Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
14 Apr 2021ANIVERSALIA NETWORKS, S.L.ANIVERSALIA NETWORKS, S.L. was fined by the AEPD EUR 2,000 for not having a GDPR-compliant privacy policy on its website. In particular, it failed to provide contact details for exercising data subject rights.ESAEPDGDPR€2,000
01 Jan 2022ANIVERSALIA NETWORKS, S.L.ANIVERSALIA NETWORKS, S.L. was fined €2,000 by the AEPD. The authority found that the website did not provide adequate contact information for individuals to exercise their data protection rights.ESAEPDGDPR€2,000
09 Jun 2016Angela BellavitaAngela Bellavita was fined EUR 2,400 by the Italian Garante. The case concerned the collection of personal data, including name, surname, and email address, through a website contact form without providing users with adequate information.ITGaranteGDPR€2,400
28 Oct 2021Anfiteatro Flavio s.r.l.Anfiteatro Flavio s.r.l. was fined EUR 2,000 by the Garante for operating a video surveillance system without the required privacy notice. The authority found a breach of Article 13 of the GDPR.ITGaranteGDPR€2,000
20 Nov 2014Andrea Romualdo CerriAndrea Romualdo Cerri was fined €2,400 by the Garante. The violation concerned failing to provide the required information to data subjects when collecting personal data through a web form on the company website.ITGaranteGDPR€2,400
19 Feb 2015Andrea AngeloniAndrea Angeloni was fined by the Garante for sending unsolicited promotional letters. The entity also failed to respond to information requests from the supervisory authority.ITGaranteGDPR€10,000
12 Feb 2026Anconambiente S.P.A.Anconambiente S.P.A. was fined by the Garante for failing to ensure that personal data processing was lawful, fair, and transparent. The authority also found that the company did not have a proper contract with a data processor, as required by Article 28 GDPR.ITGaranteGDPR€2,500
18 Oct 2022a natural personA natural person was fined EUR 150 by ANSPDCP for violating the General Data Protection Regulation. The case concerned a breach of GDPR requirements.ROANSPDCPGDPR€150
18 Apr 2018Anas S.p.A.Anas S.p.A. was fined by the Garante in the amount of 20,000 EUR for failing to designate employees as data processors and for not issuing instructions on the proper use of surveillance and geolocation systems. The authority found that these omissions breached data protection rules.ITGaranteGDPR€20,000
16 May 2019ANANEOSI MONOPROSOPI E.P.E.The company was fined for making unsolicited marketing calls to subscribers registered on the opt-out list. It also failed to properly identify itself during the calls, which hindered data subjects’ ability to exercise their rights.GRHDPAePrivacy€5,000
20 Aug 2024Ana Hotels SRLAna Hotels SRL was fined by ANSPDCP €8,000 after a data security incident caused by a ransomware attack. The incident led to unauthorized disclosure of personal data belonging to a significant number of employees.ROANSPDCPGDPR€8,000
11 Aug 2022AMPLIFON Magyarország Kereskedelmi és Szolgáltató Korlátolt Felelősségű TársaságAMPLIFON Magyarország was fined by the NAIH 80,000,000 HUF for processing personal data for market research without proper notice to data subjects, without a specific and legitimate purpose, and without a valid legal basis. The authority found that the company’s conduct breached core GDPR principles.HUNAIHGDPRFt 80,000,000
15 Mar 2012Ammiro Partners s.r.l.Ammiro Partners s.r.l. was fined for violations related to the processing of personal data. The authority cited failure to comply with a prior injunction and failure to respond to requests from the Garante.ITGaranteGDPR€250,000
08 Oct 2015Amministrazione provinciale di PordenoneAmministrazione provinciale di Pordenone was fined 4,000 EUR by the Garante. The authority found that the annual Security Programmatic Document was not updated by the required deadline, breaching data protection rules.ITGaranteGDPR€4,000
09 May 2018Amiu S.p.a.Amiu S.p.a. was fined by the Garante 20,000 EUR for improper processing of personal data through its video surveillance systems. The authority found that the company failed to properly designate data processing personnel and to implement adequate data protection measures.ITGaranteGDPR€20,000
28 Apr 2022Amiu s.p.a.Amiu s.p.a. was fined EUR 20,000 by the Italian supervisory authority, Garante. The case concerned breaches of lawfulness, fairness, transparency, and purpose limitation in the improper use of surveillance cameras in waste management services.ITGaranteGDPR€20,000
21 Sept 2017AMI S.p.A.AMI S.p.A. was fined by the Garante for installing electronic monitoring and localization devices on public transport vehicles without proper notification. The authority found this to be a breach of data protection rules.ITGaranteGDPR€40,000
16 Feb 2012Amiat s.p.a.Amiat s.p.a. was fined EUR 30,000 by the Garante for failing to designate Allsystems s.p.a. as a data processor and for not providing the necessary instructions. The authority found that the company did not adopt the minimum security measures required for data processing.ITGaranteGDPR€30,000
04 Oct 2012American Express Services Europe LimitedAmerican Express Services Europe Limited was fined by the Garante EUR 40,000 for making promotional calls without the data subject's consent. The case concerns a breach of privacy rules governing telephone marketing.ITGaranteGDPR€40,000
21 Feb 2013American Express Services Europe LimitedAmerican Express Services Europe Limited was fined EUR 60,000 by the Garante. The authority found that the security program document was not updated in line with the technical rules on minimum security measures.ITGaranteGDPR€60,000