Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
14 Jul 2023GLOBAL TELECOMUNICACIONES INTERRECARGAS, S.L.The entity was fined 1,000 EUR by the AEPD for sending an advertising SMS without the recipient’s prior consent. This constituted a breach of Article 21 of the LSSI on unsolicited commercial communications.ESAEPDePrivacy€1,000
11 Nov 2011Galineio Melathro Private ClinicThe clinic disclosed sensitive personal data without informing the data subject in advance. This breached the individual's right to object to the processing.GRHDPAGDPR€1,000
28 Apr 2022Educationest s.r.l.Educationest s.r.l. was fined EUR 1,000 by the Italian data protection authority, Garante. The case concerned the unlawful disclosure of an employee’s pregnancy status to third parties via email, in breach of data protection rules.ITGaranteGDPR€1,000
01 Jan 2017SERVICIOS DE INFORMACIÓN SOBRE LOS FICHEROS DE MOROSOS S.L.The entity sent commercial emails and SMS without proper consent and did not honor recipients’ objections. These actions breached data protection rules.ESAEPDePrivacy€1,000
12 May 2022CIUDAUTO, S.L.CIUDAUTO, S.L. was fined by the AEPD EUR 1,000 for continuing to send advertising emails despite a request to unsubscribe. The authority found a breach of Article 21 of the LSSI.ESAEPDePrivacy€1,000
01 Jan 2015GROUPALIA COMPRA COLECTIVA, S.L.GROUPALIA COMPRA COLECTIVA, S.L. was fined by the AEPD 1,000 EUR for sending an unsolicited commercial email to a user who had previously requested to unsubscribe from such communications. The authority found a breach of Article 21.1 of the LSSI.ESAEPDePrivacy€1,000
21 Mar 2025Bucharest Down Town Hotel SRLThe National Supervisory Authority for Personal Data Processing fined Bucharest Down Town Hotel SRL for GDPR violations following a complaint. The case concerned non-compliant processing of personal data.ROANSPDCPGDPR€1,000
24 Nov 2022dott.ssa Emilia ColosimoThe Garante imposed a EUR 1,000 fine on dott.ssa Emilia Colosimo for breaches of the principles of lawful, fair and transparent processing of personal data, data minimization, and data security. The authority also cited insufficient safeguards against unauthorized or unlawful processing.ITGaranteGDPR€1,000
14 Sept 2018IAHORRO BUSINESS SOLUTIONS SLIAHORRO BUSINESS SOLUTIONS SL was fined by the AEPD €1,000 for sending unsolicited commercial electronic communications. The company also failed to provide a procedure for exercising rights of access, rectification, cancellation, or objection.ESAEPDePrivacy€1,000
26 Sept 2022ECOMM MOVADGENCY S.L.ECOMM MOVADGENCY S.L. was fined by the AEPD for sending commercial communications without the recipient’s consent. The company continued sending emails despite the recipient’s objection, which breached Article 21 GDPR.ESAEPDGDPR€1,000
29 Apr 2021CRIQUET PUBLICIDAD, S.L.CRIQUET PUBLICIDAD, S.L. was fined by the AEPD in the amount of 1,000 EUR for sending unsolicited commercial emails. The recipient’s address was registered on the Robinson List, which constitutes a breach of Article 21.1 of the LSSI.ESAEPDePrivacy€1,000
11 Nov 2021Comune di Varano BorghiComune di Varano Borghi was fined EUR 1,000 by the Garante for unlawfully publishing personal data online. The authority found a breach of GDPR principles of data minimization and transparency.ITGaranteGDPR€1,000
07 Jul 2022E Software Concept SRLE Software Concept SRL was fined EUR 1,000 by ANSPDCP. The sanction was imposed for failing to provide requested information to the supervisory authority.ROANSPDCPGDPR€1,000
23 May 2024Green Land African MinimarketThe Garante fined Green Land African Minimarket EUR 1,000 for improper use of a video surveillance system. The system captured areas beyond the company's premises and recorded employees without meeting the required legal conditions.ITGaranteGDPR€1,000
08 Dec 2025Compania de Apă Oltenia S.A.The company was fined EUR 1,000 by ANSPDCP after an employee disclosed personal data on a social network. The case was initiated following a complaint from the data subject.ROANSPDCPGDPR€1,000
10 Aug 2015Anonymised (HDPA 95/2015)A fine was imposed on the residential complex “Lofos Edison” for installing additional surveillance cameras without authorization. The authority also noted that the installation was not properly notified to the competent authority.GRHDPAGDPR€1,000
22 Mar 2018ARGOINFOR S.L.ARGOINFOR S.L. was fined by the AEPD in the amount of 1,000 EUR. The case concerned the sending of unsolicited commercial emails, which breaches Article 21 of the LSSI.ESAEPDePrivacy€1,000
28 Apr 2026vzwDecision on the merits No. 94/2026 of 28 April 2026 was issued by the Belgian Gegevensbeschermingsautoriteit. A Belgian vzw was fined EUR 1,000 for failing to respond to registered letters and failing to appear at the hearing, which was treated as a breach of the GDPR cooperation duty.BEGegevensbeschermingsautoriteit (GBA)GDPR€1,000
09 Jun 2023UNIÓN DE RADIOS LIBRES Y COMUNITARIAS DE MADRIDThe entity did not comply with a data protection authority resolution concerning the right to erasure. As a result, AEPD imposed a fine for breaching Article 58.2 of the GDPR.ESAEPDGDPR€1,000
04 Jan 2022BEAUTY & AESTHETIC BALEARIC, SL.BEAUTY & AESTHETIC BALEARIC, SL. was fined by the AEPD €1,000 for sending marketing emails without an opt-out mechanism. The authority found this to be a breach of Article 21 of the LSSI.ESAEPDePrivacy€1,000