Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
10 Jun 2025Accounting Audit SRLAccounting Audit SRL was fined by ANSPDCP for a data security breach caused by a cyber attack. The incident led to unauthorized disclosure of personal data, including identification data and financial documents, affecting a large number of data subjects, mainly employees of the company’s clients.ROANSPDCPGDPR€10,000
21 Oct 2014ACDACD was fined by the HDPA 1,000 EUR for sending unsolicited marketing emails without the recipients’ consent. This breached Article 11 of Law 3471/2006.GRHDPAePrivacy€1,000
10 Apr 2025Acea EnergiaAcea Energia was fined EUR 3,000,000 by the Garante. The authority found unauthorized telemarketing activities and insufficient protection of databases against access by unauthorized agents.ITGaranteGDPR€3,000,000
12 Feb 2026Acea Energia S.p.A.Acea Energia S.p.A. was fined by the Garante 2,000,000 EUR for processing inaccurate and outdated personal data of customers. This led to the activation of unsolicited energy supply contracts, indicating significant deficiencies in data quality controls.ITGaranteGDPR€2,000,000
06 Jul 2023AcegasApsAmga S.p.A.AcegasApsAmga S.p.A. was fined €10,000 by the Italian supervisory authority, Garante. The sanction concerned the company’s failure to respond to a data subject’s request for access to personal data, in breach of GDPR Article 15.ITGaranteGDPR€10,000
21 Jun 2018Acentro s.r.l.Acentro s.r.l. was fined EUR 10,000 by the Garante for failing to appoint data processors and provide them with the necessary instructions. The case concerns non-compliance with data protection obligations.ITGaranteGDPR€10,000
26 Oct 2023A.C. Group S.r.l.s.A.C. Group S.r.l.s. was fined by the Garante 10,000 EUR for making an unsolicited marketing call to a number listed in the Public Register of Objections without prior informed consent. The authority also found that the company failed to adequately respond to a data subject rights request.ITGaranteGDPR€10,000
01 Jan 2022ACKERMANN & SCHWARTZ ATTORNEYS AT LAW SLP.The company was fined by the AEPD EUR 10,000 for processing personal data without consent. The authority also found that its website privacy information was insufficient, including missing contact details and information on data subject rights.ESAEPDGDPR€10,000
09 Aug 2021ACONCAGUA JUEGOS S.A.ACONCAGUA JUEGOS S.A. was fined by the AEPD 10,000 EUR for failing to appoint a Data Protection Officer. The authority also found that the company did not address a data subject’s erasure request within the legal deadline.ESAEPDGDPR€10,000
21 Jul 2022Acqua Novara.VCO S.p.a.Acqua Novara.VCO S.p.a. was fined EUR 20,000 by the Garante for breaches related to the processing of personal data. The case concerned confidentiality and the risks arising from handling sensitive data in a workplace context.ITGaranteGDPR€20,000
24 Sept 2015Acquapark di Milillo Rosa & C. s.a.s.Acquapark di Milillo Rosa & C. s.a.s. was fined EUR 6,400 by the Garante for collecting personal data without providing the required information notice and for publishing user photos without consent. The case concerns failures to meet transparency obligations and lawful processing requirements.ITGaranteGDPR€6,400
29 Apr 2016ACROSS SRLACROSS SRL was fined by the AEPD in the amount of 1,500 EUR for sending unsolicited commercial emails without proper consent. The case concerned Article 21.1 of the LSSI and indicates a lack of a valid legal basis for direct marketing.ESAEPDePrivacy€1,500
28 May 2026Action Fit di MilanoThe Garante fined Action Fit di Milano EUR 3,930 for sending unsolicited commercial emails to a customer without consent. The authority found this to be a breach of data protection rules.ITGaranteGDPR€3,930
19 Jul 2018Active Network S.p.a.Active Network S.p.a. was fined by the Garante 20,000 EUR for retaining telematic traffic data for more than 12 months. The authority found that this practice breached data protection rules in the context of crime detection and repression.ITGaranteGDPR€20,000
24 Jan 2024ACTIVITE DE COMMERCE DE GROS PHARMACEUTIQUES (procédure simplifiée)The CNIL imposed an administrative fine of EUR 20,000 on ACTIVITE DE COMMERCE DE GROS PHARMACEUTIQUES. The case was handled under a simplified procedure.FRCNILGDPR€20,000
01 Jan 2024ACTIVOS INTELIGENTES, S.L.ACTIVOS INTELIGENTES, S.L. was fined by the AEPD 5,000 EUR for requiring guests to submit selfies with their ID cards during check-in. The authority found the data collection excessive and not properly justified or explained in terms of processing purposes.ESAEPDGDPR€5,000
01 Jan 2021AD735 DATA MEDIA ADVERTISING S.L.AD735 DATA MEDIA ADVERTISING S.L. was fined €3,000 by the AEPD for failing to comply with information requests. The case concerned Article 58(1) GDPR and the duty to cooperate with the supervisory authority.ESAEPDGDPR€3,000
04 Oct 2021AD735 DATA MEDIA ADVERTISING S.L.The entity was fined by the AEPD for breaching data protection rules. It continued sending commercial emails despite repeated requests from the complainant to delete their data.ESAEPDePrivacy€6,000
23 Aug 2021AD735 DATA MEDIA ADVERTISING S.L.AD735 DATA MEDIA ADVERTISING S.L. was fined EUR 15,000 by the AEPD for failing to comply with a resolution concerning the right of access. The authority cited a breach of Article 83(6) GDPR.ESAEPDGDPR€15,000
19 Apr 2021AD735 DATA MEDIA ADVERTISING S.L.AD735 DATA MEDIA ADVERTISING S.L. was fined EUR 15,000 by the AEPD. The authority found that the company failed to comply with a data subject's right to erasure and sent commercial communications without the recipient's explicit consent.ESAEPDePrivacy€15,000