Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
06 Feb 2024GESTIÓN DE PATRIMONIOS ANFIPOLIS SOCIEDAD DE RESPONSABILIDAD LIMITADAThe AEPD fined GESTIÓN DE PATRIMONIOS ANFIPOLIS SOCIEDAD DE RESPONSABILIDAD LIMITADA EUR 2,000 for sending unsolicited commercial communications without the recipient's consent. The authority noted that the messages were sent despite the recipient's opposition.ESAEPDePrivacy€2,000
13 Jun 2025Anonymised (HDPA 21/2025)A fine was imposed for breaching the principles of lawfulness, fairness, and transparency in data processing in connection with a video surveillance system. The case concerned improper processing of personal data through video monitoring.GRHDPAGDPR€2,000
22 Jul 2025Anonimizirano (IP-RS 0609-101/2024/5)A legal entity was fined by IP-RS for a GDPR breach involving the unauthorized disclosure of personal data, including hospital treatment details, via email. The case concerned processing that failed to meet confidentiality and access-control requirements.SIIP-RSGDPR€2,000
17 Dec 2020Ordine degli Assistenti Sociali della Regione LazioOrdine degli Assistenti Sociali della Regione Lazio was fined EUR 2,000 by the Garante. The authority found that the entity failed to respond to a request for access to personal data, which is a breach of GDPR Article 15.ITGaranteGDPR€2,000
29 Apr 2025Tirrenia Hospital S.r.l.Tirrenia Hospital S.r.l. was fined by the Garante EUR 2,000 for breaching the data processing principles set out in GDPR Article 5. The case concerned processing in the healthcare sector, where a particularly high level of compliance is required.ITGaranteGDPR€2,000
29 May 2026Unicredit Bank SAUnicredit Bank SA was fined EUR 2,000 by ANSPDCP. The authority found that the bank failed to notify a personal data breach within the required 72-hour deadline.ROANSPDCPGDPR€2,000
17 Apr 2026Sicra PressThe Garante imposed a 2,000 EUR fine on Sicra Press for using non-anonymized data in articles related to judicial matters. The authority found a breach of data protection rules.ITGaranteGDPR€2,000
22 Feb 2024BLU MANAGEMENT SPAIN, S.L.BLU MANAGEMENT SPAIN, S.L. was fined €2,000 by the AEPD for sharing a job applicant’s contact details without consent. The authority treated this as a breach of data protection rules.ESAEPDGDPR€2,000
01 Jan 2020VOLTIMUM, S.A.VOLTIMUM, S.A. was fined EUR 2,000 by the AEPD for sending commercial emails after the recipient had opted out. The authority found this to be a breach of Article 21 of the LSSI on marketing communications.ESAEPDePrivacy€2,000
04 Sept 2024Agrotikos Elaiourgikos Synetairismos StylidasAgrotikos Elaiourgikos Synetairismos Stylidas was fined EUR 2,000 by the HDPA. The authority found breaches of data minimization and transparency principles, as well as inadequate technical and organizational measures in its video surveillance system.GRHDPAGDPR€2,000
15 Apr 2021Ordine degli Avvocati di RomaOrdine degli Avvocati di Roma was fined €2,000 by the Garante for a significant delay in responding to a data subject access request. The case highlights a failure to meet the required timelines for handling access requests under data protection rules.ITGaranteGDPR€2,000
01 Sept 2025Osnovna škola XAZOP imposed a fine of EUR 2,000 on Osnovna škola X for breaching GDPR rules on personal data processing. The case involved unlawful processing of personal data, indicating a compliance failure under data protection requirements.HRAZOPGDPR€2,000
09 Mar 2023Consorzio Concessioni Reti Gas S.c.a.r.l.The Garante fined Consorzio Concessioni Reti Gas S.c.a.r.l. EUR 2,000 for GDPR breaches linked to the improper handling of email accounts and the failure to provide data processing information after an internship ended. The case highlights deficiencies in information duties and access control over personal data.ITGaranteGDPR€2,000
21 Jul 2025VIVLIOPOLEION TIS ESTIAS, I.D. KOLLAROU & SIA A.E.The company was fined by the HDPA in the amount of €2,000 for failing to build data protection into the design of its processing and for not applying privacy by default. The authority treated this as a breach of GDPR requirements on privacy by design and by default.GRHDPAGDPR€2,000
17 Feb 2025Meedea Construct Prest SRLThe company was fined for violating the principles and lawfulness of personal data processing, specifically Articles 6 and 9 of the GDPR. A corrective measure was also imposed to ensure GDPR compliance in data collection and processing and to reduce the risk of unauthorized access and disclosure.ROANSPDCPGDPR€2,000
10 Jun 2020Istituto autonomo per le case popolari della provincia di IserniaIstituto autonomo per le case popolari della provincia di Isernia was fined EUR 2,000 by the Garante. The authority found that personal data, including health information, had been published on the institutional website without a proper legal basis.ITGaranteGDPR€2,000
09 May 2024IRIDEX GROUP SALUBRIZARE SRLIRIDEX GROUP SALUBRIZARE SRL was fined by ANSPDCP 2,000 EUR for sending a collective email to clients with recipients' email addresses visible. The incident resulted in unauthorized disclosure of personal data.ROANSPDCPGDPR€2,000
21 May 2021COOPERA RC SERVICES, S.L.COOPERA RC SERVICES, S.L. was fined by the AEPD 2,000 EUR for failing to provide the contact details needed to exercise data protection rights. The authority found a breach of the information obligations under Article 13 GDPR.ESAEPDGDPR€2,000
23 Jun 2020COMUNIDAD DE PROPIETAROS R.R.R.The entity was fined for installing video surveillance cameras without the required informational signage. The case concerned a breach of data protection rules and the obligation to properly inform individuals subject to monitoring.ESAEPDGDPR€2,000
18 Jan 2021MEJORFRESCO TIENDA ONLINE, S.L.MEJORFRESCO TIENDA ONLINE, S.L. was fined by the AEPD EUR 2,000 for sending advertising emails without the recipient's consent. The case concerned Article 21 of the LSSI and reflects unlawful direct marketing practices.ESAEPDePrivacy€2,000