Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
08 Jun 2020B.B.B.B.B.B. was fined by the AEPD 1,500 EUR for maintaining a video surveillance camera directed toward common areas without justified cause. The conduct caused anxiety to the complainant and was treated as a data protection breach.ESAEPDGDPR€1,500
09 Aug 2022Denmar Nacrut SRLDenmar Nacrut SRL was fined EUR 1,500 by ANSPDCP for violating GDPR provisions. The case concerns non-compliance with personal data protection requirements.ROANSPDCPGDPR€1,500
08 Aug 2014Anonymised (HDPA 115/2014)The controller was fined for processing personal data without consent and for sending unsolicited marketing messages. The case indicates breaches of core data protection and marketing communication obligations.GRHDPAePrivacy€1,500
09 Jan 2024EDITEUR DE SITE WEB - ANNUAIRE INVERSE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 1,500 on EDITEUR DE SITE WEB - ANNUAIRE INVERSE under a simplified procedure. The case concerns a breach of rules covered by the supervisory authority’s decision.FRCNILGDPR€1,500
01 Jan 2018CAFETERÍA NAGASAKICAFETERÍA NAGASAKI was fined by the AEPD 1,500 EUR for using surveillance cameras to capture images of public sidewalks without justification. The authority found this to be a breach of data protection rules.ESAEPDGDPR€1,500
01 Jan 2016TRAVELGENIO, S.L.TRAVELGENIO, S.L. was fined by the AEPD in the amount of €1,500 for sending unsolicited commercial emails to a customer. The conduct breached Article 21.1 of the LSSI, which governs marketing communications without prior consent.ESAEPDePrivacy€1,500
05 May 2022ABUNTIA SERVICES, S.L.ABUNTIA SERVICES, S.L. was fined by the AEPD EUR 1,500 for sending commercial SMS messages without prior consent from recipients. The authority found this breached Article 21 of the LSSI on unsolicited commercial communications.ESAEPDePrivacy€1,500
06 Sept 2013Groupon Greece Monoprosopi Etaireia Periorismenis EfthynisGroupon Greece was fined by the HDPA for failing to inform customers that their credit card data was stored by a third party. The authority found this to be a breach of data protection law.GRHDPAePrivacy€1,500
01 Jul 2020CAFÉ RESTAURANTE B.B.B.The entity installed a surveillance camera facing a public space, despite recommendations from the local police. This breached data protection regulations.ESAEPDGDPR€1,500
07 Dec 2023Anonymised (CyDPC ΑΠΟΦΑΣΗ ΓεΣΥ 77.pdf)A doctor accessed a patient's health records in the General Health System (GHS) without proper authorization or referral. The authority found this breached GDPR principles of lawful and transparent processing of personal data.CYCyDPCGDPR€1,500
04 Aug 2022LEASE PLAN SERVICIOS, S.A.U.LEASE PLAN SERVICIOS, S.A.U. was fined by the AEPD EUR 1,500 for failing to properly handle a request to restrict the processing of personal data. This led to unauthorized commercial communications being sent.ESAEPDePrivacy€1,500
23 Oct 2019CERRAJERIA CARLOS RODRIGUEZ S.L.CERRAJERIA CARLOS RODRIGUEZ S.L. was fined by the AEPD EUR 1,500 for collecting personal data without providing the required information to the data subjects. The authority found a breach of Article 13 GDPR.ESAEPDGDPR€1,500
24 Mar 2026SIA "Fitsypro"SIA "Fitsypro" was fined EUR 1,500 by the DVI. The decision has entered into force.LVDVIGDPR€1,500
17 May 2022MAYR MELNHOF PACKAGING ROMANIA S.R.L.The company was fined by ANSPDCP for processing images in a manner that was not adequate, relevant, or limited to what was necessary for the stated purpose. The authority found a breach of the data minimization principle.ROANSPDCPGDPR€1,500
28 Apr 2022Direzione Didattica Statale 1° Circolo–EboliDirezione Didattica Statale 1° Circolo–Eboli was fined by the Garante 1,500 EUR for breaching the GDPR principles of lawfulness, fairness, and transparency in data processing. The case concerned improper processing of personal data under the GDPR.ITGaranteGDPR€1,500
01 Jan 2015LASTMINUTE NETWORK S.L.LASTMINUTE NETWORK S.L. was fined by the AEPD in the amount of €1,500 for sending unsolicited commercial emails to a complainant who had previously requested that such communications stop. The authority found this conduct to be a breach of Article 21 of the LSSI.ESAEPDePrivacy€1,500
24 Mar 2020VOX ESPAÑAVOX ESPAÑA was fined by the AEPD 1,500 EUR for retaining personal data after a deletion request. The case also involved sending an email to a former member despite consent being withdrawn, which breached GDPR requirements.ESAEPDGDPR€1,500
02 Oct 2020GRUPO OCIO DESARROLLO Y SERVICIOS, S.L.The entity was fined by the AEPD in the amount of 1,500 EUR for sending unsolicited commercial communications via WhatsApp. The authority found a breach of the complainant's rights to data protection and to object to data processing.ESAEPDePrivacy€1,500
04 Jul 2024Lapis SasThe Garante fined Lapis Sas EUR 1,500 for incorrectly presenting itself as the data controller. This created public confusion and constituted a prolonged breach of GDPR requirements.ITGaranteGDPR€1,500
02 Sept 2019LA SALA 2015 S.L.U.LA SALA 2015 S.L.U. was fined by the AEPD 1,500 EUR for improper processing of personal data through a video surveillance system. The cameras captured images disproportionately from public sidewalks without the required legal basis.ESAEPDGDPR€1,500