Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
03 Nov 2021B.B.B.The entity processed personal data without consent by using the complainant's data to make a purchase on Amazon. The authority found a breach of GDPR Article 6.ESAEPDGDPR€2,000
11 Jul 2025MEDIADENTMEDIADENT was fined for failing to cooperate with the supervisory authority. The case concerned Article 31 GDPR, which requires controllers and processors to cooperate with the authority during its work.GRHDPAGDPR€2,000
13 Dec 2022CONSULTORÍA PERITACIONES ALMERIENSES, S.L.The company did not respond to a data access request and failed to publish information on data processing or the data controller on its website. AEPD treated this as a breach of the information obligations under Article 13 GDPR.ESAEPDGDPR€2,000
01 Jan 2024WAGESTREAM SPAIN S.L.U.WAGESTREAM SPAIN S.L.U. was fined by the AEPD for processing employees’ personal data without proper consent. The case involved names, personal email addresses, bank account numbers, and salary details, in breach of Article 6(1) GDPR.ESAEPDGDPR€2,000
17 Apr 2026Io e te s.r.l.s.Io e te s.r.l.s. was fined EUR 2,000 by the Italian Garante. The case concerned improper use of a surveillance camera that enabled remote viewing through a mobile application without proper authorization.ITGaranteGDPR€2,000
18 Dec 2025SOCIETE EXERCANT UNE ACTIVITE D'AGENCE DE VOYAGE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 2,000 on SOCIETE EXERCANT UNE ACTIVITE D'AGENCE DE VOYAGE and issued an injunction. The case concerns a breach of rules supervised by the CNIL.FRCNILGDPR€2,000
13 May 2021Brico Rida s.r.l.Brico Rida s.r.l. was fined by the Garante in the amount of 2,000 EUR for operating a video surveillance system without the required information notice to data subjects. The authority found a breach of Article 13 GDPR.ITGaranteGDPR€2,000
23 Mar 2023Paolo MeloniThe condominium administrator, Paolo Meloni, was fined for disclosing to all residents that a family had tested positive for COVID-19. The authority found this to be a breach of data protection rules.ITGaranteGDPR€2,000
16 Feb 2023CONCENTRA CENTRAL DE COMPRAS Y SERVICIOS S.L.The entity was fined for making misleading advertising calls without explicit consent from recipients. The authority cited breaches of GDPR Articles 14 and 21(4).ESAEPDGDPR€2,000
15 Apr 2025United Business Solutions SRLANSPDCP completed an investigation at United Business Solutions SRL and found a violation of GDPR provisions. As a result, a fine of EUR 2,000 was imposed.ROANSPDCPGDPR€2,000
19 May 2011Anonymised (HDPA 59/2011)The company was fined for sending unsolicited electronic messages and faxes without subscriber consent. This conduct breached e-privacy rules governing direct electronic communications.GRHDPAePrivacy€2,000
07 Feb 2024Account Exchange SRLAccount Exchange SRL was fined EUR 2,000 by ANSPDCP for violating GDPR provisions related to data processing. The case concerned non-compliant processing of personal data.ROANSPDCPGDPR€2,000
20 Mar 2026Domeniul Public și Privat SADomeniul Public și Privat SA was fined 2,000 EUR by ANSPDCP for GDPR violations. The case concerned non-compliance with personal data protection requirements.ROANSPDCPGDPR€2,000
13 Mar 2023Modaone SRLModaone SRL was fined by ANSPDCP EUR 2,000 for sending commercial emails to a data subject after the person had objected. The authority found a breach of the GDPR right to object.ROANSPDCPGDPR€2,000
01 Jan 2025MALAGASUITE SHOWROOM, S.L.MALAGASUITE SHOWROOM, S.L. was fined by the AEPD 2,000 EUR for failing to inform guests about the processing of their personal data. The authority found a breach of Article 13 GDPR.ESAEPDGDPR€2,000
15 Apr 2021Società triveneta di chirurgiaSocietà triveneta di chirurgia was fined EUR 2,000 by the Garante for processing personal data without meeting the requirements of lawfulness, fairness, and transparency. The authority also found a breach of the data minimization principle.ITGaranteGDPR€2,000
16 Apr 2022ORI, S.l.ORI, S.l. was fined by the AEPD 2,000 EUR for failing to provide a privacy policy on its website. Personal data was collected through multiple forms, which constituted a breach of data protection rules.ESAEPDGDPR€2,000
22 Feb 2024Camera di Commercio Industria Artigianato e Agricoltura di XXCamera di Commercio was fined for violating data protection principles by improperly disclosing personal data. The disclosure could have allowed third parties to learn the content of a judicial decision and infringed the privacy of the individual concerned.ITGaranteGDPR€2,000
20 Jun 2022Anonymised (HDPA 23/2022)A fine was imposed for failing to respond to a data access request within the required timeframe. The case concerns a breach of the controller’s obligations to facilitate data subject rights.GRHDPAGDPR€2,000
23 Apr 2023COYARE SLUCOYARE SLU was fined by the AEPD EUR 2,000 for a data protection breach linked to mass email sending. Using CC instead of BCC exposed recipients’ email addresses and could have compromised their identities.ESAEPDGDPR€2,000