Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
29 Sept 2011Agenzia per le erogazioni in agricoltura (AGEA)The Italian Data Protection Authority fined Agenzia per le erogazioni in agricoltura (AGEA) EUR 40,000 for violations related to the processing of personal data within the National Agricultural Information System (Sian). The case concerned compliance of the processing activities with personal data protection requirements.ITGaranteGDPR€40,000
10 Apr 2025Agenzia Mobilità Ambiente e Territorio S.r.l.The Garante fined Agenzia Mobilità Ambiente e Territorio S.r.l. 9,000 EUR for failing to provide sufficient transparency to data subjects. The authority found a breach of the GDPR principles of lawfulness, fairness, and transparency.ITGaranteGDPR€9,000
11 Dec 2008agenzia funebre floricoltura Rampura di Loi AlessandroThe funeral agency was fined by the Garante for providing clients with inadequate information. The authority found this to be a breach of data protection rules.ITGaranteGDPR€3,000
21 May 2025Agenzia di Tutela della Salute, della Città Metropolitana di Milano, Servizio Prevenzione e Sicurezza Ambienti di Lavoro Milano Città NordAgenzia di Tutela della Salute was fined EUR 7,000 by the Garante for improperly sending medical reports and certificates. The authority found a breach of data protection rules.ITGaranteGDPR€7,000
13 May 2021Agenzia di Tutela della Salute della Città metropolitana di MilanoAgenzia di Tutela della Salute della Città metropolitana di Milano was fined by the Garante 80,000 EUR for violations linked to data processing during an emergency. The authority found inadequate data protection measures and a failure to provide required information to data subjects.ITGaranteGDPR€80,000
27 Jan 2016Agenzia di promozione economica della ToscanaAgenzia di promozione economica della Toscana was fined 10,000 EUR by the Garante for publishing lists of disabled candidates admitted to competitive exams on its institutional websites. The authority found that this disclosure breached data protection rules.ITGaranteGDPR€10,000
12 Dec 2024Agenzia delle Dogane e dei MonopoliAgenzia delle Dogane e dei Monopoli was fined by the Garante in the amount of EUR 40,000 for violations related to data processing. The case concerned non-compliance with Art. 2-ter of the Italian Data Protection Code.ITGaranteGDPR€40,000
07 Mar 2019Agenzia delle Dogane e dei MonopoliAgenzia delle Dogane e dei Monopoli was fined for unlawfully processing judicial data by communicating information about an ongoing criminal proceeding without a legal basis. The case concerned a breach of the rules governing the lawful processing of sensitive data.ITGaranteGDPR€10,000
22 Oct 2025Agency for Control of Outstanding Debts S.R.L.The company was fined EUR 2,000 by ANSPDCP for breaching multiple GDPR provisions. The case followed a complaint alleging deficiencies in personal data protection compliance.ROANSPDCPGDPR€2,000
12 Dec 2024AGENCE DE COMMUNICATION ET DE PRODUCTION AUDIOVISUELLE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 6,000 on AGENCE DE COMMUNICATION ET DE PRODUCTION AUDIOVISUELLE under a simplified procedure. The case concerns a confirmed breach of rules supervised by the CNIL.FRCNILGDPR€6,000
30 Dec 2022A&G Couriers Limited T/A Fastway Couriers (Ireland)The Irish DPC fined A&G Couriers Limited T/A Fastway Couriers (Ireland) 15,000 EUR in inquiry IN-21-6-2. The penalty has been collected.IEDPCGDPR€15,000
30 May 2025AG-BROKER ASIGURARE S.R.L.AG-BROKER ASIGURARE S.R.L. was fined 5,000 EUR by ANSPDCP. The sanction concerned the failure to notify a personal data security breach.ROANSPDCPGDPR€5,000
07 Sept 2011Aga s.r.l.Aga s.r.l. was fined EUR 8,000 by the Garante for processing online customers' personal data without ensuring freely given and specific consent. The authority found this to be a breach of data protection rules.ITGaranteGDPR€8,000
15 Oct 2024AFP GESTION DEL COLOR, S.L.AFP GESTION DEL COLOR, S.L. was fined by the AEPD in the amount of €1,000 for sending unsolicited commercial emails. The conduct breached Article 21.1 of the LSSI, which prohibits marketing communications without prior consent.ESAEPDePrivacy€1,000
27 Mar 2025AFK Letters Co LtdBetween January and September 2023, AFK Letters Co Ltd made 95,277 spam calls, leading to multiple complaints to the ICO and TPS. The company did not provide evidence that the called numbers had consented to receiving calls. The ICO imposed a £90,000 fine.GBICOGDPR€108,000
09 Mar 2023Aesse S.r.l.s.Aesse S.r.l.s. was fined by the Italian Garante in the amount of €3,000. The case concerned unsolicited telemarketing calls made without consent and insufficient information provided about the source of personal data.ITGaranteGDPR€3,000
17 Jan 2008Aesculapius s.r.l.Aesculapius s.r.l. was fined by the Garante for missing the deadline to notify personal data processing activities. The breach concerned obligations under the Italian Data Protection Code.ITGaranteGDPR€10,000
10 Jun 2021Aeroporto Guglielmo Marconi di Bologna S.p.a.Aeroporto Guglielmo Marconi di Bologna S.p.a. was fined by the Garante EUR 40,000 for violations related to the protection of whistleblower identities. The case indicates insufficient personal data safeguards in the handling of reports.ITGaranteGDPR€40,000
20 Oct 2015AEROCLUB DEL SOLAEROCLUB DEL SOL was fined EUR 600 by the AEPD for sending unsolicited emails advertising airplane insurance. The authority found this breached Article 21.1 of the LSSI on commercial communications without prior consent.ESAEPDePrivacy€600
12 May 2021A. EPILOGI IDIOTIKI KEFALAIOUCHIKI ETAIREIAThe company was fined by the HDPA 5,000 EUR for sending unsolicited promotional emails without consent. The authority also found that it failed to respond to data subject access requests and did not provide a valid opt-out address for communications.GRHDPAGDPR€5,000