Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
22 May 2018Adolfo AllegriniAdolfo Allegrini, a general practitioner, was fined for failing to implement minimum security measures to protect personal and sensitive data. This allowed unauthorized access to the healthcare system.ITGaranteGDPR€10,000
01 Jan 2017A DOS RUEDAS EN LA RED, SLA DOS RUEDAS EN LA RED, SL was fined EUR 2,200 by the AEPD for sending unsolicited commercial emails. The conduct breached Article 21 of the LSSI, which restricts marketing communications without prior consent.ESAEPDePrivacy€2,200
22 Jun 2017Adsalsa Italia Publicidad SucursalAdsalsa Italia Publicidad Sucursal was fined EUR 20,000 by the Garante. The authority found that personal data were processed without obtaining separate consent for each purpose, in breach of data protection rules.ITGaranteGDPR€20,000
11 Apr 2019AD Sphera Group s.r.l.AD Sphera Group s.r.l. was fined EUR 2,400 by the Garante for failing to provide the required privacy notice on its website. The breach concerned Article 13 of the Italian Data Protection Code.ITGaranteGDPR€2,400
12 Sept 2025A Düsseldorf-based personnel recruitment companyOn 2025-09-12, the LDI NRW announced a data protection fine of over 35,000 EUR against a Düsseldorf-based personnel recruitment company. The authority said the company repeatedly ignored job seekers’ requests for access and deletion and failed to respond to the supervisory authority’s inquiries.DELandesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-WestfalenGDPR€35,000
26 Mar 2025Advanced Computer Software Group LimitedThe UK Information Commissioner's Office fined Advanced Computer Software Group Limited, Advanced Health and Care Limited, and Aston Midco Limited a total of £3,076,320. The penalty related to serious UK GDPR Article 32(1) security failings linked to a ransomware attack and data breach affecting healthcare services.GBInformation Commissioner's OfficeGDPR€3,678,000
26 Mar 2025Advanced Computer Software Group LimitedThe UK Information Commissioner’s Office (ICO) fined Advanced Computer Software Group Limited £3,070,000 for security failings. The issues put the personal information of 79,404 people at risk. The case highlights inadequate safeguards over processed personal data.GBICOGDPR€3,671,000
13 Jan 2022ADVANS BROKERS CORREDURIA DE SEGUROS S.L.ADVANS BROKERS CORREDURIA DE SEGUROS S.L. was fined by the AEPD EUR 80,000 for a data breach affecting 55,000 individuals, including minors. The authority found that the incident was reported to the AEPD with delay.ESAEPDGDPR€80,000
13 Feb 2025ADVFAST s.r.l.s.ADVFAST s.r.l.s. was fined by the Garante for failing to respond to information requests concerning repeated unsolicited telemarketing calls. The case indicates a failure to cooperate with the supervisory authority.ITGaranteGDPR€2,000
08 Nov 2024AECORP 005, S.L.AECORP 005, S.L. was fined EUR 6,000 by the AEPD for failing to provide access to information requested during an investigation. The authority found a breach of Article 58.1 GDPR.ESAEPDGDPR€6,000
12 Feb 2020AEMA HISPANICA, S.L.AEMA HISPANICA, S.L. was fined by the AEPD 6,000 EUR for sending one employee's payroll to another employee. The incident constituted a breach of data protection rules.ESAEPDGDPR€6,000
22 Jun 2016Aemme Car S.r.l.Aemme Car S.r.l. was fined by the Garante in the amount of 2,400 EUR for collecting personal data through its website without providing users with the required information notice. This conduct breached the Italian data protection code.ITGaranteGDPR€2,400
03 Sept 2025AENA, S.M.E., S.A.The AEPD imposed a fine of EUR 10,043,002 on AENA, S.M.E., S.A. for processing passenger personal data in a manner deemed unnecessary and disproportionate. The authority found that the company’s practices breached data protection rules.ESAEPDGDPR€10,043,000
12 May 2021A. EPILOGI IDIOTIKI KEFALAIOUCHIKI ETAIREIAThe company was fined by the HDPA 5,000 EUR for sending unsolicited promotional emails without consent. The authority also found that it failed to respond to data subject access requests and did not provide a valid opt-out address for communications.GRHDPAGDPR€5,000
20 Oct 2015AEROCLUB DEL SOLAEROCLUB DEL SOL was fined EUR 600 by the AEPD for sending unsolicited emails advertising airplane insurance. The authority found this breached Article 21.1 of the LSSI on commercial communications without prior consent.ESAEPDePrivacy€600
10 Jun 2021Aeroporto Guglielmo Marconi di Bologna S.p.a.Aeroporto Guglielmo Marconi di Bologna S.p.a. was fined by the Garante EUR 40,000 for violations related to the protection of whistleblower identities. The case indicates insufficient personal data safeguards in the handling of reports.ITGaranteGDPR€40,000
17 Jan 2008Aesculapius s.r.l.Aesculapius s.r.l. was fined by the Garante for missing the deadline to notify personal data processing activities. The breach concerned obligations under the Italian Data Protection Code.ITGaranteGDPR€10,000
09 Mar 2023Aesse S.r.l.s.Aesse S.r.l.s. was fined by the Italian Garante in the amount of €3,000. The case concerned unsolicited telemarketing calls made without consent and insufficient information provided about the source of personal data.ITGaranteGDPR€3,000
27 Mar 2025AFK Letters Co LtdBetween January and September 2023, AFK Letters Co Ltd made 95,277 spam calls, leading to multiple complaints to the ICO and TPS. The company did not provide evidence that the called numbers had consented to receiving calls. The ICO imposed a £90,000 fine.GBICOGDPR€108,000
15 Oct 2024AFP GESTION DEL COLOR, S.L.AFP GESTION DEL COLOR, S.L. was fined by the AEPD in the amount of €1,000 for sending unsolicited commercial emails. The conduct breached Article 21.1 of the LSSI, which prohibits marketing communications without prior consent.ESAEPDePrivacy€1,000