Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
03 Apr 2014Armando ChessaArmando Chessa was fined by the Garante for failing to provide adequate information about the use of a video surveillance system. The authority found a breach of data protection rules.ITGaranteGDPR€2,400
11 Feb 2021Arma dei carabinieriArma dei carabinieri was fined by the Garante for improperly handling sensitive and judicial data without adequate safeguards against unauthorized access. The authority found breaches of the GDPR and the Italian Privacy Code.ITGaranteGDPR€10,000
09 Oct 2025Arienti & C. s.r.l. a socio unicoThe Garante fined Arienti & C. s.r.l. a socio unico EUR 8,000 for denying a former employee access to their email account after the employment contract ended. The authority found this breached GDPR Article 15 on the right of access to personal data.ITGaranteGDPR€8,000
20 Jul 2017Aria S.p.a.Aria S.p.a. was fined 20,000 EUR by the Garante. The authority found a data protection breach for failing to designate employees as data processors.ITGaranteGDPR€20,000
06 Feb 2014Arianna ContuArianna Contu was fined by the Garante for operating a video surveillance system in her bar without the required notices informing people of the monitoring. The case concerned non-compliance with privacy law signage obligations.ITGaranteGDPR€2,400
16 Mar 2023Argon Medical DevicesArgon Medical Devices was fined NOK 2.5 million by the Norwegian Data Protection Authority, Datatilsynet. The company failed to report a personal data breach involving European employees within the 72-hour deadline required by GDPR Article 33.NODatatilsynetGDPR€218,000
22 Mar 2018ARGOINFOR S.L.ARGOINFOR S.L. was fined by the AEPD in the amount of 1,000 EUR. The case concerned the sending of unsolicited commercial emails, which breaches Article 21 of the LSSI.ESAEPDePrivacy€1,000
26 Oct 2023Argentum Data Solutions LtdBetween 1 January 2021 and 31 January 2022, a total of 2,330,423 SMS messages were sent without consent. Argentum Data Solutions Ltd sent 24,309 messages directly and allowed its lines to be used by third parties to send the remaining 2,306,114. The conduct breached regulation 22 of PECR and came to the ICO’s attention through complaints reported via the 7726 spam tool.GBICOePrivacy€74,568
01 Jan 2015ARGATEL SOLUTIONS S.L.ARGATEL SOLUTIONS S.L. was fined by the AEPD €2,200 for sending unsolicited SMS messages. The authority found that the company had not obtained prior consent and did not provide an unsubscribe option.ESAEPDePrivacy€2,200
24 May 2013ARGATEL SOLUTIONS SLARGATEL SOLUTIONS SL was fined EUR 600 by the AEPD. The sanction concerned sending unsolicited premium SMS advertisements without recipient consent, in breach of Article 21.2 of the LSSI.ESAEPDePrivacy€600
01 Jan 2020ARGAN-LET, S.L.ARGAN-LET, S.L. was fined 900 EUR by the AEPD for sending unsolicited commercial SMS messages without prior consent. This conduct breached Article 21 of the LSSI.ESAEPDePrivacy€900
24 Nov 2022Areti S.p.A.Areti S.p.A. was fined EUR 1,000,000 by the Garante for incorrectly labeling a customer as a “defaulting client” based on inaccurate and outdated data. The issue may have affected up to 16,743 other individuals, indicating a broader data processing failure.ITGaranteGDPR€1,000,000
13 Sept 2024ARES CAPITAL, S.A.ARES CAPITAL, S.A. was fined by the AEPD for requiring employees to use personal phones for work together with continuous monitoring apps. The authority found that the company did not provide sufficient information about data collection, breaching GDPR rules on lawful basis, transparency, and data processing principles.ESAEPDGDPR€200,000
08 Feb 2024AREIA CONSULTING, LTDAREIA CONSULTING, LTD was fined by the AEPD in the amount of 2,000 EUR for sending unsolicited commercial emails without prior recipient consent. The authority found this conduct breached Article 21 of the LSSI.ESAEPDePrivacy€2,000
12 Nov 2014Areacom s.r.l.Areacom s.r.l. was fined by the Garante 16,000 EUR for collecting personal data through its website without providing the required privacy notice. The breach concerned Article 13 of the Italian Data Protection Code.ITGaranteGDPR€16,000
17 Feb 2025ARCONADA 1932, S.L.ARCONADA 1932, S.L. did not properly handle a data subject request for access to and deletion of personal data. This breached Articles 15 and 17 of the GDPR, and the company was fined for failing to comply with the AEPD's resolution.ESAEPDGDPR€1,500
29 Mar 2018ARC Informazioni s.r.l.ARC Informazioni s.r.l. was fined 20,000 EUR by the Garante. The authority found that the company failed to notify data processing activities as required by the Italian Privacy Code.ITGaranteGDPR€20,000
18 Mar 2024Arbeids- og velferdsetaten (NAV)On 18.03.2024, Datatilsynet imposed a NOK 20 million administrative fine and additional orders on Arbeids- og velferdsetaten (NAV). The case concerned inadequate protection of confidentiality through access control and log monitoring, with several serious compliance deficiencies identified.NODatatilsynetGDPR€1,730,000
18 Mar 2024Arbeids- og velferdsetaten (NAV)The Norwegian DPA, Datatilsynet, fined NAV 20,000,000 NOK for inadequate confidentiality safeguards in access control and logging. The authority identified structural and organizational weaknesses in the protection of personal data.NODatatilsynetGDPR€1,730,000
28 Nov 2023Arbeids- og velferdsetaten (NAV)The Norwegian DPA has notified NAV of a planned 20 million NOK fine for serious information security deficiencies in its IT systems. The issues included inadequate access control and a lack of systematic log monitoring, which may have compromised the confidentiality of sensitive personal data.NODatatilsynetGDPR€1,707,000