Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
13 May 2021Synlab Med srlSynlab Med srl was fined EUR 20,000 by the Garante. The authority found that personal data were improperly transmitted to an entity not competent to process them, breaching the principles of data minimization and integrity.ITGaranteGDPR€20,000
01 Jan 2016SYNERTEC GROUP, S.L.SYNERTEC GROUP, S.L. was fined by the AEPD in the amount of 5,000 EUR for sending unsolicited commercial emails. The recipient was registered on the Robinson List, and the conduct breached Article 21 of the LSSI.ESAEPDePrivacy€5,000
20 Jan 2015SYNERTEC GROUP S.L.SYNERTEC GROUP S.L. was fined by the AEPD in the amount of €52,000 for sending unsolicited commercial emails. The conduct breached Article 21 of the LSSI, which restricts marketing communications without prior consent.ESAEPDePrivacy€52,000
22 Nov 2012Synergo s.r.l.Synergo s.r.l. was fined by the Italian Garante for failing to notify the processing of sensitive health data. The case involved information on HIV status and infectious diseases, which should have been notified under the Italian data protection code.ITGaranteGDPR€40,000
13 Apr 2023SWG S.p.A.SWG S.p.A. was fined EUR 15,000 by the Garante for blocking an employee’s access to email and phone before the agreed termination date. This prevented access to personal data, including sensitive data.ITGaranteGDPR€15,000
12 May 2026SWDESWDE was fined by the APD 50,000 EUR for unlawful call recordings and monitoring used for quality evaluation and training purposes. The authority found breaches of transparency, data minimization, and other GDPR principles.BEAPDGDPR€50,000
18 Sept 2008Suzuki Italia S.p.A.Suzuki Italia S.p.A. was fined for failing to provide the required privacy notice to individuals whose personal data was obtained from a third party. The breach was found under the Italian Data Protection Code.ITGaranteGDPR€45,000
06 Jul 2023SUROVI (Surovi Ristorante indiano e kebab di Chowdhury Monika)The Garante fined SUROVI restaurant EUR 1,000 for operating a video surveillance system without the required privacy notice. The authority found this to be a breach of Article 13 of the GDPR.ITGaranteGDPR€1,000
01 Jan 2015SURGE CENTRO DE ESTUDIOS S.L.SURGE CENTRO DE ESTUDIOS S.L. was fined by the AEPD EUR 1,400 for sending unsolicited commercial emails to the complainant. This conduct breached Article 21.1 of the LSSI.ESAEPDePrivacy€1,400
01 Jan 2024SUPERVISTA OPTICS SLUSUPERVISTA OPTICS SLU was fined by the AEPD 20,000 EUR for sending commercial electronic communications to a user who had previously opted out. The authority found a breach of Article 21 of the LSSI.ESAEPDePrivacy€20,000
12 Nov 2015Supermercato Centro Storico srlSupermercato Centro Storico srl was fined €12,400 by the Garante for inadequate data protection measures linked to its video surveillance system. The authority found that the required informational signage was missing, in breach of data protection rules.ITGaranteGDPR€12,400
16 Oct 2025SUPERMARCHE (procédure simplifiée)CNIL imposed an administrative fine of EUR 20,000 on SUPERMARCHE and issued an injunction. The case was handled under a simplified procedure.FRCNILGDPR€20,000
02 Feb 2022SUPERCOR, S.A.SUPERCOR, S.A. was fined by the AEPD for using surveillance cameras in employee rest areas without proper notification. The authority found this conduct to be in breach of GDPR Article 6.ESAEPDGDPR€70,000
19 Nov 2017Superbeton S.p.a.Superbeton S.p.a. was fined 20,000 EUR by the Garante for failing to properly notify the use of a geolocation system on its vehicles. The authority treated this as a breach of data protection notification obligations.ITGaranteGDPR€20,000
16 Sept 2022SUPER 24H LOS ROSALES, S.L.The company was fined EUR 300 by the AEPD for operating an external surveillance camera without visible signage. It also failed to provide information on the data controller and data subject rights required under GDPR.ESAEPDGDPR€300
18 Jun 2025SUNERIS, S.A.SUNERIS, S.A. was fined by the AEPD in the amount of 9,000 EUR for improper handling of personal data. The case involved copying a guest’s information without consent and leaving a master key card accessible, which breached data protection principles.ESAEPDGDPR€9,000
18 Apr 2022SUMINISTRADOR IBÉRICO DE ENERGÍA, S.L.The company changed the electricity and gas supplier without the customer's consent. This constituted a breach of data protection rules and led to a fine imposed by the AEPD.ESAEPDGDPR€30,000
01 Jan 2023SUMINISTRADOR IBÉRICO DE ENERGÍA, S.L.SUMINISTRADOR IBÉRICO DE ENERGÍA, S.L. was fined by the AEPD 50,000 EUR for processing personal data without consent. The case involved formalizing an electricity supply contract and charging the complainant's bank account without authorization.ESAEPDGDPR€50,000
01 Jan 2023Suministrador Ibérico de Energía, S.L.Suministrador Ibérico de Energía, S.L. was fined by the AEPD €70,000 for switching a customer's electricity provider without consent. The authority found that the processing lacked a valid legal basis under Article 6(1) GDPR.ESAEPDGDPR€70,000
22 Dec 2022SUDREZIDENȚIAL Broker S.R.L.The company was fined for failing to inform data subjects about a personal data breach. The authority found a violation of Article 34 of the GDPR.ROANSPDCPGDPR€10,000