Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
17 Dec 2020LABORATORIO OCTOGÓN, S.L.LABORATORIO OCTOGÓN, S.L. was fined by the AEPD €1,000 for improperly positioning a surveillance camera. The camera captured third-party areas without justification, which breached data protection principles.ESAEPDGDPR€1,000
08 May 2024DIMAGAZA, S.L.DIMAGAZA, S.L. was fined by the AEPD 1,000 EUR for posting personal data of employees affected by a collective dismissal on a notice board accessible to outsiders. The authority found a breach of the principles of integrity and confidentiality.ESAEPDGDPR€1,000
30 Jan 2023BANKINTER, S.A.BANKINTER, S.A. was fined by the AEPD in the amount of 1,000 EUR for not adequately handling a data subject access request. The authority found a breach of Article 15 of the GDPR.ESAEPDGDPR€1,000
15 Oct 2024AFP GESTION DEL COLOR, S.L.AFP GESTION DEL COLOR, S.L. was fined by the AEPD in the amount of €1,000 for sending unsolicited commercial emails. The conduct breached Article 21.1 of the LSSI, which prohibits marketing communications without prior consent.ESAEPDePrivacy€1,000
12 Dec 2024Istituto Comprensivo Statale CalenzanoIstituto Comprensivo Statale Calenzano was fined EUR 1,000 by the Garante for breaching data protection principles. The case concerned the processing of personal data without meeting the requirements of lawfulness, fairness, and transparency.ITGaranteGDPR€1,000
05 Aug 2022Mister Brick S.a.s.Mister Brick S.a.s. was fined EUR 1,000 by the Garante for sending an unsolicited promotional email without obtaining prior consent from the recipient. The authority found this to be a breach of GDPR requirements on lawful processing and consent.ITGaranteGDPR€1,000
24 Nov 2022Medicover S.R.L.Medicover S.R.L. was fined EUR 1,000 by ANSPDCP for a data security breach. An email sent to a customer included additional contract documents belonging to other clients, resulting in disclosure of third-party personal data.ROANSPDCPGDPR€1,000
11 Sept 2025Giada FM S.r.l.Giada FM S.r.l. was fined EUR 1,000 by the Garante for failing to respond to an employee’s request to access personal data. The request covered training certificates and medical visit documentation, which is a breach of the GDPR access rights.ITGaranteGDPR€1,000
21 Oct 2014ACDACD was fined by the HDPA 1,000 EUR for sending unsolicited marketing emails without the recipients’ consent. This breached Article 11 of Law 3471/2006.GRHDPAePrivacy€1,000
24 Jun 2025I ASPIDA TOU DAVIDThe HDPA imposed a EUR 1,000 fine on I ASPIDA TOU DAVID. The authority found that the entity failed to cooperate, which breaches GDPR requirements.GRHDPAGDPR€1,000
06 Mar 2020B.B.B.A private individual was fined by the AEPD €1,000 for installing surveillance cameras without the required informational signage. The case concerned a breach of data protection rules linked to proper notice for video surveillance.ESAEPDGDPR€1,000
16 Dec 2021Università Telematica Internazionale UninettunoUniversità Telematica Internazionale Uninettuno was fined EUR 1,000 by the Italian supervisory authority Garante. The authority found breaches of lawfulness, fairness, transparency, and data minimization principles.ITGaranteGDPR€1,000
25 Jul 2013Anonymised (HDPA 90/2013)HDPA imposed a fine of EUR 1,000 on Anonymised (HDPA 90/2013) for the illegal collection and further processing of personal data. The case concerns a breach of the lawful processing requirements.GRHDPAGDPR€1,000
02 Oct 2023Cez Vânzare S.A.Cez Vânzare S.A. was fined by ANSPDCP EUR 1,000 for a data protection breach. The incident resulted in unauthorized disclosure or access to personal data, including names, correspondence addresses, and customer codes of both individuals and legal entities.ROANSPDCPGDPR€1,000
26 Oct 2023Provvedimento del 26 ottobre 2023 [9960920]The Garante imposed a EUR 1,000 fine on a condominium administrator for installing a video surveillance system without a proper legal basis or assembly resolution. The conduct was found to breach GDPR rules on lawful processing.ITGaranteGDPR€1,000
29 Jan 2024JAÉN, SENTIDO Y COMÚNThe entity was fined by the AEPD for failing to comply with a data protection authority resolution. The breach concerned sending emails to multiple recipients without using BCC, contrary to Article 58(2) GDPR.ESAEPDGDPR€1,000
14 May 2026FeGi M&A Services s.r.l.FeGi M&A Services s.r.l. was fined EUR 1,000 by the Garante for making promotional phone calls without the required consent. The authority found this conduct breached GDPR principles of fairness and transparency.ITGaranteGDPR€1,000
08 Nov 2024PPC Energie Muntenia S.AThe National Supervisory Authority for Personal Data Processing completed an investigation at PPC Energie Muntenia S.A and found a violation of GDPR provisions. As a result, a fine of EUR 1,000 was imposed.ROANSPDCPGDPR€1,000
27 Apr 2023B.B.B.The entity was fined by the AEPD in the amount of EUR 1,000 for installing surveillance cameras without proper signage and justification. The authority treated this as a breach of data protection rules.ESAEPDGDPR€1,000
14 Dec 2021MALAGATROM, S.L.UMALAGATROM, S.L.U was fined by the AEPD in the amount of EUR 1,000 for failing to comply with a prior decision. That decision required the removal of comments containing personal data from its Amazon page and the implementation of measures to prevent similar incidents in the future.ESAEPDGDPR€1,000