Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
14 Sept 2011BONANZA DIGITAL SERVICES S.L.BONANZA DIGITAL SERVICES S.L. was fined by the AEPD €1,800 for sending unsolicited SMS messages with sexual content. The authority found this breached Article 21 of the LSSI on commercial communications sent without recipient consent.ESAEPDePrivacy€1,800
01 Jan 2014BONANZA DIGITAL SERVICES S.L.BONANZA DIGITAL SERVICES S.L. was fined by the AEPD 8,000 EUR for sending unsolicited SMS messages promoting “Tarot del Alba”. The company did not provide an opt-out mechanism, which breached Article 21.1 of the LSSI.ESAEPDePrivacy€8,000
02 Jun 2014BONANZA DIGITAL SERVICES, S.L.BONANZA DIGITAL SERVICES, S.L. was fined by the AEPD EUR 30,001 for sending unsolicited advertising SMS messages without the recipient’s consent. The company also failed to provide an opt-out mechanism, breaching the LSSI.ESAEPDePrivacy€30,001
21 May 2015BONANZA DIGITAL SERVICES, S.L.BONANZA DIGITAL SERVICES, S.L. was fined EUR 35,000 by the AEPD for sending 20 unsolicited advertising SMS messages without prior consent. The company also failed to provide an opt-out mechanism, breaching the LSSI.ESAEPDePrivacy€35,000
16 Dec 2009BonassisaLab s.r.l.BonassisaLab s.r.l. was fined by the Garante for failing to notify personal data processing activities. The breach concerned requirements under the Italian Data Protection Code.ITGaranteGDPR€10,000
11 Feb 2021Bonatti S.p.ABonatti S.p.A was fined EUR 40,000 by the Garante for violating data protection rules. The company improperly shared an employee's medical data with a third party.ITGaranteGDPR€40,000
04 Feb 2025Bonnier NewsThe Swedish Authority for Privacy Protection (IMY) imposed an administrative fine of SEK 13 million on Bonnier News for unlawful personal data processing. The Administrative Court in Stockholm reviewed the case and confirmed that the company lacked a lawful basis and that the sanction was proportionate.SEIntegritetsskyddsmyndighetenGDPR€1,138,000
26 Jun 2023Bonnier News ABBonnier News AB was fined by IMY SEK 13,000,000 for processing personal data without a legal basis. The authority found that the company profiled individuals using behavioral data to display targeted ads and for direct marketing purposes.SEIMYGDPR€1,112,000
01 Jan 2024BONTECU DISTRIBUCIONES, S.L.U.BONTECU DISTRIBUCIONES, S.L.U. was fined by the AEPD for processing personal data without consent and for failing to have proper data processing agreements in place. The case concerned a complainant who received an unsolicited contract from Factor Energía.ESAEPDGDPR€25,000
31 Mar 2021Booking.com B.V.Booking.com B.V. was fined for failing to report a personal data breach to the Dutch Data Protection Authority within 72 hours of becoming aware of it, as required by GDPR Article 33. The case concerns the controller’s obligation to notify the supervisory authority without undue delay.NLAPGDPR€475,000
22 Jun 2017Bookingshow s.p.a.Bookingshow s.p.a. was fined EUR 62,000 by the Garante for unlawfully processing personal data. The company required mandatory consent for promotional purposes during online ticket purchases, which breached data processing rules.ITGaranteGDPR€62,000
01 Jan 2022BOOKSY INTERNATIONAL SPOLKA, S.L.BOOKSY INTERNATIONAL SPOLKA, S.L. was fined by the AEPD €500 for sending unsolicited commercial SMS messages. The recipient was registered on the Robinson List, which constituted a breach of Article 21 of the LSSI.ESAEPDePrivacy€500
29 Oct 2020Borgo Fonte Scura s.r.l.Borgo Fonte Scura s.r.l. was fined by the Garante 4,000 EUR for failing to provide proper data protection information to individuals, including employees, about the use of a video surveillance system at its premises. The authority found that the required privacy notice obligations were not met.ITGaranteGDPR€4,000
04 Dec 2020BORJAMOTOR, S.A.BORJAMOTOR, S.A. was fined by the AEPD €8,000 for sending commercial SMS messages without explicit consent from recipients. The authority also identified improper consent practices for personal data processing on the company’s website.ESAEPDePrivacy€8,000
16 Jan 2026Born S.r.l.Born S.r.l. was fined by the Garante 15,000 EUR for making unsolicited promotional calls to numbers listed in the Public Register of Oppositions. The conduct breached data protection rules governing telephone marketing and the right to object.ITGaranteGDPR€15,000
16 Jun 2023BORSA MEDIC, S.L.BORSA MEDIC, S.L. was fined 10,000 EUR by the AEPD for failing to comply with a data deletion request and for sending unsolicited advertising emails after the recipient objected. The case concerns breaches of data protection and electronic commerce rules.ESAEPDePrivacy€10,000
15 Jun 2020Bostadsrättsförening HalmstadBRF Gårdsbjörken was fined by IMY for unlawful video and audio surveillance in common areas. The authority found breaches of GDPR principles, including data minimization and transparency.SEIMYGDPR€1,898
10 Jun 2024BOULANGERIE (procédure simplifiée)CNIL imposed an administrative fine of EUR 5,000 on BOULANGERIE under a simplified procedure. The record does not provide further details on the underlying infringement.FRCNILGDPR€5,000
16 Feb 2023BOX 24 2050 S.L.BOX 24 2050 S.L. was fined by the AEPD 2,000 EUR for making misleading advertising calls without prior explicit consent. The conduct breached data protection rules and the requirement for lawful processing.ESAEPDGDPR€2,000
03 Jun 2025B*** Parkraumbewirtschaftung Ges.m.b.H.The company was fined by the Austrian Data Protection Authority (DSB) for failing to cooperate during the investigation. It did not respond to multiple requests for statements or to a summons for an oral hearing, which constitutes a breach of Article 31 GDPR.ATDSBGDPR€16,000