Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
20 Apr 2022Anonymisé (CNPD decision-09-fr-2022)The CNPD fined the company EUR 2,000 for failing to respond in time to a data subject access request and for not providing all required information under GDPR Articles 12 and 15. The company also failed to cooperate with the supervisory authority, contrary to Article 31 GDPR.LUCNPDGDPR€2,000
09 Sept 2022Anonymised (HDPA 48/2022)The mayor of a municipality was fined for sending unsolicited emails without the recipients’ consent. The authority found breaches of GDPR transparency and purpose limitation principles.GRHDPAGDPR€2,000
09 Jun 2021INMOPISO ZARAGOZA, S.L.INMOPISO ZARAGOZA, S.L. was fined EUR 2,000 by the AEPD for failing to provide data protection information to a customer who made a deposit for a property purchase. The case concerns a breach of the transparency and information duty owed to the data subject.ESAEPDGDPR€2,000
06 Jul 2023Provvedimento del 6 luglio 2023 [9925450The Garante imposed a EUR 2,000 fine on an individual for posting images of other people on social media without their consent. The authority found a breach of GDPR rights, including the rights to erasure and objection.ITGaranteGDPR€2,000
11 Sept 2020BODEGAS DINASTIA, S.L.BODEGAS DINASTIA, S.L. was fined by the AEPD EUR 2,000 for non-compliance with data protection rules on its websites. The issues concerned the privacy policy and the way cookie consent was obtained.ESAEPDePrivacy€2,000
04 Aug 2025Linea Stampalibera Società Cooperativa r.l.The Garante imposed a EUR 2,000 fine on Linea Stampalibera Società Cooperativa r.l. for unlawfully disseminating personal data, including health information, on its online news site. The authority found a breach of data protection rules.ITGaranteGDPR€2,000
21 Mar 2024Estlevante s.r.l.s.The Garante imposed a EUR 2,000 fine on Estlevante s.r.l.s. for failing to provide the required privacy notice for its video surveillance system. The breach concerned Article 13 of the GDPR.ITGaranteGDPR€2,000
28 Apr 2022Comune di PartannaComune di Partanna was fined by the Garante for breaching data protection principles, including lawfulness, fairness, transparency, and data minimization. The case concerned the improper handling of personal data in a disciplinary procedure.ITGaranteGDPR€2,000
16 Sept 2021Istituto Comprensivo - IC Cosenza III “V. Negroni”Istituto Comprensivo - IC Cosenza III “V. Negroni” was fined by the Garante 2,000 EUR for unlawful processing of personal data and inadequate data protection. The authority also noted that personal data were made accessible online, increasing the risk to affected individuals.ITGaranteGDPR€2,000
08 Jun 2021IMAGINA FRAN SPORT, S.L.IMAGINA FRAN SPORT, S.L. was fined 2,000 EUR by the AEPD for not having an updated privacy policy on its website. The authority found a breach of the information obligations under GDPR Article 13.ESAEPDGDPR€2,000
13 Mar 2025Istituto Alberghiero Mediterraneo di Pulsano (TA)Istituto Alberghiero Mediterraneo di Pulsano was fined EUR 2,000 by the Garante. The authority found breaches of the principles of lawfulness, fairness, and transparency in personal data processing.ITGaranteGDPR€2,000
15 Sept 2022Sofisticated Luxury Flats s.r.l.Sofisticated Luxury Flats s.r.l. was fined €2,000 by the Garante for using a biometric device to monitor employee attendance without a proper legal basis. The authority found that this practice breached data protection rules.ITGaranteGDPR€2,000
06 Oct 2014TROPIAUTO MOTRIL SATROPIAUTO MOTRIL SA was fined by the AEPD EUR 2,000 for sending unsolicited advertising emails after the recipient had exercised the right to opt out. The authority found a breach of Article 21 of the LSSI.ESAEPDePrivacy€2,000
31 May 2021Anonymizováno (ÚOOÚ UOOU-03580/20-23)The entity was fined for continuing to process personal data for marketing purposes despite the data subject's objection and request for erasure. The authority found this to be a breach of GDPR Article 21.CZUOOUGDPR€79
29 Apr 2025Comune di NoliComune di Noli was fined EUR 2,000 by the Garante for failing to ensure lawful, fair, and transparent processing of personal data. The authority also found a breach of data minimization because unauthorized access to unredacted images was possible through an online portal.ITGaranteGDPR€2,000
11 Jan 2024Provincia di CatanzaroThe Garante fined Provincia di Catanzaro EUR 2,000 for violations of data protection obligations under Article 37 GDPR. The case concerned non-compliance with requirements related to the designation of a data protection officer.ITGaranteGDPR€2,000
10 Feb 2025PPC Energie Muntenia SAThe operator was fined by ANSPDCP in the amount of EUR 2,000 for violating GDPR provisions. The case concerns non-compliance with personal data protection requirements.ROANSPDCPGDPR€2,000
11 Nov 2021COMUNIDAD DE PROPIETARIOS R.R.R.The community of property owners was fined by the AEPD EUR 2,000 for sharing residents’ personal data with a security company without proper authorization or a contract. The disclosure included names, addresses, and financial information.ESAEPDGDPR€2,000
11 Oct 2023B.B.B.The entity installed surveillance cameras without consent in a rented equestrian club. The recordings captured minors and disabled individuals, which constituted a privacy violation.ESAEPDGDPR€2,000
28 Jun 2022AUDIO STOCK, S.L.AUDIO STOCK, S.L. was fined €2,000 by the AEPD for sending commercial SMS messages despite the recipient's objection. The authority found this conduct breached Article 21 of the LSSI on unsolicited commercial communications.ESAEPDePrivacy€2,000