Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
24 Feb 2010ADEC Assistenza dentistica e cure odontoiatriche-ortodontiche s.r.l.ADEC Assistenza dentistica e cure odontoiatriche-ortodontiche s.r.l. was fined 6,000 EUR by the Garante. The authority found that personal data were processed through the website contact form without the required information notice, in breach of Article 13 of the Italian Data Protection Code.ITGaranteGDPR€6,000
02 Oct 2014Addressvitt s.r.l.Addressvitt s.r.l. was fined by the Garante in the amount of EUR 130,000 for processing personal data without providing adequate information or obtaining consent. The case also involved data taken from public telephone directories and used without proper authorization.ITGaranteGDPR€130,000
25 Feb 2020Addiko Bank d.d.The High Administrative Court of the Republic of Croatia upheld AZOP’s decision of 25 February 2020 against Addiko Bank d.d. The confirmed administrative fine was 145,995.09 EUR for obstructing customers’ access to their personal data and credit documentation.HRAZOPGDPR€145,000
01 Dec 2016Adda Gestioni Industriali e Mobiliari s.p.a.Adda Gestioni Industriali e Mobiliari S.p.a. was fined by the Garante 2,400 EUR for improper data processing through a video surveillance system. The authority found that adequate notices were not provided for external cameras monitoring the parking area.ITGaranteGDPR€2,400
27 Feb 2023Adatkezelési tájékoztatás átláthatóságaThe entity did not provide data subjects with transparent and accurate information about the purposes and legal bases of processing. This breached GDPR Articles 6, 12, and 13, and the authority imposed a fine of HUF 1,000,000.HUNAIHGDPR€2,630
08 Apr 2025Adatbiztonsági problémák ügyféladatbázis adatfeldolgozó általi költöztetése soránThe authority found that Ügyfél1 failed to implement appropriate security measures when processing data during the database migration. This breach of GDPR Article 32 resulted in a fine of 2,000,000 HUF.HUNAIHGDPR€4,920
24 Jan 2020Adatbiztonsági intézkedések és incidenskezelési gyakorlat hiányosságaiThe entity failed to implement appropriate technical and organizational measures to protect data, including storing access data in printed form. Its internal incident management policy also did not regulate the obligation to notify the supervisory authority.HUNAIHGDPR€1,490
02 Aug 2023Adatbázisban tárolt személyes adatok kezelésének jogszerűségeThe entity was fined by NAIH HUF 1,500,000 for processing personal data without a legal basis. The authority also found that the entity failed to demonstrate compliance with data processing requirements and did not provide adequate information to data subjects.HUNAIHGDPR€3,870
01 Jan 2022ADADE BURGOS, S.L.ADADE BURGOS, S.L. was fined by the AEPD EUR 5,000 for improper use of personal data. The company informed clients about an employee's disciplinary dismissal, which breached data protection rules.ESAEPDGDPR€5,000
08 Feb 2024ADADE BURGOS, S.L.ADADE BURGOS, S.L. was fined by the AEPD 5,000 EUR for improper use of personal data. The company informed clients about an employee’s disciplinary dismissal in a manner that breached data protection rules.ESAEPDGDPR€5,000
26 Nov 2024AD735 DATA MEDIA ADVERTISING, S.L.AD735 DATA MEDIA ADVERTISING, S.L. was fined by the AEPD EUR 10,000 for sending unsolicited advertising emails. The messages were sent despite the recipient's unsubscribe request and inclusion on the Robinson list, breaching the LSSI.ESAEPDePrivacy€10,000
01 Jan 2024AD735 DATA MEDIA ADVERTISING, S.L.AD735 DATA MEDIA ADVERTISING, S.L. was fined by the AEPD 2,000 EUR for improperly accessing personal data linked to a phone number without the owner's consent. The authority found a breach of Article 7 of the GDPR.ESAEPDGDPR€2,000
11 Feb 2025AD735 DATA MEDIA ADVERTISING, S.L.AD735 DATA MEDIA ADVERTISING, S.L. was fined by the AEPD 10,000 EUR for sending unsolicited email messages and failing to properly handle unsubscribe requests. The conduct breached Article 21 of the LSSI.ESAEPDePrivacy€10,000
01 Jan 2021AD735 DATA MEDIA ADVERTISING S.L.AD735 DATA MEDIA ADVERTISING S.L. was fined €3,000 by the AEPD for failing to comply with information requests. The case concerned Article 58(1) GDPR and the duty to cooperate with the supervisory authority.ESAEPDGDPR€3,000
04 Oct 2021AD735 DATA MEDIA ADVERTISING S.L.The entity was fined by the AEPD for breaching data protection rules. It continued sending commercial emails despite repeated requests from the complainant to delete their data.ESAEPDePrivacy€6,000
23 Aug 2021AD735 DATA MEDIA ADVERTISING S.L.AD735 DATA MEDIA ADVERTISING S.L. was fined EUR 15,000 by the AEPD for failing to comply with a resolution concerning the right of access. The authority cited a breach of Article 83(6) GDPR.ESAEPDGDPR€15,000
19 Apr 2021AD735 DATA MEDIA ADVERTISING S.L.AD735 DATA MEDIA ADVERTISING S.L. was fined EUR 15,000 by the AEPD. The authority found that the company failed to comply with a data subject's right to erasure and sent commercial communications without the recipient's explicit consent.ESAEPDePrivacy€15,000
01 Jan 2024ACTIVOS INTELIGENTES, S.L.ACTIVOS INTELIGENTES, S.L. was fined by the AEPD 5,000 EUR for requiring guests to submit selfies with their ID cards during check-in. The authority found the data collection excessive and not properly justified or explained in terms of processing purposes.ESAEPDGDPR€5,000
24 Jan 2024ACTIVITE DE COMMERCE DE GROS PHARMACEUTIQUES (procédure simplifiée)The CNIL imposed an administrative fine of EUR 20,000 on ACTIVITE DE COMMERCE DE GROS PHARMACEUTIQUES. The case was handled under a simplified procedure.FRCNILGDPR€20,000
19 Jul 2018Active Network S.p.a.Active Network S.p.a. was fined by the Garante 20,000 EUR for retaining telematic traffic data for more than 12 months. The authority found that this practice breached data protection rules in the context of crime detection and repression.ITGaranteGDPR€20,000