
01 Aug 2025društvo XThe company failed to implement appropriate organizational and technical security measures, which led to the unauthorized disclosure of personal data of clients involved in credit financing. AZOP imposed a fine of 17,500 EUR.HRAZOPGDPR€17,500
01 Aug 2025Dr. Max SRLANSPDCP fined Dr. Max SRL EUR 1,000 after an investigation concluded in August 2025. The authority found breaches of GDPR Articles 12 and 17, including failure to respond to a deletion request and unlawful retention of an identity card copy without consent.ROAutoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter PersonalGDPR€1,000
04 Aug 2025Azienda Ospedaliero-UniversitariaThe Italian data protection authority fined Azienda Ospedaliero-Universitaria EUR 80,000 for improperly configuring its health dossier. It found that staff could access patients’ clinical histories without proper profiling, alerts, or access logging, and that patients were not adequately informed or able to consent or object.ITGarante per la protezione dei dati personaliGDPR€80,000
04 Aug 2025Linea Stampalibera Società Cooperativa r.l.The Garante imposed a EUR 2,000 fine on Linea Stampalibera Società Cooperativa r.l. for unlawfully disseminating personal data, including health information, on its online news site. The authority found a breach of data protection rules.ITGaranteGDPR€2,000
04 Aug 2025Azienda Ospedaliero Universitaria CareggiAzienda Ospedaliero Universitaria Careggi was fined by the Garante EUR 20,000 for violations related to the management of electronic health records. The authority found non-compliance with data protection requirements.ITGaranteGDPR€20,000
05 Aug 2025Ordinul Biochimiștilor, Biologilor și Chimiștilor în Sistemul Sanitar din RomâniaANSPDCP imposed a EUR 1,000 fine on the Order of Biochemists, Biologists and Chemists in the Romanian Healthcare System for breaching Article 15 of the GDPR. The case concerned improper handling of a data subject access request.ROANSPDCPGDPR€1,000
06 Aug 2025GOHIPOTECA, S.L.GOHIPOTECA, S.L. processed personal data without consent, using an individual's data to apply for a mortgage without authorization. The AEPD imposed a fine of EUR 2,000 for this violation.ESAEPDGDPR€2,000
06 Aug 2025SERVICIOS FINANCIEROS CARREFOUR, E.F.C., S.ASERVICIOS FINANCIEROS CARREFOUR, E.F.C., S.A suffered a data breach involving unauthorized access to and exfiltration of customer personal data, including payment information. The incident was linked to phishing and account compromise, resulting in the loss of sensitive data.ESAEPDGDPR€2,500,000
06 Aug 2025ORNITOLÓGICA DE ANDALUCÍA FOAORNITOLÓGICA DE ANDALUCÍA FOA was fined EUR 1,500 by the AEPD for sending a mass email that contained personal data, including names and DNI numbers, without adequate security measures. The authority found this to be a breach of data protection rules.ESAEPDGDPR€1,500
06 Aug 2025YUNEXPRESS SPAIN, S.L.YUNEXPRESS SPAIN, S.L. was fined EUR 9,000 by the AEPD for failing to formalize a data processing agreement and for inaccuracies in data handling. The authority found breaches of GDPR Articles 28(3) and 5(1)(d).ESAEPDGDPR€9,000
11 Aug 2025APARELLS ORTOPEDICS CURTO, S.L.APARELLS ORTOPEDICS CURTO, S.L. did not provide complete personal data and medical records in response to an access request. The AEPD found this to be a breach of data protection rules and imposed a fine of 10,000 EUR.ESAEPDGDPR€10,000
11 Aug 2025FUNDACIÓN PARA EL DESARROLLO DE LA ENFERMERÍA y SINDICATO DE ENFERMERÍA, SATSESATSE and FUDEN were fined by the AEPD EUR 15,000 after a ransomware incident affected personal data. The authority also found that the parties had not properly formalized a joint controllership agreement under the GDPR.ESAEPDGDPR€15,000
12 Aug 2025Asociația Casa de Ajutor Reciproc „FLEXICREDIT”In June 2025, ANSPDCP completed an investigation at Asociația Casa de Ajutor Reciproc „FLEXICREDIT” and found violations of GDPR provisions. The entity was fined EUR 3,000.ROANSPDCPGDPR€3,000
13 Aug 2025TELECONTACT LIST S.L.TELECONTACT LIST S.L. was fined by the AEPD €1,000 for failing to respond to a data subject’s requests to exercise the rights of access and erasure. The authority found a breach of GDPR obligations, including Article 17.ESAEPDGDPR€1,000
13 Aug 2025Anonimizirano (IP-RS 0609-97/2024/2)A sole proprietor was fined for failing to respond to a request from the Information Commissioner within the specified 10-day period. The authority treated this as a breach of Article 31 GDPR.SIIP-RSGDPR€500
14 Aug 2025ALIQUAM SOFTWARE DEVELOPMENT, S.R.L.UALIQUAM SOFTWARE DEVELOPMENT, S.R.L.U was fined by the AEPD 1,400 EUR for sending unsolicited marketing emails despite requests to stop. The case concerns a breach of the LSSI rules on commercial communications.ESAEPDePrivacy€1,400
18 Aug 2025SC Elite Conta SRLThe National Supervisory Authority for Personal Data Processing completed an investigation in July 2025 at SC Elite Conta SRL and found a GDPR violation. The company was fined for failing to properly notify a personal data security breach.ROANSPDCPGDPR€3,000