Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
03 Sept 2025AENA, S.M.E., S.A.The AEPD imposed a fine of EUR 10,043,002 on AENA, S.M.E., S.A. for processing passenger personal data in a manner deemed unnecessary and disproportionate. The authority found that the company’s practices breached data protection rules.ESAEPDGDPR€10,043,000
22 Jun 2016Aemme Car S.r.l.Aemme Car S.r.l. was fined by the Garante in the amount of 2,400 EUR for collecting personal data through its website without providing users with the required information notice. This conduct breached the Italian data protection code.ITGaranteGDPR€2,400
12 Feb 2020AEMA HISPANICA, S.L.AEMA HISPANICA, S.L. was fined by the AEPD 6,000 EUR for sending one employee's payroll to another employee. The incident constituted a breach of data protection rules.ESAEPDGDPR€6,000
08 Nov 2024AECORP 005, S.L.AECORP 005, S.L. was fined EUR 6,000 by the AEPD for failing to provide access to information requested during an investigation. The authority found a breach of Article 58.1 GDPR.ESAEPDGDPR€6,000
13 Feb 2025ADVFAST s.r.l.s.ADVFAST s.r.l.s. was fined by the Garante for failing to respond to information requests concerning repeated unsolicited telemarketing calls. The case indicates a failure to cooperate with the supervisory authority.ITGaranteGDPR€2,000
13 Jan 2022ADVANS BROKERS CORREDURIA DE SEGUROS S.L.ADVANS BROKERS CORREDURIA DE SEGUROS S.L. was fined by the AEPD EUR 80,000 for a data breach affecting 55,000 individuals, including minors. The authority found that the incident was reported to the AEPD with delay.ESAEPDGDPR€80,000
26 Mar 2025Advanced Computer Software Group LimitedThe UK Information Commissioner's Office fined Advanced Computer Software Group Limited, Advanced Health and Care Limited, and Aston Midco Limited a total of £3,076,320. The penalty related to serious UK GDPR Article 32(1) security failings linked to a ransomware attack and data breach affecting healthcare services.GBInformation Commissioner's OfficeGDPR€3,678,000
26 Mar 2025Advanced Computer Software Group LimitedThe UK Information Commissioner’s Office (ICO) fined Advanced Computer Software Group Limited £3,070,000 for security failings. The issues put the personal information of 79,404 people at risk. The case highlights inadequate safeguards over processed personal data.GBICOGDPR€3,671,000
12 Sept 2025A Düsseldorf-based personnel recruitment companyOn 2025-09-12, the LDI NRW announced a data protection fine of over 35,000 EUR against a Düsseldorf-based personnel recruitment company. The authority said the company repeatedly ignored job seekers’ requests for access and deletion and failed to respond to the supervisory authority’s inquiries.DELandesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-WestfalenGDPR€35,000
11 Apr 2019AD Sphera Group s.r.l.AD Sphera Group s.r.l. was fined EUR 2,400 by the Garante for failing to provide the required privacy notice on its website. The breach concerned Article 13 of the Italian Data Protection Code.ITGaranteGDPR€2,400
22 Jun 2017Adsalsa Italia Publicidad SucursalAdsalsa Italia Publicidad Sucursal was fined EUR 20,000 by the Garante. The authority found that personal data were processed without obtaining separate consent for each purpose, in breach of data protection rules.ITGaranteGDPR€20,000
01 Jan 2017A DOS RUEDAS EN LA RED, SLA DOS RUEDAS EN LA RED, SL was fined EUR 2,200 by the AEPD for sending unsolicited commercial emails. The conduct breached Article 21 of the LSSI, which restricts marketing communications without prior consent.ESAEPDePrivacy€2,200
22 May 2018Adolfo AllegriniAdolfo Allegrini, a general practitioner, was fined for failing to implement minimum security measures to protect personal and sensitive data. This allowed unauthorized access to the healthcare system.ITGaranteGDPR€10,000
09 Apr 2024ADNAYA GREEN SOLUTIONS, S.L.ADNAYA GREEN SOLUTIONS, S.L. was fined by the AEPD EUR 10,000 for unlawfully sharing personal data with a third party without consent. The authority found this conduct breached Article 6(1) of the GDPR.ESAEPDGDPR€10,000
21 Jun 2024ADMINISTRACIONES BENIPON, S.L.ADMINISTRACIONES BENIPON, S.L. was fined 2,200 EUR by the AEPD for failing to provide access to information as required under Article 58(1) GDPR. The case concerns non-compliance with the supervisory authority’s information access requirements.ESAEPDGDPR€2,200
09 Oct 2025AD Media S.r.l.AD Media S.r.l. was fined EUR 5,000 by the Garante for sending promotional emails without proper consent. The authority found a breach of the principles of lawfulness, fairness, and transparency in data processing.ITGaranteGDPR€5,000
06 Jul 2023Ad Maiora Distribuzioni S.a.s. di Editrice Ad Maiora S.r.l.s. & C.Ad Maiora Distribuzioni was fined EUR 15,000 by the Garante. The authority found that the company made unsolicited promotional calls and failed to respond to requests for access to and deletion of personal data.ITGaranteGDPR€15,000
01 Jan 2018ADGOALS MEDIA S.L.ADGOALS MEDIA S.L. was fined by the AEPD in the amount of 1,500 EUR for sending unsolicited SMS advertisements without prior recipient consent. The authority also found that no opt-out mechanism was provided, which constitutes a breach of Article 21 of the LSSI.ESAEPDePrivacy€1,500
27 Apr 2023ADENET SYSTEMS, S.L.ADENET SYSTEMS, S.L. was fined EUR 6,000 by the AEPD for failing to provide access. The authority treated this as a breach of Article 58(1) GDPR and an obstruction of its investigative functions.ESAEPDGDPR€6,000
15 Sept 2022ADENET SYSTEMS, S.L.ADENET SYSTEMS, S.L. was fined by the AEPD for obstructing the data protection authority’s inspection. The conduct breached Article 58(1) GDPR.ESAEPDGDPR€3,000