Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
09 Sept 2022COMUNIDAD DE PROPIETARIOS R.R.R.COMUNIDAD DE PROPIETARIOS R.R.R. was fined by the AEPD 2,000 EUR for unauthorized access to and dissemination of video surveillance recordings. The case concerns a breach of data protection rules.ESAEPDGDPR€2,000
20 Feb 2025Medstar S.R.L.Medstar S.R.L. was fined by ANSPDCP for failing to notify the data breach to the supervisory authority. The company also did not inform the affected individuals about the unauthorized disclosure of their personal data.ROANSPDCPGDPR€2,000
01 Jan 2021RECLAMADOR, S.L.RECLAMADOR, S.L. was fined €2,000 by the AEPD for sending a commercial electronic communication after the recipient had exercised the right to erasure. The authority found this conduct breached GDPR and LSSI requirements.ESAEPDGDPR€2,000
01 Jan 2017Happy Social Media LTD.Happy Social Media LTD. was fined by the AEPD EUR 2,000 for sending advertising emails to individuals who had opted out of receiving them. The case concerned Article 21.1 of the LSSI and the obligation to respect objections to marketing communications.ESAEPDePrivacy€2,000
29 Jun 2023FORKMERGE S.L.FORKMERGE S.L. was fined by the AEPD EUR 2,000 for failing to comply with a data subject’s request to remove personal data from search engine results. The authority found this to be a breach of Article 17 GDPR.ESAEPDGDPR€2,000
18 Jan 2021INDUSTRIAS METÁLICAS ANRO, S.L.INDUSTRIAS METÁLICAS ANRO, S.L. was fined by the AEPD for failing to comply with cookie policy requirements on its website. The breach concerned Article 22.2 of the LSSI.ESAEPDePrivacy€2,000
04 Aug 2022Sephora Cosmetics România SASephora Cosmetics România SA was fined EUR 2,000 by ANSPDCP for violating GDPR provisions. The case concerned non-compliance with personal data protection requirements.ROANSPDCPGDPR€2,000
04 Dec 2020BEINNOVA.ESBEINNOVA.ES was fined by the AEPD EUR 2,000 for sending unsolicited marketing emails without the recipient's consent. This conduct breached Article 21 of the LSSI on electronic commercial communications.ESAEPDePrivacy€2,000
28 Jun 2021ELEGA ENERGÍA, S.L.ELEGA ENERGÍA, S.L. was fined EUR 2,000 by the AEPD for failing to provide information about cookies and for not obtaining user consent before placing them. The authority found a breach of Article 22.2 of the LSSI.ESAEPDePrivacy€2,000
27 Sept 2022Anonymised (HDPA 18/2022)A fine was imposed for sending unsolicited political communication via SMS without prior consent. The case concerns a breach of consent requirements for political and marketing communications.GRHDPAePrivacy€2,000
16 Feb 2022FEDERACION CASTELLANO-LEONESA DE SALVAMENTO Y SOCORRISMOThe organization was fined EUR 2,000 by the AEPD for requiring participants to consent to data processing and image rights transfers without any option to refuse. The authority found this incompatible with Article 6(1) GDPR.ESAEPDGDPR€2,000
13 Dec 2021SC Nobiotic Pharma SRLSC Nobiotic Pharma SRL was fined €2,000 by ANSPDCP for failing to respond to information requests. The authority treated this as a breach of GDPR obligations.ROANSPDCPGDPR€2,000
14 Feb 2023MENZIES AVIATION SPAIN S.L.MENZIES AVIATION SPAIN S.L. was fined by the AEPD 2,000 EUR for sending emails to multiple recipients without using BCC. This exposed employees’ personal data to other recipients.ESAEPDGDPR€2,000
16 Jan 2026Liceo Classico e Scientifico Alessandro VoltaLiceo Classico e Scientifico Alessandro Volta was fined 2,000 EUR by the Garante for publishing personal data on its institutional website without a proper legal basis. The authority found breaches of lawfulness, fairness, and transparency principles.ITGaranteGDPR€2,000
18 Dec 2025Elba Catering Distribuzioni s.r.l.s.Elba Catering Distribuzioni s.r.l.s. was fined EUR 2,000 by the Garante for installing a video surveillance system that primarily captured public streets. The authority found that this processing breached data protection rules.ITGaranteGDPR€2,000
25 Nov 2019YA candidate in municipal elections was fined for using a customer list to send election propaganda. The authority found a breach of the GDPR purpose limitation principle.BEAPDGDPR€2,000
01 Sept 2020Geanonimiseerd (APD 53/2020)A politician was fined for sending an election propaganda email without consent. The authority found unlawful processing of personal data and a failure to implement appropriate technical and organizational measures.BEAPDGDPR€2,000
22 May 2024TRADING INTERNATIONAL TOURIST, S.L.TRADING INTERNATIONAL TOURIST, S.L. was fined 2,000 EUR by the AEPD for adding the complainant’s phone number to a WhatsApp group with more than 500 members without consent. The authority found a breach of Article 6(1) GDPR, which requires a lawful basis for processing personal data.ESAEPDGDPR€2,000
08 Aug 2024PUERTO FOGONES SLPUERTO FOGONES SL was fined EUR 2,000 by the AEPD. The authority found a breach for failing to provide access to information as required under Article 58.1 of the GDPR.ESAEPDGDPR€2,000
02 Oct 2024Global Ports’s Services S.R.L.The company was fined for processing personal data without a legal basis, which breaches Article 6 of the GDPR. The case concerned unlawful processing by the controller.ROANSPDCPGDPR€2,000