Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
05 May 2022JOYPAZAR, S.A.JOYPAZAR, S.A. was fined by the AEPD for reinstalling a surveillance camera that captured images of a public children's park. The authority found this to be a breach of data protection rules.ESAEPDGDPR€2,000
01 Jan 2023KUGELCHEN PROPIERTIES, S.L.KUGELCHEN PROPIERTIES, S.L. was fined by the AEPD EUR 2,000 for processing personal data without consent. The company continued charging a customer despite requests to delete personal data and stop transactions.ESAEPDGDPR€2,000
19 May 2011Anonymised (HDPA 59/2011)The company was fined for unlawfully processing email addresses without prior consent. The authority found this to be a breach of data protection law.GRHDPAGDPR€2,000
12 Dec 2024Anonymisiert (DSB 2024-0.796.258)The individual unlawfully processed intimate photos by transferring and storing them without the data subject’s consent. This breached GDPR principles of lawfulness, purpose limitation, and data minimization.ATDSBGDPR€2,000
16 Dec 2021Sindicato Intersectorial Trabajadores/as Provincia de AlicanteThe labor union was fined by the AEPD for breaching data protection rules. The case concerned the publication of committee meeting minutes containing signatures on a union notice board and in a WhatsApp group.ESAEPDGDPR€2,000
09 Jun 2021S.C.The operator was fined by ANSPDCP for failing to provide requested information to the supervisory authority. This constituted a breach of GDPR requirements.ROANSPDCPGDPR€2,000
17 Jul 2025Comune di Tocco da CasauriaComune di Tocco da Casauria was fined EUR 2,000 by the Garante for publishing personal data on its institutional website. The authority found that the processing did not comply with the principles of lawfulness, fairness, transparency, and data minimization.ITGaranteGDPR€2,000
17 Mar 2021VASCO ANDALUZA DE INVERSIONES, S.L.VASCO ANDALUZA DE INVERSIONES, S.L. was fined by the AEPD 2,000 EUR for unlawfully sharing personal data with third parties without informing the data subject. The authority found this conduct to be in breach of Article 6 of the GDPR.ESAEPDGDPR€2,000
11 Jan 2024Libero Consorzio comunale di CaltanissettaLibero Consorzio comunale di Caltanissetta was fined by the Garante EUR 2,000 for breaching Article 37(7) of the GDPR. The decision also orders publication of the sanction on the authority’s website.ITGaranteGDPR€2,000
22 Feb 2024Unica s.r.l.s.Unica s.r.l.s. was fined by the Garante EUR 2,000 for using a facial recognition system to record employee attendance without a proper legal basis. The authority found that the processing of biometric data breached GDPR requirements.ITGaranteGDPR€2,000
02 Oct 2023COMUNIDAD DE PROPIETARIOS A.A.A.The president of a homeowners' association shared a bank receipt containing personal data in a WhatsApp group. AEPD found a breach of confidentiality principles under GDPR and imposed a EUR 2,000 fine.ESAEPDGDPR€2,000
18 Oct 2022SC Materiale Constructii Online SRLSC Materiale Constructii Online SRL was fined by ANSPDCP in the amount of EUR 2,000 for violating the General Data Protection Regulation (GDPR). The case concerned non-compliance with personal data protection requirements.ROANSPDCPGDPR€2,000
01 Jan 2024AD735 DATA MEDIA ADVERTISING, S.L.AD735 DATA MEDIA ADVERTISING, S.L. was fined by the AEPD 2,000 EUR for improperly accessing personal data linked to a phone number without the owner's consent. The authority found a breach of Article 7 of the GDPR.ESAEPDGDPR€2,000
04 Feb 2022CORON ISLAND SLUCORON ISLAND SLU was fined by the AEPD 2,000 EUR for requiring a customer’s phone number when issuing an invoice. The authority found that the data was not necessary for invoicing, which breached the data minimization principle.ESAEPDGDPR€2,000
27 Sept 2016SERVIHABITAT SERVICIOS INMOBILIARIOS, S.L.SERVIHABITAT SERVICIOS INMOBILIARIOS, S.L. was fined by the AEPD EUR 2,000 for sending unsolicited commercial communications by email. The authority found this breached Article 21.1 of the LSSI.ESAEPDePrivacy€2,000
01 Jan 2019CAFE BAR NINA (Nina Cb)CAFE BAR NINA was fined €2,000 by the AEPD for installing an unauthorized surveillance camera. The conduct breached data protection requirements.ESAEPDGDPR€2,000
14 Aug 2022INVERTIA TENERIFE 2019, S.L.INVERTIA TENERIFE 2019, S.L. was fined 2,000 EUR by the AEPD for failing to inform data subjects about the processing of their personal data. The authority treated this as a breach of Article 13 GDPR.ESAEPDGDPR€2,000
17 Mar 2021GERCO FIT, S.L.GERCO FIT, S.L. was fined by the AEPD in the amount of 2,000 EUR for processing personal data without proper consent. The authority found a breach of Article 6 of the GDPR.ESAEPDGDPR€2,000
20 Jun 2022Asociația de Proprietari Aviației ParkThe operator was fined by ANSPDCP for violating the GDPR. The case concerned non-compliance with personal data protection requirements.ROANSPDCPGDPR€2,000
29 May 2023SERVICIOS E INTERVENCIONES EN EDIFICACION DEL MEDITERRÁNEO, S.L.The company published an image on its website without the individual's express consent. The authority treated the case as a repeat infringement because the company had previously been sanctioned for the same conduct.ESAEPDGDPR€2,000