Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
29 Jan 2020B.B.B.The AEPD fined B.B.B. EUR 2,000 for using a phone number for a purpose other than the one for which it was originally collected. The authority found this to be a breach of the GDPR principle of purpose limitation.ESAEPDGDPR€2,000
26 Jun 2025SC Piramida Trade Invest SRLSC Piramida Trade Invest SRL was fined EUR 2,000 by ANSPDCP. The case concerned a violation of Article 21 of the GDPR, which governs the right to object to data processing.ROANSPDCPGDPR€2,000
24 May 2022Anonymised (HDPA 26/2022)A fine of EUR 2,000 was imposed for sending unsolicited political communication by SMS without the recipient's prior consent. The authority treated this as a breach of data protection and electronic communications rules.GRHDPAePrivacy€2,000
01 Jan 2021Dña. B.B.B.The entity was fined for publishing personal images and contact numbers on a dating website without proper consent. The authority found a breach of Article 6(1) of the GDPR.ESAEPDGDPR€2,000
02 Jul 2020Istituto Comprensivo di Uggiano La ChiesaIstituto Comprensivo di Uggiano La Chiesa was fined €2,000 by the Garante for posting lists at the school entrance that included minors' names, dates of birth, addresses, phone numbers, and vaccination status. The authority found breaches of lawfulness, fairness, transparency, and data minimization principles.ITGaranteGDPR€2,000
25 Jan 2023FUNDACIÓN GOODJOBFUNDACIÓN GOODJOB was fined EUR 2,000 by the AEPD. The authority found that the organization collected unnecessary health data related to disability without a proper legal basis, breaching data minimization principles.ESAEPDGDPR€2,000
11 Apr 2025NEW GAMBLING SOLUTIONS S.R.L.In March 2025, ANSPDCP completed an investigation into NEW GAMBLING SOLUTIONS S.R.L. and found a GDPR violation. The company was fined EUR 2,000.ROANSPDCPGDPR€2,000
09 Jul 2020Comune di BaronissiComune di Baronissi was fined by the Garante for publishing personal data online without a proper legal basis. The authority found a breach of the data minimization principle.ITGaranteGDPR€2,000
10 Oct 2024FEDERAL NAJANAJANA, S.L.FEDERAL NAJANAJANA, S.L. was fined by the AEPD €2,000 for sending unsolicited commercial messages via WhatsApp without the recipient’s explicit consent. The authority found a breach of Article 21 of the LSSI.ESAEPDePrivacy€2,000
12 Feb 2026Ristorante pizzeria CN 45The Garante fined Ristorante pizzeria CN 45 2,000 EUR for operating a video surveillance system without proper compliance. The case concerns GDPR breaches related to the lawful operation and implementation of CCTV monitoring.ITGaranteGDPR€2,000
02 Oct 2023AVENTURA EN TRAMPOLINES, S.L.Aventura en Trampolines, S.L. was fined by the AEPD EUR 2,000 for breaching GDPR Article 7. The company required consent for image use without allowing users to refuse specific terms, which did not meet data protection requirements.ESAEPDGDPR€2,000
16 Oct 2025PRIME TRANSACTION SAPRIME TRANSACTION SA was fined EUR 2,000 by ANSPDCP for a data security breach caused by a cyberattack. The incident led to unauthorized access to personal data of many individuals, including identification, contact, financial information, and copies of identity documents.ROANSPDCPGDPR€2,000
11 Dec 2024INSTITUTO RAIMON GAJA, S.L.INSTITUTO RAIMON GAJA, S.L. was fined by the AEPD 2,000 EUR for sending unsolicited commercial communications by email. The conduct breached Article 21.1 of the LSSI, despite the recipient’s request to stop receiving such messages.ESAEPDePrivacy€2,000
19 Nov 2021MEETING PUERTO C.B.MEETING PUERTO C.B. was fined by the AEPD EUR 2,000 for unlawful processing of personal data. The breach involved posting images and comments on social media without the consent of the data subjects, contrary to Article 6(1) of the GDPR.ESAEPDGDPR€2,000
29 Apr 2021Comune di Santa NinfaComune di Santa Ninfa was fined by the Garante 2,000 EUR for publishing a complainant’s personal data online. The publication also included detailed references to enforcement proceedings, which breached GDPR requirements.ITGaranteGDPR€2,000
15 Sept 2022Immobiliare Riscostruzione Meloria s.r.l.The company was fined by the Garante in the amount of 2,000 EUR for installing a video surveillance system without the required informational signage. This breached GDPR rules on transparency and the duty to inform individuals subject to monitoring.ITGaranteGDPR€2,000
29 Dec 2025Ordinul Asistenților Medicali Generaliști, Moașelor și Asistenților Medicali din România – Filiala NeamțANSPDCP imposed a fine on the Neamț branch of the Romanian Order of General Nurses, Midwives, and Nurses for GDPR violations. The case concerned non-compliance with personal data protection requirements.ROANSPDCPGDPR€2,000
26 Oct 2023SOCIETE AYANT POUR ACTIVITE PRINCIPALE L'EVENEMENTIEL (procédure simplifiée)The CNIL imposed a EUR 2,000 fine on SOCIETE AYANT POUR ACTIVITE PRINCIPALE L'EVENEMENTIEL under a simplified procedure. The case concerned a breach of personal data protection rules.FRCNILGDPR€2,000
12 Jan 2023BRISTOL LOGISTICS SABRISTOL LOGISTICS SA was fined EUR 2,000 by ANSPDCP for violating GDPR provisions. The case concerns non-compliant processing of personal data.ROANSPDCPGDPR€2,000
08 Jul 2022SISTEMAS TUBULARES DE INGENIERÍA CANARIAS, S.L.SISTEMAS TUBULARES DE INGENIERÍA CANARIAS, S.L. was fined by the AEPD 2,000 EUR for breaching data retention and confidentiality principles. The company improperly used personal data to file a police report and shared it with multiple parties.ESAEPDGDPR€2,000