Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
05 May 2022THOMAS INTERNATIONAL SYSTEMS, S.A.THOMAS INTERNATIONAL SYSTEMS, S.A. was fined by the AEPD 50,000 EUR for processing special categories of personal data without proper legal justification. The company requested sensitive information, including disability and ethnicity, in psychometric questionnaires.ESAEPDGDPR€50,000
13 Feb 2025Thomas FeroDr Thomas Fero was fined by the Garante EUR 10,000 for sending patients electoral campaign emails without their consent. The authority found this to be a breach of GDPR rules on personal data processing.ITGaranteGDPR€10,000
25 Aug 2023This Is The Big Deal LimitedThis Is The Big Deal Limited sent or instigated 41,417,889 unsolicited direct marketing messages to individuals without consent, breaching regulation 22 of PECR. In addition, 102,132 text messages were sent without the required opt-out information under regulation 23 of PECR. The ICO imposed a fine of 30,000 GBP.GBICOePrivacy€35,028
01 Jun 2023Thin SrlThin Srl was fined EUR 15,000 by the Garante for breaching the GDPR principles of lawfulness, fairness, and transparency in data processing. The case concerned processing activities linked to a medical project.ITGaranteGDPR€15,000
25 Sept 2020THE WASHPOINT S.L.THE WASHPOINT S.L. was fined by the AEPD 2,000 EUR for lacking a privacy policy and for having an improper cookie policy on its website. The breach concerned Article 13 of the GDPR and Article 22.2 of the LSSI.ESAEPDePrivacy€2,000
13 Nov 2024Thermogen S.r.l.Thermogen S.r.l. was fined by the Garante for making unsolicited promotional calls without proper consent. The conduct breached the GDPR and national privacy laws.ITGaranteGDPR€10,000
04 Nov 2025THERE’S AN AI FOR THAT S.R.LTHERE’S AN AI FOR THAT S.R.L. was fined 30,000 RON by ANSPDCP. The sanction concerns a breach of the national ePrivacy law.ROANSPDCPePrivacy€5,898
01 Jan 2023THE RED KIWI, S.L.THE RED KIWI, S.L. was fined 30,000 EUR by the AEPD. The breach involved adding clients’ phone numbers to a WhatsApp group without consent, which enabled unauthorized access to personal data.ESAEPDGDPR€30,000
08 Jun 2017THE PHONE HOUSE SPAIN, S.L.U.THE PHONE HOUSE SPAIN, S.L.U. was fined by the AEPD 2,500 EUR for sending commercial text messages without providing recipients with a simple and free way to object to the processing of their data for promotional purposes. The case concerned non-compliance with the LSSI rules on marketing communications.ESAEPDePrivacy€2,500
11 Sept 2025THE OBJECTIVE MEDIA, S.L.THE OBJECTIVE MEDIA, S.L. published an individual's personal data on its website without consent. The AEPD found this to be a breach of data protection principles and imposed a 20,000 EUR fine.ESAEPDGDPR€20,000
20 Oct 2025The Medical Specialist GroupThe Medical Specialist Group LLP reported a personal data breach after suspicious emails indicated that cyber criminals had accessed its mail server. An internal investigation found the server had been compromised in August 2021 through multiple vulnerabilities, allowing access to and theft of stored emails containing personal data.GGODPAGDPR€115,000
01 Jan 2012THE LEADER NEWSPAPER, S.L.THE LEADER NEWSPAPER, S.L. was fined by the AEPD EUR 2,000 for sending commercial emails without prior recipient consent. The authority found this conduct breached Article 21 of the LSSI.ESAEPDePrivacy€2,000
08 Aug 2014THE GOLDEN ATHENS SPAThe company processed personal data without consent, breaching the principles of lawfulness and data minimization under Greek law. HDPA imposed a fine of EUR 1,000.GRHDPAGDPR€1,000
17 Apr 2026The European House - Ambrosetti S.p.A.The European House - Ambrosetti S.p.A. was fined by Garante 85,000 EUR for a data breach. The incident involved unauthorized access and exfiltration of personal and authentication data affecting an unspecified number of individuals.ITGaranteGDPR€85,000
21 May 2026The European House – Ambrosetti spaThe Italian data protection authority fined The European House – Ambrosetti spa EUR 85,000 for security shortcomings following a data breach affecting 61,670 people. The company notified affected individuals too late, only after intervention by the authority.ITGarante per la protezione dei dati personaliGDPR€85,000
07 Jul 2023THE COMAKING SPACE, S.L.U.THE COMAKING SPACE, S.L.U. was fined by the AEPD EUR 2,000 for sending unsolicited commercial emails without recipient consent. The conduct breached the LSSI rules on electronic marketing communications.ESAEPDePrivacy€2,000
06 Mar 2024The Central Young Men’s Christian AssociationThe Central YMCA sent an email to participants in a programme for people living with HIV using “CC” instead of “BCC”, which exposed recipients’ email addresses to all recipients. From those addresses, 166 individuals could be identified or potentially identified, allowing an inference that they were likely living with HIV. The ICO imposed a £7,500 fine and issued a reprimand.GBICOGDPR€8,772
02 Oct 2019Tgroup s.r.l.Tgroup s.r.l. was fined 6,400 EUR by the Italian data protection authority, Garante. The case concerned the activation of a SIM card without the user's knowledge, which breached data protection rules.ITGaranteGDPR€6,400
06 Oct 2023Texas Andreas Petersen A/SThe Danish Data Protection Authority reported Texas Andreas Petersen A/S to the police and recommended a fine of at least DKK 200,000. The case concerned the collection and sharing of website visitors' personal data without a legal basis.DKDatatilsynetGDPR€26,818
28 May 2015Tex97 s.r.l.Tex97 s.r.l. was fined EUR 20,000 by the Italian data protection authority, Garante. The company retained customers' telephone traffic data for more than 24 months, in breach of Article 132 of the Italian Data Protection Code.ITGaranteGDPR€20,000