Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
15 Jun 2026SSG SELECT SOLUTIONS S.R.LSSG SELECT SOLUTIONS S.R.L. was fined by ANSPDCP in the amount of EUR 2,000 for GDPR violations. The investigation was completed in April 2026.ROANSPDCPGDPR€2,000
15 Mar 2018S.P. Selezione Personale s.r.l.S.P. Selezione Personale s.r.l. was fined by the Garante in the amount of EUR 20,000 for violations related to the processing of personal data in head hunting and recruitment activities. The case concerned irregularities in the handling of candidate data.ITGaranteGDPR€20,000
22 Oct 2025SPRINTER MEGACENTROS DEL DEPORTE, S.L.SPRINTER MEGACENTROS DEL DEPORTE, S.L. experienced a data breach affecting approximately 6.2 million individuals, involving unauthorized access and encryption of critical systems. The incident was intentional and involved data from multiple EU member states.ESAEPDGDPR€2,600,000
12 Jun 2023Spotify, rätten till tillgångIMY fined Spotify AB SEK 58 million for failing to provide clear and understandable information about the purposes of processing, categories of personal data, and other required details under Article 15 GDPR. The authority also found that technical log file descriptions were provided in English, which did not meet the requirement for clear communication in the data subject’s language.SEIMYGDPR€4,992,000
03 Jun 2025Spotify ABOn 2025-06-03, Kammarrätten ruled that Spotify AB must pay an administrative fine of 58 million SEK. The case concerned insufficient transparency and inadequate information to data subjects under the GDPR, following an investigation by Integritetsskyddsmyndigheten.SEIntegritetsskyddsmyndigheten (IMY)GDPR€5,309,000
20 Feb 2024SPORT & SPA GEST, S.L.SPORT & SPA GEST, S.L. was fined by the AEPD 20,000 EUR for breaches of GDPR Articles 6(1), 13, 9, and 35. The case concerned improper data processing and insufficient information provided to users.ESAEPDGDPR€20,000
07 Aug 2021SPORTIUM APUESTAS DIGITAL S.A.U.SPORTIUM APUESTAS DIGITAL S.A.U. was fined by the AEPD 5,000 EUR for sending marketing emails after a data deletion request and for having non-compliant cookie policies on its website. The case indicates failures in data protection and user consent controls.ESAEPDePrivacy€5,000
12 Feb 2026Sportitalia Società Sportiva Dilettantistica a.r.l.Sportitalia Società Sportiva Dilettantistica a.r.l. was fined EUR 30,000 by the Garante for violations related to the processing of personal data in promotional emails. The authority found that the company did not comply with GDPR requirements in connection with these marketing communications.ITGaranteGDPR€30,000
10 Nov 2022Sportitalia, società sportiva dilettantistica a responsabilità limitataSportitalia was fined €20,000 by the Italian supervisory authority, Garante. The case concerned the use of a biometric system to record employee attendance without a proper legal basis, in breach of GDPR rules on data processing and special categories of data.ITGaranteGDPR€20,000
26 Jan 2026SportAdmin i Skandinavien ABSportAdmin i Skandinavien AB was fined by IMY 6,000,000 SEK for failing to implement appropriate technical and organizational measures to ensure an adequate level of security for personal data. The deficiency resulted in a data breach.SEIMYGDPR€564,000
26 Feb 2025SportadminIMY fined Sportadmin SEK 6 million after an IT attack exposed personal data of more than 2.1 million individuals, mostly children. The authority found that the company had not maintained an appropriate security level for the personal data it processed.SEIntegritetsskyddsmyndighetenGDPR€538,000
01 Mar 2023Spółdzielnie Mieszkaniową „UODO imposed an administrative fine of PLN 51,876 on the controller for failing to notify the supervisory authority of a personal data breach without undue delay. The authority also found that the affected data subject was not informed about the breach.PLUODOGDPR€11,098
13 Nov 2024Spinacqua S.r.l.Spinacqua S.r.l. was fined by the Garante €10,000 for making unsolicited promotional calls to a number listed in the Public Opposition Register. The company did not obtain consent and failed to verify the number’s registration status before contacting it.ITGaranteGDPR€10,000
31 Jan 2025S.P.E.E.H. HIDROELECTRICA S.AThe company was fined for a data security breach during the launch of its application. The incident resulted from a technical error and insufficient testing, which did not ensure adequate data protection.ROANSPDCPGDPR€15,000
20 Oct 2025S.P.E.E.H. HIDROELECTRICA SAS.P.E.E.H. HIDROELECTRICA SA was fined by ANSPDCP EUR 5,000 for failing to notify a personal data breach. The incident involved customer data, including names, contract details, and billing information.ROANSPDCPGDPR€5,000
01 Aug 2012Spazio S s.r.l.Spazio S s.r.l. was fined by the Garante 10,400 EUR for sending unsolicited commercial emails. The authority found that the company failed to provide adequate information and did not obtain valid consent from recipients, breaching privacy rules.ITGaranteGDPR€10,400
22 Jun 2023Spaziani FabrizioThe Garante fined Spaziani Fabrizio EUR 1,000 for non-compliant video surveillance practices. The case involved cameras that were not properly signposted and may have captured public areas.ITGaranteGDPR€1,000
10 Sept 2025S-PankkiThe sanctions board of the Office of the Data Protection Ombudsman imposed a EUR 1.8 million fine on S-Pankki for failing to ensure information security in its online banking authentication service. The case concerned a software vulnerability in S-mobiili that allowed logins using another customer’s credentials and resulted in a personal data security breach.FIOffice of the Data Protection OmbudsmanGDPR€1,800,000
01 Jan 2013SPAIN ON LINE, S.L.SPAIN ON LINE, S.L. was fined €30,001 by the AEPD for sending unsolicited promotional emails despite requests to stop. The conduct breached Article 21 of the LSSI on marketing communications without consent.ESAEPDePrivacy€30,001
01 Jan 2013SPACIO TERMAL, S.L.SPACIO TERMAL, S.L. was fined by the AEPD EUR 600 for sending unsolicited commercial emails without the required consent. The conduct breached Article 21 of the LSSI, which governs electronic marketing communications.ESAEPDePrivacy€600