Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
13 Mar 2025Istituto Alberghiero Mediterraneo di Pulsano (TA)Istituto Alberghiero Mediterraneo di Pulsano was fined EUR 2,000 by the Garante. The authority found breaches of the principles of lawfulness, fairness, and transparency in personal data processing.ITGaranteGDPR€2,000
13 Mar 2025Casatua S.r.l.Casatua S.r.l. was fined by the Garante 10,000 EUR for sending unsolicited communications via WhatsApp without obtaining proper recipient consent. The company also failed to implement adequate procedures to ensure compliance with data protection rules.ITGaranteGDPR€10,000
12 Mar 2025Automobilus International S.R.L.The company was fined for failing to implement appropriate technical and organizational measures to ensure an adequate level of security. The authority found this to be a breach of Article 32 of the GDPR.ROANSPDCPGDPR€5,000
11 Mar 2025UNIÓN DE CRÉDITO PARA LA FINANC. MOB. E INMOB., CREDIFIMO, E.F.C., SAUCREDIFIMO was fined by the AEPD for unlawfully processing personal data by including an individual's data in a credit file without a lawful basis. The authority found a breach of Article 6 of the GDPR.ESAEPDGDPR€200,000
11 Mar 2025Noy Business Tranzactions SRLANSPDCP completed an investigation in February 2025 at Noy Business Tranzactions SRL and found a breach of Article 17 of the GDPR. As a result, the controller was fined EUR 1,000.ROANSPDCPGDPR€1,000
11 Mar 2025LÁSER METALPRINT 3D, S.L.LÁSER METALPRINT 3D, S.L. was fined by the AEPD 10,000 EUR for deploying a video surveillance system without proper data processing agreements. The authority found a breach of GDPR Article 28.ESAEPDGDPR€10,000
10 Mar 2025Οργανισμός Χρηματοδοτήσεως ΣτέγηςThe Housing Finance Corporation was fined by the CyDPC in the amount of €10,000 for retaining personal data beyond the legal retention period. The authority found this breached GDPR storage limitation and data accuracy requirements.CYCyDPCGDPR€10,000
07 Mar 2025SENDING TRANSPORTE Y COMUNICACIÓN, S.A.SENDING TRANSPORTE Y COMUNICACIÓN, S.A. was fined EUR 80,000 by the AEPD for breaching GDPR Articles 28(2) and 28(4). The company subcontracted data processing without the required authorization.ESAEPDGDPR€80,000
06 Mar 2025SIA "VSV ZOO"The DVI imposed a fine of 500 EUR on SIA "VSV ZOO". The decision has entered into force.LVDVIGDPR€500
06 Mar 2025SERVICIOS DE INTEGRACIÓN DE ANDALUCÍASERVICIOS DE INTEGRACIÓN DE ANDALUCÍA was fined €2,000 by the AEPD for adding an employee’s personal phone number to a work WhatsApp group without consent. The authority found a breach of the GDPR lawful-basis requirement under Article 6(1).ESAEPDGDPR€2,000
06 Mar 2025SHOPBAG GROUP ONLINE SRLSHOPBAG GROUP ONLINE SRL was fined EUR 2,000 by ANSPDCP. The authority found that the company failed to provide information requested for the performance of its supervisory tasks.ROANSPDCPGDPR€2,000
06 Mar 2025CUBILLO GALLEGO, S.L.CUBILLO GALLEGO, S.L. was fined by the AEPD in the amount of 900 EUR for failing to comply with data protection authority resolutions. The breach concerned the absence of required privacy information on the company website and in contracts.ESAEPDGDPR€900
06 Mar 2025Dane anonimowe (J.)UODO imposed an administrative fine of PLN 56,824 on Anonymous data (J.) for failing to implement appropriate technical and organizational measures to ensure processing security. The case concerned a breach of personal data protection obligations.PLUODOGDPR€13,604
06 Mar 2025AVENTURA EN TRAMPOLINES S.L.AVENTURA EN TRAMPOLINES S.L. was fined 900 EUR by the AEPD for failing to comply with data protection authority resolutions. The case concerned Article 58(2) GDPR, which requires cooperation with the supervisory authority.ESAEPDGDPR€900
04 Mar 2025WEBRASOFT SRLIn January 2025, the National Supervisory Authority for Personal Data Processing completed an investigation into WEBRASOFT SRL and found a breach of GDPR provisions. As a result, the operator was fined EUR 20,000.ROANSPDCPGDPR€20,000
03 Mar 2025BEKO ROMÂNIA SAIn February 2025, ANSPDCP completed an investigation at BEKO ROMÂNIA SA and found violations of GDPR provisions. As a result, the controller was fined EUR 10,000.ROANSPDCPGDPR€10,000
01 Mar 2025Tensa Art Design S.A.The Romanian data protection authority investigated Tensa Art Design S.A., operator of lensa.ro, in March 2025. It found GDPR violations involving direct marketing without valid consent and improper handling of data subject access and erasure requests. Two fines totaling 15,000 EUR were imposed.ROANSPDCPGDPR€10,000
28 Feb 2025DYNAMIC EXPRESS COURIER S.LDYNAMIC EXPRESS COURIER S.L was fined 15,000 EUR by the AEPD for subcontracting without prior authorization and for failing to put proper contracts in place with subcontractors. The authority found this conduct breached GDPR Article 28 on processor arrangements.ESAEPDGDPR€15,000
27 Feb 2025Comune di SciaccaThe Garante fined Comune di Sciacca EUR 2,500 for violations related to the processing of personal data. The case concerned the communication of data to third parties without a proper legal basis.ITGaranteGDPR€2,500
27 Feb 2025RED ESPAÑOLA DE IDENTIFICACIÓN DE ANIMALES DE COMPAÑÍAREIAC was fined EUR 600 by the AEPD for failing to provide the required information to the data protection authority. The case concerns Article 58(1) GDPR and reflects a failure to cooperate with the supervisory authority.ESAEPDGDPR€600