Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
24 Aug 2021Топлофикация София ЕАДThe Bulgarian data protection authority fined Toplofikatsia Sofia EAD 2,000 BGN for unlawful processing of personal data caused by a name coincidence. The error led to incorrect legal actions being taken against an individual.BGCPDPGDPR€1,023
12 Mar 2026Liceo Scientifico MorgagniLiceo Scientifico Morgagni was fined by the Garante for violations related to the processing of sensitive data. The authority cited inadequate security measures in the protection of those data.ITGaranteGDPR€2,000
20 Feb 2025NAROBESA INV, S.L.NAROBESA INV, S.L. was fined EUR 2,000 by the AEPD for failing to provide the required documentation to the data protection authority. The case concerns a breach of the cooperation duty under Article 58(1) GDPR.ESAEPDGDPR€2,000
06 Dec 2021Societatea Civilă Medicală Policlinica TommedANSPDCP completed an investigation at Societatea Civilă Medicală Policlinica Tommed and found breaches of GDPR provisions. The operator was fined and required to align data collection and processing activities with data protection requirements to prevent unauthorized disclosure of personal data.ROANSPDCPGDPR€2,000
23 Jun 2020SALBEGAP, S.L.SALBEGAP, S.L. was fined by the AEPD EUR 2,000 for installing surveillance cameras in common areas without authorization from the homeowners' association. The authority found that this breached data protection principles.ESAEPDGDPR€2,000
27 May 2022B.B.B.B.B.B. was fined EUR 2,000 by the AEPD for failing to provide adequate data protection information in rental contract documentation. The authority found a breach of Article 13 GDPR.ESAEPDGDPR€2,000
03 Aug 2023Med Life SAMed Life SA was fined EUR 2,000 by ANSPDCP. The authority found that the company violated the complainant’s right of access by refusing to provide certain video recordings from the reception area of one of its hospitals.ROANSPDCPGDPR€2,000
07 Apr 2021Ignatiadis Nikolaos and SIA E.E.The company was fined for unlawfully using a surveillance camera to monitor employees. The authority found a breach of data protection principles and an absence of a valid legal basis for processing.GRHDPAGDPR€2,000
11 Aug 2020DERDIX 5000 SLThe entity published photos of minors in a magazine without obtaining consent, which constitutes a breach of data protection rules. The case concerns the unauthorized disclosure of children’s images and was sanctioned by the AEPD.ESAEPDGDPR€2,000
01 Jan 2019B.B.B.B.B.B. was fined 2,000 EUR by the AEPD for reusing paper containing personal data. This made the data accessible to third parties without consent, constituting a breach of data protection rules.ESAEPDGDPR€2,000
05 Feb 2025RESIDENTIAL QUALITY ENJOY, S.L.The company was fined EUR 2,000 by the AEPD for requesting and processing personal data, including minors' IDs, without proper consent or information. The authority found this to be a breach of data protection principles and transparency obligations.ESAEPDGDPR€2,000
01 Jan 2022ANIVERSALIA NETWORKS, S.L.ANIVERSALIA NETWORKS, S.L. was fined €2,000 by the AEPD. The authority found that the website did not provide adequate contact information for individuals to exercise their data protection rights.ESAEPDGDPR€2,000
20 Jul 2020CABRERA & GIL ABOGADOS, S.L.P.CABRERA & GIL ABOGADOS, S.L.P. was fined by the AEPD €2,000 for disclosing personal data without consent. The case concerns Article 6 GDPR, which requires a valid legal basis for processing personal data.ESAEPDGDPR€2,000
10 Jun 2020Comune di MontevagoComune di Montevago was fined by the Garante 2,000 EUR for the unlawful online publication of personal data without an appropriate legal basis. The case concerned a breach of the principles of lawful processing and data protection in the public disclosure of information online.ITGaranteGDPR€2,000
01 Jan 2016SYS N PROCS FR EXPS, S.L.SYS N PROCS FR EXPS, S.L. was fined 2,000 EUR by the AEPD. The authority found that the company sent unsolicited commercial emails without prior consent, in breach of Article 21.1 of the LSSI.ESAEPDePrivacy€2,000
01 Oct 2020Asociația de proprietari Militari R, comuna Chiajna, județul IlfovThe homeowners' association was fined by ANSPDCP €2,000 for failing to respond to a data subject's request. The authority treated this as a breach of GDPR rules on the exercise of individual rights.ROANSPDCPGDPR€2,000
15 Sept 2016SELF TRADE BANK, SAUSELF TRADE BANK, SAU was fined by the AEPD EUR 2,000 for sending unsolicited commercial emails to a customer. The customer had not authorized the use of their personal data for promotional purposes, which breached Article 21.1 of the LSSI.ESAEPDePrivacy€2,000
27 Jan 2022Circolo culturale “Ruian”Circolo culturale “Ruian” was fined EUR 2,000 by the Garante for operating a video surveillance system in breach of data protection rules. The cameras were not properly signposted, which failed to meet the required information obligations toward monitored individuals.ITGaranteGDPR€2,000
15 Jun 2026SSG SELECT SOLUTIONS S.R.LSSG SELECT SOLUTIONS S.R.L. was fined by ANSPDCP in the amount of EUR 2,000 for GDPR violations. The investigation was completed in April 2026.ROANSPDCPGDPR€2,000
04 Jun 2021INTERSUMI S.C.INTERSUMI S.C. was fined EUR 2,000 by the AEPD for not having an adequate privacy policy on its website. The authority found this to be a breach of Article 13 of the GDPR.ESAEPDGDPR€2,000