Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
26 Jun 2014Sudmetal s.r.l.Sudmetal s.r.l. was fined for using an integrated video surveillance system that allowed images from workplaces to be viewed without the required safeguards. The authority found this to be a breach of privacy regulations.ITGaranteGDPR€12,000
13 Apr 2023Suditaly Imprese Meridionali Soc. coop.The Garante imposed a 2,500 EUR fine on Suditaly Imprese Meridionali Soc. coop. for publishing detailed health data without the data subjects' consent. The case concerned Article 9 of the GDPR, which restricts processing of special categories of personal data.ITGaranteGDPR€2,500
15 Mar 2018Studio Silver Consulting S.r.l.s.Studio Silver Consulting S.r.l.s. was fined EUR 30,000 by the Garante for violations related to the processing of personal data in its debt management activities. The case concerned improper handling of personal data in the context of debt collection operations.ITGaranteGDPR€30,000
19 Dec 2024Studio Riabilitazione Creditizia s.r.l.s.The Garante fined Studio Riabilitazione Creditizia s.r.l.s. €70,000 for improperly accessing financial data from the Central Credit Register without proper authorization. The authority found this conduct breached data protection principles.ITGaranteGDPR€70,000
27 Oct 2016Studio Medico Odontoiatrico Associato Gimmelli B. & G.Studio Medico Odontoiatrico Associato Gimmelli B. & G. was fined by the Garante for unlawfully processing personal data by disclosing it to Ina Assitalia s.p.a. without obtaining the required informed consent from the data subject. The case reflects a breach of core lawful-processing requirements.ITGaranteGDPR€6,400
13 Dec 2012Studio Immobiliare Conca D'Oro s.r.l.Studio Immobiliare Conca D'Oro s.r.l. was fined by the Garante 6,400 EUR for making promotional phone calls without providing the required information notice and without obtaining consent. The authority found this to be a breach of the Italian Data Protection Code.ITGaranteGDPR€6,400
24 Nov 2022STS Di Prisinzano s.r.l.STS Di Prisinzano s.r.l. was fined EUR 1,000 by the Garante for failing to provide a data subject with an adequate privacy notice during roadside assistance. The authority found a breach of Article 13 GDPR.ITGaranteGDPR€1,000
01 Jan 2025STRATESYS TECHNOLOGY SOLUTIONS, S.L.STRATESYS TECHNOLOGY SOLUTIONS, S.L. was fined EUR 100,000 by the AEPD for breaching Article 5(1)(f) of the GDPR. The case concerned a failure to protect the integrity and confidentiality of personal data.ESAEPDGDPR€100,000
12 May 2017Strategy MentorThe fine was imposed for sending unsolicited marketing emails to a large number of recipients without prior consent. This conduct breached ePrivacy rules governing electronic marketing communications.GRHDPAePrivacy€75,000
10 Jan 2025Stowarzyszenie „Maraton” z GorlicThe President of the Personal Data Protection Office imposed an administrative fine of PLN 916.71 on Stowarzyszenie „Maraton” z Gorlic. The penalty concerned failure to notify a personal data breach within the required 72-hour deadline, together with related compliance shortcomings.PLPrezes Urzędu Ochrony Danych OsobowychGDPR€215
24 Jan 2022Stortingets administrasjonThe Norwegian DPA notified the Storting's administration of a NOK 2,000,000 fine for failing to implement adequate technical and organizational measures, including two-factor authentication. The deficiency led to a data breach affecting email accounts of representatives and staff.NODatatilsynetGDPR€196,000
21 Jun 2021Storstockholms Lokaltrafik, SLStorstockholms Lokaltrafik, SL was fined by IMY for using body-worn cameras without a legal basis. The authority found breaches of the GDPR principles of lawfulness, transparency, and data minimization.SEIMYGDPR€1,566,000
19 Dec 2024STOMATOLOGUE (procédure simplifiée)CNIL imposed an administrative fine of EUR 5,000 on STOMATOLOGUE under a simplified procedure. The case concerned a breach that resulted in an administrative sanction.FRCNILGDPR€5,000
27 Jan 2021STOCKHUNTERS, S.L.STOCKHUNTERS, S.L. was fined EUR 4,000 by the AEPD for failing to comply with GDPR Article 13. The authority found that the website privacy policy did not meet the required information standards.ESAEPDGDPR€4,000
20 Mar 2024Stjarnan ehf.Stjarnan ehf., operating Subway in Iceland, was fined by Persónuvernd for unlawful electronic surveillance of employees. The authority found that employees were not properly notified and were not adequately informed about their rights.ISPersónuverndGDPR€10,095
15 Dec 2016Stireria Rosa di HU XINStireria Rosa di HU XIN was fined 2,400 EUR by the Garante. The authority found that the company failed to inform data subjects about the processing of personal data through a video surveillance system covering public areas.ITGaranteGDPR€2,400
04 Apr 2013Stifter Josef KG.Stifter Josef KG. was fined by the Garante for failing to provide the required data protection notice to customers when collecting personal data during e-commerce transactions. This constituted a breach of Article 13 of the Italian Data Protection Code.ITGaranteGDPR€2,400
04 Apr 2013Stifter Josef KGStifter Josef KG was fined 2,400 EUR by the Garante. The company failed to provide the required data protection notice to customers when collecting personal data during online orders.ITGaranteGDPR€2,400
08 Jul 2025Stichting Oud LemmerStichting Oud Lemmer was fined by the AP 500 EUR for processing personal data without a legal basis. The case concerned live streaming camera footage of public spaces, which breached GDPR Articles 5 and 6.NLAPGDPR€500
11 May 2021Stichting Ondersteuning Provinciale Fractie Overijssel Partij voor de Vrijheid (PVV Overijssel)PVV Overijssel was fined by the AP EUR 7,500 for failing to report a personal data breach within the required 72-hour period. The case concerns a delayed notification to the supervisory authority about a security incident.NLAPGDPR€7,500