Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
10 Apr 2025Aliseo s.r.l.Aliseo s.r.l. was fined by the Garante for operating a video surveillance system without proper notice and for monitoring employees, including audio recording. The authority found the monitoring disproportionate to the stated security purpose.ITGaranteGDPR€5,000
14 Aug 2025ALIQUAM SOFTWARE DEVELOPMENT, S.R.L.UALIQUAM SOFTWARE DEVELOPMENT, S.R.L.U was fined by the AEPD 1,400 EUR for sending unsolicited marketing emails despite requests to stop. The case concerns a breach of the LSSI rules on commercial communications.ESAEPDePrivacy€1,400
12 Jan 2024Alior Bank SA Varșovia Sucursala BucureștiAlior Bank SA, through its Romanian branch, was fined EUR 17,000 by ANSPDCP. The sanction followed an investigation that identified GDPR violations.ROANSPDCPGDPR€17,000
15 Mar 2023Alianța pentru Unirea RomânilorThe fine was imposed for collecting personal data through a website without informing the data subjects and without meeting the conditions for lawful processing. The breach affected a significant number of individuals and indicates non-compliance with basic transparency and legality requirements.ROANSPDCPGDPR€10,000
18 Feb 2026ALÍA GESTIÓN INTEGRAL DE SERVICIOS, S.L.ALÍA GESTIÓN INTEGRAL DE SERVICIOS, S.L. was fined EUR 250,000 by the AEPD for a data protection breach. The incident involved unauthorized access to the internal network after VPN credentials were compromised.ESAEPDGDPR€250,000
21 Jan 2016Alfonso EspositoAlfonso Esposito, a gynecologist, was fined by the Garante for processing clients’ personal data for medical purposes without obtaining their consent. The authority found this to be a breach of the Italian Data Protection Code.ITGaranteGDPR€10,000
29 Apr 2021Alfa Shipyard s.r.l.Alfa Shipyard s.r.l. was fined by the Garante in the amount of €5,000 for failing to respond to a data subject's request for information. The authority found this to be a breach of GDPR obligations.ITGaranteGDPR€5,000
24 Mar 2021Ålesund kommuneÅlesund kommune was fined by Datatilsynet for using the Strava app in schools without conducting a risk assessment. As a result, students’ personal data was processed without adequate controls and safeguards.NODatatilsynetGDPR€4,923
22 May 2018Alessandro SabatiniAlessandro Sabatini, a general practitioner, was fined EUR 10,000 by the Garante. The authority found that minimum personal data security measures were not implemented, which allowed unauthorized access to a health information system.ITGaranteGDPR€10,000
02 Apr 2015Ales Groupe Italia S.p.A.Ales Groupe Italia S.p.A. was fined EUR 20,000 by the Garante for violations related to data processing on its website. Users were asked to provide personal data without proper consent mechanisms.ITGaranteGDPR€20,000
02 Dec 2020Aleris Sjukvård ABAleris Sjukvård AB was fined by IMY for failing to conduct a needs and risk analysis before granting access rights in its TakeCare journal system. The authority found this breached GDPR security requirements.SEIMYGDPR€1,458,000
02 Dec 2020Aleris Närsjukvård ABAleris Närsjukvård AB was fined by IMY for failing to conduct a needs and risk analysis before granting access rights in its medical record systems. The authority found this breached GDPR data security requirements.SEIMYGDPR€1,167,000
02 Jul 2024ALDI MAGYARORSZÁG ÉLELMISZER Élelmiszer Kereskedelmi Betéti TársaságALDI Magyarország was fined by the NAIH 80,000,000 HUF for failing to ensure transparency in data processing related to the purchase of alcoholic beverages. The authority found breaches of GDPR transparency and data minimization principles.HUNAIHGDPR€202,000
02 Jul 2024ALDI MAGYARORSZÁG ÉLELMISZER Élelmiszer Kereskedelmi Betéti TársaságNAIH imposed a HUF 95,000,000 fine on ALDI Magyarország for GDPR violations linked to data processing during alcohol purchases. The authority cited improper age verification and insufficient personal data protection measures.HUNAIHGDPR€240,000
01 Jan 2015ALDA GLOBAL SERVICES, S.L.ALDA GLOBAL SERVICES, S.L. was fined EUR 600 by the AEPD. The case concerned sending unsolicited commercial communications by SMS without consent, in breach of Article 21.1 of the LSSI.ESAEPDePrivacy€600
01 May 2025ALBOR ENERGÍA S.L.ALBOR ENERGÍA S.L. was fined by the AEPD in the amount of 20,000 EUR for a data protection breach. The case concerned unauthorized subcontracting without informing the responsible party, as required by Article 28 of the GDPR.ESAEPDGDPR€20,000
27 Sept 2022ALBERO FORTE COMPOSITE, S.L.The company used employees’ facial images for clocking in and out without proper notice about biometric data processing. AEPD found this to be a breach of data protection rules and imposed a 20,000 EUR fine.ESAEPDGDPR€20,000
16 Jul 2023ALBEN AIRPORT FACILITIES S.L.ALBEN AIRPORT FACILITIES S.L. was fined 500 EUR by the AEPD for failing to provide access to information required under Article 58.1 of the GDPR. This obstructed the data protection authority’s supervisory and investigative functions.ESAEPDGDPR€500
04 Mar 2021ALAVA NORTE, S.L.ALAVA NORTE, S.L. was fined by the AEPD in the amount of 4,000 EUR for installing surveillance cameras without sufficient justification. The cameras captured both public and private spaces, which breached data protection principles.ESAEPDGDPR€4,000
24 Feb 2010Alampi Carmela & C. s.n.c. di Sapone GiovannaThe company was fined for processing personal data through a video surveillance system without providing the required simplified and detailed information to data subjects. This constituted a breach of Article 13 of the Italian Data Protection Code.ITGaranteGDPR€6,000