Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
07 Nov 2020B.B.B.B.B.B. was fined by the AEPD EUR 2,000 for operating a video surveillance system directed toward public space. The measure affected the rights of third parties without justified cause and raised data protection compliance concerns.ESAEPDGDPR€2,000
04 Dec 2025Istituto Comprensivo Centro di Casalecchio di RenoThe Garante fined Istituto Comprensivo Centro di Casalecchio di Reno EUR 2,000 for publishing personal data online without a proper legal basis. The authority found breaches of data minimization and transparency principles.ITGaranteGDPR€2,000
17 Sept 2019vzw YThe Litigation Chamber fined vzw Y for failing to respond properly to a data subject’s requests for access to and erasure of personal data. The authority found breaches of GDPR Articles 12, 15, and 17.BEAPDGDPR€2,000
28 May 2019Geanonimiseerd (APD 04/2019)The APD Litigation Chamber imposed a EUR 2,000 fine for using email addresses collected for urban planning purposes to send election propaganda by a mayor. The authority found a breach of the GDPR purpose limitation principle.BEAPDGDPR€2,000
01 Jan 2015DIVINITEL, S.L.DIVINITEL, S.L. was fined by the AEPD EUR 2,000 for sending unsolicited commercial messages without recipient consent. This constituted a breach of Article 21.2 of the LSSI.ESAEPDePrivacy€2,000
22 Oct 2025Agency for Control of Outstanding Debts S.R.L.The company was fined EUR 2,000 by ANSPDCP for breaching multiple GDPR provisions. The case followed a complaint alleging deficiencies in personal data protection compliance.ROANSPDCPGDPR€2,000
26 Mar 2026Copacabana s.r.l.Copacabana s.r.l. was fined EUR 2,000 by the Garante for installing a video surveillance system without the required informational signage and necessary authorization. The authority cited a breach of GDPR Article 13.ITGaranteGDPR€2,000
01 Jan 2014STAGE ENTERTAINMENT ESPAÑA, S.L.STAGE ENTERTAINMENT ESPAÑA, S.L. was fined by the AEPD 2,000 EUR for continuing to send commercial emails to a user despite repeated requests to delete their data and stop communications. The authority found a breach of Article 21.1 of the LSSI.ESAEPDePrivacy€2,000
28 Apr 2022Ekss s.r.l.Ekss s.r.l. was fined by the Garante EUR 2,000 for operating a video surveillance system without the required informational signage. The authority found this to be a breach of Article 13 GDPR.ITGaranteGDPR€2,000
03 Sept 2020Comune di CasaloldoComune di Casaloldo was fined by the Garante for publishing personal data on its institutional website without an appropriate legal basis. The conduct breached the principles of lawfulness, fairness, transparency, and data minimization.ITGaranteGDPR€2,000
29 May 2023B.B.B.The entity was fined by the AEPD for failing to remove a viral video from Twitter that breached data protection rules. The case indicates a lack of timely action in response to content processing personal data without a lawful basis.ESAEPDGDPR€2,000
12 May 2025CV PRO CONSULT S.R.L.The National Supervisory Authority for Personal Data Processing completed an investigation in April 2025 at CV PRO CONSULT S.R.L. and found a GDPR violation. As a result, a fine of EUR 2,000 was imposed.ROANSPDCPGDPR€2,000
03 Feb 2021ASESORÍA MUNIZ SOLÁN, S.L.ASESORÍA MUNIZ SOLÁN, S.L. was fined by the AEPD 2,000 EUR for breaching confidentiality after sending a debt certificate relating to a third party instead of the correct document. The authority also noted inadequate security measures under GDPR Article 32.ESAEPDGDPR€2,000
22 Sept 2022Bitfactor SRLBitfactor SRL was fined EUR 2,000 by ANSPDCP after a data security incident caused by a malfunctioning application. The application sent marketing communications, resulting in a breach of personal data confidentiality affecting 1,757 users.ROANSPDCPGDPR€2,000
24 Sept 2020BRONSON BAR, S.L.BRONSON BAR, S.L. was fined 2,000 EUR by the AEPD. The company used the reverse side of a contract to create an inventory, which was then publicly displayed, breaching data integrity and confidentiality principles.ESAEPDGDPR€2,000
16 Feb 2024Anonymised (HDPA 6/2024)The company was fined 2,000 EUR by the HDPA for unlawful processing of personal data. It used vehicle tracking data outside working hours to locate an employee.GRHDPAGDPR€2,000
08 Jan 2021C.C.C.C.C.C. was fined EUR 2,000 by the AEPD. The authority found that the company failed to provide a written contract and did not inform the complainant about the processing of personal data, in breach of Article 13 GDPR.ESAEPDGDPR€2,000
23 Sept 2024PPC ENERGIE MUNTENIA S.A.In September 2024, ANSPDCP completed an investigation into PPC ENERGIE MUNTENIA S.A. and found violations of GDPR provisions. The company was fined EUR 2,000.ROANSPDCPGDPR€2,000
14 Jan 2021Poliambulatorio Talenti S.r.l.Poliambulatorio Talenti S.r.l. was fined €2,000 by the Italian supervisory authority, Garante. The case concerned the improper handling of a data access request, which constitutes a breach of GDPR Article 5.ITGaranteGDPR€2,000
22 Nov 2019MEGASTAR, S.L.MEGASTAR, S.L. was fined by the AEPD EUR 2,000 for surveillance cameras that were improperly oriented and captured disproportionate images. The authority also found that the required informational signage was missing, constituting a breach of Article 5(1)(c) GDPR.ESAEPDGDPR€2,000