Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
25 Jan 2018ATAM S.p.A. – Azienda territoriale Arezzo Mobilità S.p.A.ATAM S.p.A. was fined by the Italian data protection authority, Garante, in the amount of €20,000. The case concerned failures to meet notification obligations related to a geolocation system used to track vehicles.ITGaranteGDPR€20,000
16 Feb 2011Athena Research s.r.l.Athena Research s.r.l. was fined 6,000 EUR by the Garante for sending unsolicited commercial faxes without the recipients' explicit consent. The authority also found that the required privacy notice was not provided, in breach of the Italian Data Protection Code.ITGaranteGDPR€6,000
21 Jul 2023ATLAS ENTERTAINMENT, S.L.ATLAS ENTERTAINMENT, S.L. did not comply with a data subject’s request to delete personal data. The AEPD imposed a fine of EUR 1,000 for the GDPR breach.ESAEPDGDPR€1,000
30 Jun 2014ATRAPALO, S.L.ATRAPALO, S.L. was fined by the AEPD EUR 600 for sending unsolicited commercial emails to a user who had previously requested to unsubscribe. The authority found a breach of Article 21.1 of the LSSI.ESAEPDePrivacy€600
14 Oct 2024ATRESMEDIA CORPORACIÓN DE MEDIOS DE COMUNICACIÓN, S.A.ATRESMEDIA was fined by the AEPD EUR 50,000 for publishing a video containing violent content and the voices of the aggressors and the victim. The authority found a breach of data protection rules.ESAEPDGDPR€50,000
01 Jan 2023ATRESMEDIA CORPORACIÓN DE MEDIOS DE COMUNICACIÓN, S.A.ATRESMEDIA was fined by the AEPD in the amount of 50,000 EUR for publishing excessive personal data. The case concerned an audio recording of a victim's court statement, which was not necessary for the journalistic purpose.ESAEPDGDPR€50,000
11 Sept 2025ATRESMEDIA CORPORACIÓN DE MEDIOS DE COMUNICACIÓN, S.A.ATRESMEDIA was fined by the AEPD for disclosing personal data, including a handwritten signature, in a news broadcast without necessity. The authority found that the disclosure breached data protection principles because it was not proportionate to the purpose of the publication.ESAEPDGDPR€10,000
13 May 2021ATS di Bergamo, Agenzia di Tutela della saluteATS di Bergamo was fined by the Garante 20,000 EUR for violations involving the improper handling of sensitive health data. The case concerned the use of email to transmit data, which did not provide an adequate level of protection.ITGaranteGDPR€20,000
23 Nov 2021atvinnuvega- og nýsköpunarráðuneytiðThe Icelandic DPA, Persónuvernd, fined atvinnuvega- og nýsköpunarráðuneytið for processing personal data in breach of core GDPR principles, including transparency and security. The case concerned the Ferðagjöf app, where the authority found deficiencies in data protection compliance.ISPersónuverndGDPR€50,850
05 Sept 2025AUDIO ÓPTICA EUROPA, S.L.AUDIO ÓPTICA EUROPA, S.L. was fined by the AEPD EUR 1,500 for using a minor’s image without valid consent. The authority found this conduct to be in breach of Article 6 of the GDPR.ESAEPDGDPR€1,500
28 Jun 2022AUDIO STOCK, S.L.AUDIO STOCK, S.L. was fined €2,000 by the AEPD for sending commercial SMS messages despite the recipient's objection. The authority found this conduct breached Article 21 of the LSSI on unsolicited commercial communications.ESAEPDePrivacy€2,000
07 Jul 2025AURThe Romanian data protection authority imposed two fines on AUR totaling EUR 25,000. The sanctions concerned unauthorized access to supporters' personal data in the AUR app and unlawful collection of personal data on campaign platforms.ROAutoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter PersonalGDPR€25,000
17 Mar 2016Aurelia FevolaAurelia Fevola was fined by the Garante for collecting personal data through her website without providing users with the required information notice. This conduct breached the Italian Data Protection Code.ITGaranteGDPR€2,400
10 Sept 2015Aurelia ZanniAurelia Zanni was fined EUR 2,400 by the Garante for failing to provide an adequate simplified privacy notice. The case concerned its “compro oro” business and non-compliance with the Italian Data Protection Code and the 2010 video surveillance guidelines.ITGaranteGDPR€2,400
24 Nov 2016Aurora Jonica soc. coop.Aurora Jonica soc. coop. was fined by the Garante 10,000 EUR for making an unsolicited promotional call. The phone number was registered in the public opt-out list, which breached data protection rules.ITGaranteGDPR€10,000
17 Apr 2026Ausl ModenaAusl Modena was fined by the Garante in the amount of 3,500 EUR for creating duplicate patient records. The case involved processing health data without proper transparency and compliance with data protection rules.ITGaranteGDPR€3,500
01 Jun 2023AUSL Toscana Sud EstThe Garante fined AUSL Toscana Sud Est 20,000 EUR for the unlawful dissemination of a patient's health data. The authority found a breach of data protection principles.ITGaranteGDPR€20,000
12 May 2016Auto 2000 s.p.a.Auto 2000 s.p.a. was fined by the Garante for collecting personal data through its website without providing users with the required information notice. The authority found this to be a breach of Article 13 of the Italian Data Protection Code.ITGaranteGDPR€2,400
12 May 2016Auto 2000 s.p.a.Auto 2000 s.p.a. was fined by the Garante for collecting personal data through its website without providing users with the required information notice. The case concerned a breach of Article 13 of the Italian Data Protection Code.ITGaranteGDPR€2,400
04 Aug 2022AUTOBIZ, S.A. SUCURSAL EN ESPAÑAAUTOBIZ, S.A. Sucursal en España was fined by the AEPD €800 for sending unsolicited marketing messages. The authority also found that the company failed to provide a functional opt-out mechanism, breaching Article 21 of the LSSI.ESAEPDePrivacy€800