Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
29 Jan 2015Abruzzo Vigilanza s.r.l.Abruzzo Vigilanza s.r.l. was fined €8,000 by the Garante for using a vehicle tracking system without the required notification. The case concerns non-compliance with data protection notification obligations.ITGaranteGDPR€8,000
19 Nov 2025About YouThe Hungarian Competition Authority (GVH) found that About You used misleading discount pricing and pressured consumers with countdown timers and scarcity messages. The company was ordered to pay HUF 505 million to the Hungarian central budget and to provide compensation to affected Hungarian customers.HUGazdasági VersenyhivatalOmnibus€1,323,000
03 Feb 2011Able Tech s.r.l.Able Tech s.r.l. was fined EUR 9,000 by the Garante for failing to provide timely information to the data subject. The breach concerned the obligation under Article 13 of the Italian Data Protection Code.ITGaranteGDPR€9,000
16 Mar 2017ABELHAS.PT LIMITEDABELHAS.PT LIMITED was fined EUR 5,000 by the AEPD for failing to provide the required information and procedures to reject data processing on its website. The authority found a breach of Article 22.2 of the LSSI.ESAEPDePrivacy€5,000
12 Apr 2018ABC OROLOGERIA E TELEFONIA S.r.l.ABC OROLOGERIA E TELEFONIA S.r.l. was fined by the Garante in the amount of 60,000 EUR for activating SIM cards without the express consent of the individuals to whom the cards were registered. The case concerns a breach of data protection rules.ITGaranteGDPR€60,000
04 Oct 2012Abbanoa s.p.a.Abbanoa s.p.a. was fined EUR 28,000 by the Garante for failing to provide the required privacy notice in its video surveillance systems. The authority found a breach of Article 13 of the Italian Privacy Code.ITGaranteGDPR€28,000
23 Mar 2021ABANCA CORPORACIÓN BANCARIA, S.A.ABANCA CORPORACIÓN BANCARIA, S.A. was fined EUR 5,000 by the AEPD for using cookies on its website without providing the required information to users or obtaining their consent. The case concerns failures to meet legal notice and consent requirements.ESAEPDePrivacy€5,000
20 Aug 2021A.A.A. (FRUTERIA)The entity was fined for operating a video surveillance system without the required signage informing individuals of its presence. The authority treated this as a breach of Article 13 GDPR on transparency and information duties.ESAEPDGDPR€1,000
24 Mar 2010A.A.A.A.A.A. was fined EUR 600 by the AEPD for sending unsolicited commercial emails without recipient consent. The company also failed to provide information on how to exercise the right of cancellation, breaching Article 21 of the LSSI.ESAEPDePrivacy€600
01 Mar 2017A.A.A.A.A.A. was fined €3,000 by the AEPD. The authority found that cookies were installed on its websites without prior information and consent, in breach of Article 22.2 of the LSSI.ESAEPDePrivacy€3,000
24 Mar 2023A.A.A.A.A.A. was fined EUR 300 by the AEPD for failing to provide adequate information about data processing in a video surveillance system. The authority found a breach of Article 13 GDPR because data subjects did not receive the required information.ESAEPDGDPR€300
31 Aug 2025A.A.A.A.A.A. was fined by the AEPD EUR 3,000 for using surveillance cameras in a tourist accommodation without a valid legal basis and without informing the individuals concerned. The authority found a breach of Article 6 of the GDPR.ESAEPDGDPR€3,000
01 Jul 2021A.A.A.The entity was fined by the AEPD 1,000 EUR for operating a video surveillance system without proper informational signage and customer information forms. The authority found this to be a breach of Article 13 of the GDPR.ESAEPDGDPR€1,000
01 Jan 2025A.A.A.A.A.A. failed to properly handle a data access request, which constitutes a breach of Article 15 GDPR. The AEPD imposed a fine of EUR 200, reduced to EUR 160 for early payment.ESAEPDGDPR€200
04 May 2010A.A.A.A.A.A. was fined by the AEPD EUR 600 for sending unsolicited commercial emails without the recipients’ consent. The conduct breached Article 21.1 of the LSSI, which governs electronic marketing communications.ESAEPDePrivacy€600
12 Jul 2021A.A.A.The entity was fined for processing personal data through a video surveillance system without appropriate security measures and without the required informational signage. The authority found a breach of Article 13 GDPR.ESAEPDGDPR€1,000
03 Mar 2022A.A.A.The entity was fined for operating a video surveillance system with cameras directed toward public areas without proper signage. This breached data protection rules and the information obligations owed to individuals being recorded.ESAEPDGDPR€600
08 Oct 2010A.A.A.A.A.A. was fined by the AEPD EUR 30,001 for sending unsolicited commercial emails. The case concerned continued email marketing despite a request to be removed from the mailing list, in breach of Article 21 of the LSSI.ESAEPDePrivacy€30,001
11 Jun 2024A.A.A.The municipality accessed and disclosed personal data without a legal basis, including full name, ID number, address, and financial details. The authority found a breach of Article 6 GDPR and imposed a EUR 500 fine.ESAEPDGDPR€500
19 Jul 2011A.A.A.A.A.A. was fined EUR 1,200 by the AEPD. The authority found that the entity sent unsolicited commercial emails without the recipient's prior consent, in breach of Article 21 of the LSSI.ESAEPDePrivacy€1,200