Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
01 Apr 2024Your Consulting SRLANSPDCP imposed a fine on Your Consulting SRL for GDPR violations related to insufficient technical and organizational security measures. The security gap allowed unauthorized access to personal data through one of the company’s applications.ROANSPDCPGDPR€3,000
15 May 2013You & Me di Borille FabrizoYou & Me di Borille Fabrizo was fined EUR 4,000 by the Italian Garante. The sanction concerned the failure to respond to requests for information about surveillance cameras, which breached data protection rules.ITGaranteGDPR€4,000
10 Apr 2025Yolo Group S.p.a.Yolo Group S.p.a. was fined by the Garante 30,000 EUR for a data breach involving personal and contact data of a large number of individuals. The authority found a violation of Article 33 of the GDPR, which concerns notification of personal data breaches.ITGaranteGDPR€30,000
04 Jun 2025Yliopiston ApteekkiThe Finnish Data Protection Ombudsman’s sanctions board imposed a EUR 1.1 million fine on Yliopiston Apteekki for data protection deficiencies. The decision states that cookies and other tracking technologies used in the online pharmacy disclosed prescription-related and other customer data to Google and Meta.FIOffice of the Data Protection OmbudsmanGDPR€1,100,000
13 Nov 2020Y HuisvestingsmaatschappijThe social housing company was fined for breaching GDPR principles, including lawfulness and transparency in personal data processing. The authority also identified deficiencies in access rights handling and privacy policy transparency.BEAPDGDPR€528,000
28 Jun 2022YEGUADA SENILLOSA, S.L.Yeguada Senillosa, S.L. was fined by the AEPD 2,000 EUR for failing to comply with cookie requirements on its website. The authority found the use of non-essential third-party cookies without proper consent and adequate information to users.ESAEPDePrivacy€2,000
30 Oct 2013Ye BiYe Bi was fined by the Garante EUR 2,400 for operating a video surveillance system at Bar Millennium without the required signage. The authority found a breach of privacy regulations.ITGaranteGDPR€2,400
27 Jun 2025YDAIL CONSTRUCT SRLANSPDCP completed an investigation at YDAIL CONSTRUCT SRL in June 2025 and found a violation of applicable legal provisions. As a result, the company was fined 20,000 RON.ROANSPDCPGDPR€3,936
18 Jul 2013Yang YijieYang Yijie was fined EUR 6,000 by the Garante for failing to provide the required privacy notice in connection with a video surveillance system at his business. The authority found a breach of Article 13 of the Italian Privacy Code.ITGaranteGDPR€6,000
01 Mar 2018Yahoo! Italia s.r.l.Yahoo! Italia s.r.l. was fined by the Garante in the amount of 60,000 EUR. The company failed to comply with a request to remove certain URLs containing personal information from its search engine and did not provide information on the implementation of that request.ITGaranteGDPR€60,000
14 Dec 2017Yahoo Italia s.r.l.Yahoo Italia s.r.l. was fined EUR 80,000 by the Garante for violations related to the processing of personal data concerning the geolocation of users connecting to its website. The case concerned irregularities in how these data were collected and processed.ITGaranteGDPR€80,000
08 Mar 2018Yahoo! Emea Limited oggi Oath (Emea) LimitedYahoo! Emea Limited, now Oath (Emea) Limited, was fined 160,000 EUR by the Garante. The authority found that the company failed to comply with a request to remove specific URLs containing personal information from Yahoo! Search.ITGaranteGDPR€160,000
27 Aug 2024YThe case concerns a football club that obtained a member list during a takeover and used the personal data for commercial mailings without a valid legal basis. The authority found breaches of several GDPR provisions and imposed a monetary fine.BEAPDGDPR€8,000
09 Jul 2020YThe Litigation Chamber imposed a fine of 5,000 EUR for unlawful processing of personal data through surveillance cameras in a residential building. The responsible party failed to establish a legal basis for the processing and did not share access with co-owners.BEAPDGDPR€5,000
25 Nov 2019YA candidate in municipal elections was fined for using a customer list to send election propaganda. The authority found a breach of the GDPR purpose limitation principle.BEAPDGDPR€2,000
06 May 2021YThe APD Litigation Chamber imposed a 50,000 EUR fine on Y. The authority found that the privacy policy lacked transparency and breached several GDPR provisions.BEAPDGDPR€50,000
05 Apr 2012XY s.r.l.XY s.r.l. was fined by the Garante 10,400 EUR for sending unsolicited commercial communications by email despite the recipient's repeated objections. The case indicates a breach of data protection rules governing electronic marketing and respect for opt-out requests.ITGaranteGDPR€10,400
15 Sept 2011XY s.r.l.XY s.r.l. was fined by the Garante in the amount of EUR 10,400 for sending an unsolicited promotional fax. The conduct breached data protection and marketing communication rules.ITGaranteGDPR€10,400
12 May 2021xy d.o.o.The company xy d.o.o. was fined by AZOP for failing to implement appropriate technical security measures. This resulted in unauthorized processing of personal data of 28,085 data subjects, indicating a data protection compliance failure.HRAZOPGDPR€30,553
20 Nov 2008XYThe entity was fined by the Garante in the amount of 4,000 EUR for failing to respond to a request for information concerning unsolicited promotional emails. The case concerned non-compliance with data protection obligations.ITGaranteGDPR€4,000