Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
10 Jul 2025Comune di LanghiranoThe Municipality of Langhirano was fined by the Garante for the unauthorized disclosure of personal data on its institutional website. The data was removed, but the authority imposed a monetary penalty of EUR 12,000.ITGaranteGDPR€12,000
10 Jul 2025Asilo nido “La Combricola Dei Birichini Di Betty”The Garante imposed a 10,000 EUR fine on the nursery for failing to provide parents with the required information about the processing of children's images. It also found that no data protection impact assessment had been carried out for the surveillance system.ITGaranteGDPR€10,000
10 Jul 2025Istituto Comprensivo 2 C.D.The Garante fined Istituto Comprensivo 2 C.D. EUR 4,000 for breaches of data protection rules. The authority cited non-compliance with the principles of lawfulness, fairness, and transparency in the processing of personal data.ITGaranteGDPR€4,000
10 Jul 2025Cooperativa Sociale CoopseliosCooperativa Sociale Coopselios was fined by the Garante €10,000 for failing to properly handle data subject requests. The нарушения concerned the GDPR rights of access, rectification, and data portability.ITGaranteGDPR€10,000
10 Jul 2025Magna PT S.p.A.Magna PT S.p.A. was fined EUR 50,000 by the Garante for requiring employees to complete a questionnaire after absences due to illness. The authority found that this practice breached GDPR rules on the processing of personal data.ITGaranteGDPR€50,000
10 Jul 2025Banco Bilbao Vizcaya Argentaria SABanco Bilbao Vizcaya Argentaria SA was fined by the Italian authority Garante in the amount of €100,000. The case concerned an inadequate response to a data access request linked to a fraud incident, which breached Article 15 of the GDPR.ITGaranteGDPR€100,000
10 Jul 2025dottoressa Monica Maria FerrariThe doctor was fined for recording conversations with a patient during a specialist visit without proper consent. The authority also found a failure to provide required information, breaching transparency and information obligations.ITGaranteGDPR€7,000
10 Jul 2025Università degli Studi di Cassino e del Lazio MeridionaleThe University of Cassino and Southern Lazio was fined €8,000 by the Garante for failing to comply with data protection rules. The case concerned improper handling of personal data requests and deficiencies in administrative procedures.ITGaranteGDPR€8,000
10 Jul 2025Centro Medico Italiano S.r.l.Centro Medico Italiano S.r.l. was fined by the Garante 30,000 EUR for failing to provide an adequate response to a data subject’s request for access to health data and information about its processing. The authority found a breach of GDPR Article 15.ITGaranteGDPR€30,000
10 Jul 2025Outly di Veneziani & Co s.r.l.The Garante fined Outly di Veneziani & Co s.r.l. EUR 15,000 for insufficient transparency when obtaining consent and for inadequate information on data retention periods. The issues affected all interested parties and potential customers.ITGaranteGDPR€15,000
10 Jul 2025Comune di ConversanoComune di Conversano was fined €3,000 by the Garante for failing to communicate the contact details of its Data Protection Officer. The breach concerned the obligation under Article 37 GDPR to notify the supervisory authority.ITGaranteGDPR€3,000
09 Jul 2025KAFFA KOFFEE ORGANISATION, S.L.KAFFA KOFFEE ORGANISATION, S.L. was fined EUR 900 by the AEPD for failing to implement appropriate technical and organizational measures. The deficiency led to email addresses being visible to multiple recipients, in breach of GDPR requirements.ESAEPDGDPR€900
09 Jul 2025DISTRIBUTED ENERGY ASSETS, S.L.DISTRIBUTED ENERGY ASSETS, S.L. was fined by the AEPD 5,000 EUR for obstructing the exercise of data subject rights. The breach concerned in particular the right to erasure under Article 17 of the GDPR.ESAEPDGDPR€5,000
09 Jul 2025SC Tremend Software Consulting SRLSC Tremend Software Consulting SRL was fined by ANSPDCP for GDPR violations. The penalty amounted to EUR 3,000.ROANSPDCPGDPR€3,000
09 Jul 2025EDICIONES CATÓLICOS Y VIDA PÚBLICA, S.L.U.The entity was fined for using non-essential cookies without obtaining prior user consent. This conduct breached the LSSI requirements on obtaining consent before activating such tracking tools.ESAEPDePrivacy€5,000
09 Jul 2025VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD 150,000 EUR for issuing a SIM card duplicate without proper consent. The incident led to unauthorized bank transfers and involved processing personal data without a lawful basis.ESAEPDGDPR€150,000
09 Jul 2025SOCIEDAD DE GESTIÓN DE ACTIVOS PROCEDENTES DE LA REESTRUCTURACIÓN BANCARIA, S.A. (SAREB)SAREB was fined €300,000 by the AEPD for breaches of GDPR Articles 5(1)(f) and 28. The case concerned data protection failures and insufficient contractual oversight of data processing activities.ESAEPDGDPR€300,000
09 Jul 2025REAL SOCIEDAD DE FUTBOL S.A.D.REAL SOCIEDAD DE FUTBOL S.A.D. suffered a ransomware attack that led to a data breach affecting 60,000 individuals, including biometric, identification, financial, and health data. The AEPD fined the company for failing to implement adequate technical and organizational measures to protect data security.ESAEPDGDPR€60,000
08 Jul 2025Stichting Oud LemmerStichting Oud Lemmer was fined by the AP 500 EUR for processing personal data without a legal basis. The case concerned live streaming camera footage of public spaces, which breached GDPR Articles 5 and 6.NLAPGDPR€500
08 Jul 2025Selgros Cash & Carry SRLIn June 2025, ANSPDCP completed an investigation at Selgros Cash & Carry SRL and found a GDPR violation. The operator was fined EUR 3,000.ROANSPDCPGDPR€3,000