Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
23 Apr 2025Diskriminerings­ombudsmannen (DO)The Swedish Authority for Privacy Protection (IMY) fined the Equality Ombudsman (DO) 100,000 SEK. IMY found that DO failed to implement appropriate technical and organizational measures to ensure an adequate level of security for personal data collected via a web form.SEIMYGDPR€9,141
16 Apr 2025SERVICIOS INMOBILIARIOS Y GESTIÓN RCL-MADRID, S.L.SERVICIOS INMOBILIARIOS Y GESTIÓN RCL-MADRID, S.L. was fined 600 EUR by the AEPD. The authority found that the company did not provide access to personal data and other information requested during the investigation. The conduct breached Article 58(1) of the GDPR.ESAEPDGDPR€600
16 Apr 2025COMUNIDAD DE PROPIETARIOS ***COMUNIDAD.1The community of property owners was fined by the AEPD for publishing personal data on a notice board. The authority found a breach of the confidentiality principle under GDPR.ESAEPDGDPR€1,000
16 Apr 2025CAIXABANK, S.A.CAIXABANK, S.A. was fined by the AEPD EUR 500,000 for failing to implement measures to ensure data integrity and confidentiality. The breach resulted in unauthorized access to personal data, indicating insufficient technical or organizational safeguards.ESAEPDGDPR€500,000
16 Apr 202520 MINUTOS EDITORA, S.L.20 MINUTOS EDITORA, S.L. was fined by the AEPD for the unauthorized dissemination of a video containing personal data. The authority found a breach of the data minimization principle under Article 5(1)(c) GDPR.ESAEPDGDPR€30,000
15 Apr 2025United Business Solutions SRLANSPDCP completed an investigation at United Business Solutions SRL and found a violation of GDPR provisions. As a result, a fine of EUR 2,000 was imposed.ROANSPDCPGDPR€2,000
15 Apr 2025LVMH IBERIA, S.L.LVMH IBERIA, S.L. was fined by the AEPD 70,000 EUR for adding an employee’s personal phone number to a WhatsApp group without consent. The authority treated this as a breach of data protection rules.ESAEPDGDPR€70,000
15 Apr 2025COLPER BUSINESS 2020 S.L.COLPER BUSINESS 2020 S.L. was fined by the AEPD EUR 20,000 for failing to provide access to personal data and the information requested by the data protection authority. The conduct was found to breach Article 58(1) of the GDPR.ESAEPDGDPR€20,000
14 Apr 2025Office Nova Concept SRLThe National Supervisory Authority for Personal Data Processing imposed a fine on Office Nova Concept SRL for breaching Article 17 of the GDPR. The case concerned non-compliance with obligations related to the right to erasure.ROANSPDCPGDPR€1,000
14 Apr 2025niegoAn administrative fine of 25,255 PLN was imposed for failure to comply with an order contained in an administrative decision of the President of UODO. The case concerns non-fulfilment of an obligation imposed by the supervisory authority.PLUODOGDPR€5,893
14 Apr 2025DPP Law LtdThe UK Information Commissioner fined law firm DPP Law Ltd 60,000 GBP for breaches of Articles 5(1)(f), 32(1), 32(2) and 33(1) of the UK GDPR. The infringements occurred between 25 May 2018 and 17 July 2022. The case concerned inadequate security measures and incident reporting obligations.GBICOGDPR€69,456
11 Apr 2025NEW GAMBLING SOLUTIONS S.R.L.In March 2025, ANSPDCP completed an investigation into NEW GAMBLING SOLUTIONS S.R.L. and found a GDPR violation. The company was fined EUR 2,000.ROANSPDCPGDPR€2,000
11 Apr 2025AIRE NETWORKS DEL MEDITERRÁNEO, S.L.The AEPD fined AIRE NETWORKS DEL MEDITERRÁNEO, S.L. 100,000 EUR for a data security incident. A SIM card duplication enabled unauthorized bank transactions, indicating insufficient safeguards and access controls.ESAEPDGDPR€100,000
10 Apr 2025Tensa Art Design S.A.Tensa Art Design S.A. was fined by ANSPDCP EUR 10,000 for GDPR violations related to its website www.lensa.ro. The case concerned non-compliant processing of personal data under data protection requirements.ROANSPDCPGDPR€10,000
10 Apr 2025Ente di Patrocinio ed Assistenza per i Cittadini e l’Agricoltura (EPACA)EPACA was fined EUR 5,000 by the Italian Garante. The authority found that the organization retained personal data beyond the legally permitted period and accessed the INPS database without a valid mandate.ITGaranteGDPR€5,000
10 Apr 2025Yolo Group S.p.a.Yolo Group S.p.a. was fined by the Garante 30,000 EUR for a data breach involving personal and contact data of a large number of individuals. The authority found a violation of Article 33 of the GDPR, which concerns notification of personal data breaches.ITGaranteGDPR€30,000
10 Apr 2025Gioele MagaldiThe Garante fined Gioele Magaldi, the manager of a blog, EUR 4,000 for publishing defamatory articles. The authority found that the content contained false information and exceeded the limits of the right to report because it lacked social utility.ITGaranteGDPR€4,000
10 Apr 2025Undici S.r.l.s.Undici S.r.l.s. was fined 8,000 EUR by the Garante for making unsolicited telemarketing calls. The authority found that the company did not verify the lawfulness of the data used for contact, breaching GDPR requirements on consent and data processing.ITGaranteGDPR€8,000
10 Apr 2025Unione Montana Appennino Parma EstUnione Montana Appennino Parma Est was fined by the Italian supervisory authority, Garante, in the amount of EUR 8,000. The authority found a lack of required transparency in data processing and failure to carry out a data protection impact assessment for workplace video surveillance.ITGaranteGDPR€8,000
10 Apr 2025Aliseo s.r.l.Aliseo s.r.l. was fined by the Garante for operating a video surveillance system without proper notice and for monitoring employees, including audio recording. The authority found the monitoring disproportionate to the stated security purpose.ITGaranteGDPR€5,000