Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
07 May 2026South Staffordshire Plc and South Staffordshire Water PlcThe Information Commissioner’s Office (ICO) imposed a fine of 963,900 GBP on South Staffordshire Plc and South Staffordshire Water Plc for breaches of Article 5(1)(f) and Article 32(1) of the UK GDPR. The case followed a cyber incident in which personal data relating to approximately 633,887 UK data subjects was exfiltrated.GBICOGDPR€1,115,000
11 May 2026South Staffordshire PlcThe ICO issued a monetary penalty against South Staffordshire Plc and South Staffordshire Water Plc in the amount of GBP 963,000. The case concerned a security breach affecting more than 633,000 individuals and an admitted infringement of Article 5(1)(f) UK GDPR.GBInformation Commissioner's OfficeGDPR€1,113,000
11 Apr 2013Sound station s.a.s.Sound station s.a.s. was fined 30,000 EUR by the Garante for registering numerous phone SIM cards to unaware third parties. The conduct breached data protection requirements.ITGaranteGDPR€30,000
01 Jan 2015SOTO GLOBAL SERVICE, S.L.SOTO GLOBAL SERVICE, S.L. was fined by the AEPD €3,200 for sending nine unsolicited commercial emails without prior consent. The authority found a breach of Article 21 of the LSSI.ESAEPDePrivacy€3,200
22 Dec 2021SOS Leukémiás Gyermekekért AlapítványSOS Leukémiás Gyermekekért Alapítvány was fined by NAIH 500,000 HUF for processing personal data without a valid legal basis. The authority also found failures to provide transparent information and to facilitate data subject access rights.HUNAIHGDPR€1,355
14 Apr 2023Sorgenia S.p.a.Sorgenia S.p.a. was fined EUR 676,956 by the Italian data protection authority, Garante. The case concerned failure to respect data deletion and objection rights in connection with unlawful telemarketing practices in the energy sector.ITGaranteGDPR€676,000
06 Jul 2016Sorec s.r.l.Sorec s.r.l. was fined EUR 4,000 by the Garante for inadequate password security in its data processing systems. The case concerned non-compliance with data protection requirements.ITGaranteGDPR€4,000
01 Dec 2011Soprintendenza per i beni architettonici, paesaggistici, storici, artistici e etnoantropologici per Napoli e provinciaThe Garante fined Soprintendenza 32,000 EUR for violations related to the processing of biometric data. The authority found that the processing did not comply with the required legal requirements.ITGaranteGDPR€32,000
23 Apr 2015Soprintendenza per i Beni Architettonici e Paesaggistici di Venezia e LagunaThe Soprintendenza per i Beni Architettonici e Paesaggistici di Venezia e Laguna was fined 4,000 EUR by the Garante. The authority found that personal data had been unlawfully communicated to private entities without an appropriate legal basis, in breach of Article 19 of the Italian Data Protection Code.ITGaranteGDPR€4,000
01 Apr 2022SOPHIE ET VOILA, S.L.SOPHIE ET VOILA, S.L. was fined EUR 10,000 by the AEPD for publishing a photo on Instagram without the data subject’s consent. The authority found a breach of Article 6 GDPR on lawful processing.ESAEPDGDPR€10,000
24 Jun 2021Soluzione Tasse S.p.A.Soluzione Tasse S.p.A. was fined by the Garante 30,000 EUR for sending unsolicited emails without proper consent. The case concerned GDPR principles on data processing and transparency.ITGaranteGDPR€30,000
11 Jul 2012SOLUCIONES CORPORATIVAS IP, S.L.U.SOLUCIONES CORPORATIVAS IP, S.L.U. was fined 600 EUR by the AEPD for sending an unsolicited email. The conduct breached Article 21 of the LSSI, which restricts commercial communications without prior consent.ESAEPDePrivacy€600
17 Mar 2021SOLRAM T Y R S.L.SOLRAM T Y R S.L. was fined by the AEPD in the amount of 3,000 EUR for failing to delete personal data from its databases. The authority found a breach of Article 17 GDPR after the company continued sending unsolicited commercial messages via WhatsApp.ESAEPDGDPR€3,000
09 May 2018SO.LOG. SrlSO.LOG. Srl was fined EUR 8,000 by the Italian data protection authority, Garante. The sanction concerned the failure to properly notify processing activities related to vehicle geolocation, in breach of the Italian Privacy Code.ITGaranteGDPR€8,000
07 Feb 2020SOLO EMBRAGUE, S.L.SOLO EMBRAGUE, S.L. was fined by the AEPD 3,000 EUR for failing to provide information about its privacy policy and for not obtaining consent for cookies on its website. The case concerns breaches of transparency obligations and consent requirements under data protection rules.ESAEPDePrivacy€3,000
25 Feb 2016Sol Levante s.r.l.Sol Levante s.r.l. was fined EUR 12,000 by the Garante for retaining surveillance footage for 11 days. This exceeded the 7-day limit set out in the authority’s video surveillance guidelines.ITGaranteGDPR€12,000
29 Sept 2021Solera Italia s.r.l.Solera Italia s.r.l. was fined EUR 10,000 by the Garante for continuing to use an employee's email account after the employment ended. The authority found that the company did not provide proper information about this processing.ITGaranteGDPR€10,000
29 Mar 2023SOLAR PROGRESS, S.L.SOLAR PROGRESS, S.L. was fined 5,000 EUR by the AEPD for displaying an employee’s personal data on a company WhatsApp profile. The authority found a breach of data protection rules.ESAEPDGDPR€5,000
21 Mar 2012Solar Energy Group s.p.aSolar Energy Group s.p.a was fined by the Garante 32,000 EUR for processing personal data collected through online forms without providing the required information or obtaining consent. The authority found breaches of Articles 13 and 23 of the Italian Privacy Code.ITGaranteGDPR€32,000
16 May 2019SOGIMA S.r.l.SOGIMA S.r.l. was fined by the Garante for allowing unauthorized access to personal data on its website. The breach involved names, email addresses, and bank details without the consent of the data subjects.ITGaranteGDPR€4,000