Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
27 Nov 2025AMERICAN EXPRESS CARTE FRANCEOn 27 November 2025, CNIL fined AMERICAN EXPRESS CARTE FRANCE EUR 1.5 million for breaches of cookie and tracker rules. The authority found that trackers were placed without consent, despite refusal, and continued to be read after consent was withdrawn.FRCNILGDPR€1,500,000
10 Oct 2023American ExpressCNIL imposed a EUR 1,500,000 fine on American Express for placing cookies without prior user consent. The case concerns breaches of GDPR and privacy law requirements.FRCNILGDPR€1,500,000
30 Jul 2021Amendă pentru încălcarea RGPDA fine of EUR 100 was imposed on an individual for violating GDPR requirements. The case was handled by the Romanian supervisory authority ANSPDCP.ROANSPDCPGDPR€100
30 Jul 2021Amendă pentru încălcarea RGPDA fine of EUR 100 was imposed on an individual by ANSPDCP for violating GDPR requirements. The case concerned a confirmed breach of personal data protection obligations.ROANSPDCPGDPR€100
08 Jan 2026Amendă pentru încălcarea Legii nr. 506/2004 și a RGPDA fine of EUR 2,000 was imposed for violations of certain provisions of Law No. 506/2004 and the GDPR. The case concerns non-compliant personal data processing and privacy protection obligations.ROANSPDCPGDPR€2,000
25 Aug 2021Amendă în aplicarea Legii nr. 190/2018The operator was fined for failing to respond to the authority's requests during an investigation. The case concerns non-cooperation with ANSPDCP in the course of supervisory proceedings.ROANSPDCPGDPR€2,029
05 Jun 2024Ambitious People Group B.V.Ambitious People Group B.V. was fined by the AP EUR 6,000 for failing to handle data erasure requests submitted by three individuals within the required timeframe. The breach concerned GDPR Articles 17 and 12.NLAPGDPR€6,000
12 Dec 2024Ambiente 2000 S.r.l.Ambiente 2000 S.r.l. was fined EUR 20,000 by the Garante. The authority found that the company required employees to disclose passwords to their work email and files containing personal data, in breach of the GDPR.ITGaranteGDPR€20,000
26 Oct 2021AMAZON ROAD TRANSPORT SPAIN, S.LAmazon Road Transport Spain, S.L was fined 3,300,000 EUR by the AEPD for requiring job candidates to provide a criminal record certificate and consent for data transfers outside the EEA. The authority found that these practices breached GDPR and LOPDGDD rules on lawful processing and data transfer safeguards.ESAEPDGDPR€3,300,000
16 Nov 2023Amazon Italia Transport s.r.l.Amazon Italia Transport s.r.l. was fined €40,000 by the Garante for failing to respond to a former employee’s request for access to personal data. The authority found a breach of Article 15 GDPR.ITGaranteGDPR€40,000
01 Dec 2022Amazon Italia Logistica s.r.l.Amazon Italia Logistica s.r.l. was fined by the Garante for delaying its response to a data subject’s request to access professional certificates. The authority found a breach of Article 15 GDPR.ITGaranteGDPR€20,000
04 Oct 2023Amazon EuropeThe CNPD imposed a fine of EUR 746,000,000 on Amazon Europe for breaches of data protection rules. The case concerned shortcomings in the processing of personal data and compliance with GDPR requirements.LUCNPDGDPR€746,000,000
23 Nov 2017AMAT PALERMO S.P.A.AMAT PALERMO S.P.A. was fined by the Garante 20,000 EUR for failing to properly notify the use of a geolocation system to track vehicles. The authority found a breach of the Italian data protection code.ITGaranteGDPR€20,000
27 Apr 2023Ama S.p.a.Ama S.p.a. was fined €239,000 by the Garante for the unlawful processing and dissemination of personal health data concerning women who had terminated pregnancies. The identities were displayed on crosses at a cemetery, resulting in an unlawful disclosure of sensitive data.ITGaranteGDPR€239,000
02 Dec 2015A.M.A.M. Azienda Meridionale Acque Messina s.p.a.A.M.A.M. Azienda Meridionale Acque Messina s.p.a. was fined by the Garante for processing employees' biometric data without notification and without requesting prior verification. The authority found that the company breached data protection rules.ITGaranteGDPR€34,000
11 Feb 2020AMALFI SERVICIOS DE RESTAURACIÓN S.L.AMALFI SERVICIOS DE RESTAURACIÓN S.L. was fined by the AEPD 6,000 EUR for installing surveillance cameras without proper consent. The authority also found that the cameras captured images of public spaces without sufficient justification, breaching data protection rules.ESAEPDGDPR€6,000
01 Jan 2019AMADOR RECREATIVOS, S.L.AMADOR RECREATIVOS, S.L. was fined by the AEPD 6,000 EUR for installing a video surveillance system aimed at public space without justified cause. The case concerned an unjustified scope of monitoring and a breach of data protection rules.ESAEPDGDPR€6,000
13 Jun 2022AMADEUS IT GROUP, S.A.AMADEUS IT GROUP, S.A. was fined by the AEPD EUR 5,000 for failing to properly handle a data subject's requests to access and delete personal data. The authority found a breach of Article 12 GDPR because the company did not provide an adequate response.ESAEPDGDPR€5,000
01 Jan 2025AMADEUSAMADEUS was fined EUR 9,000,000 by the AEPD for breaching GDPR Articles 14 and 6. The authority found that the company failed to inform data subjects about the processing of their personal data.ESAEPDGDPR€9,000,000
09 Nov 2017A.M.A.CO. s.p.a.A.M.A.CO. s.p.a. was fined by the Garante for installing non-compliant video surveillance and geolocation systems on its vehicles. The authority found that these measures breached data protection rules.ITGaranteGDPR€22,400