Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
20 Sept 2012Policlinico Sassarese s.p.a.Policlinico Sassarese s.p.a. was fined EUR 64,000 by the Garante for inadequate data protection measures. The authority cited insufficient video surveillance notices and missing consent documentation for the processing of sensitive data.ITGaranteGDPR€64,000
05 Nov 2015Enterprise Service s.r.l.Enterprise Service s.r.l. was fined EUR 62,000 by the Garante. The sanction concerned sending unsolicited promotional faxes without prior consent, in breach of privacy rules.ITGaranteGDPR€62,000
22 Jun 2017Bookingshow s.p.a.Bookingshow s.p.a. was fined EUR 62,000 by the Garante for unlawfully processing personal data. The company required mandatory consent for promotional purposes during online ticket purchases, which breached data processing rules.ITGaranteGDPR€62,000
09 May 2018Mercuri SalvatoreMercuri Salvatore was fined by the Garante EUR 60,000 for making unsolicited promotional calls to individuals whose phone numbers were listed in the opposition register. This conduct infringed their right to object to such communications.ITGaranteGDPR€60,000
27 Oct 2014TRADEINN RETAIL SERVICES, S.L.TRADEINN RETAIL SERVICES, S.L. was fined EUR 60,000 by the AEPD for sending unsolicited commercial emails to a non-customer. The authority found this breached Article 21 of the LSSI on electronic marketing communications.ESAEPDePrivacy€60,000
01 Jan 2019XFERA MÓVILES, S.A. (YOIGO)XFERA MÓVILES, S.A. (YOIGO) was fined by the AEPD EUR 60,000 for incorrectly including personal data in a creditworthiness file. The authority found a breach of the GDPR accuracy principle under Article 5(1)(d).ESAEPDGDPR€60,000
01 Jan 2019AVON COSMETICS SAUAVON COSMETICS SAU was fined by the AEPD 60,000 EUR for improper processing of personal data. The company included an individual in a creditworthiness file without first verifying the person’s identity.ESAEPDGDPR€60,000
01 Jan 2019VIAQUA XESTIÓN INTEGRAL DE AUGAS DE GALICIA, S.A.The company changed contract data without authorization, which constituted a breach of Article 6 of the GDPR. The AEPD imposed a fine of 60,000 EUR.ESAEPDGDPR€60,000
12 Apr 2018ABC OROLOGERIA E TELEFONIA S.r.l.ABC OROLOGERIA E TELEFONIA S.r.l. was fined by the Garante in the amount of 60,000 EUR for activating SIM cards without the express consent of the individuals to whom the cards were registered. The case concerns a breach of data protection rules.ITGaranteGDPR€60,000
19 Dec 2024Altroconsumo Edizioni S.r.l.Altroconsumo Edizioni S.r.l. was fined by the Garante EUR 60,000 for sending unsolicited marketing emails despite unsubscribe requests. The authority also found deficiencies in obtaining valid consent and in the handling of personal data by third-party affiliates involved in the campaign.ITGaranteGDPR€60,000
10 Oct 2013TeleTu s.p.a.TeleTu s.p.a. was fined 60,000 EUR by the Italian Garante. The sanction concerned unsolicited promotional phone calls made without the required consent of the data subject.ITGaranteGDPR€60,000
22 Dec 2023HISPAPOST, S.A.HISPAPOST, S.A. was fined EUR 60,000 by the AEPD for failing to properly safeguard and handle personal data. The incident resulted in the abandonment of 1,404 letters containing personal information, indicating inadequate data protection procedures.ESAEPDGDPR€60,000
25 Jan 2018Provincia di Reggio CalabriaProvincia di Reggio Calabria was fined by the Garante 60,000 EUR for publishing special-category personal data, including health information, on its institutional website. The disclosure breached data protection rules and triggered supervisory enforcement.ITGaranteGDPR€60,000
14 Apr 2025DPP Law LtdThe UK Information Commissioner fined law firm DPP Law Ltd 60,000 GBP for breaches of Articles 5(1)(f), 32(1), 32(2) and 33(1) of the UK GDPR. The infringements occurred between 25 May 2018 and 17 July 2022. The case concerned inadequate security measures and incident reporting obligations.GBICOGDPR€69,456
18 Feb 2021INFORMÁTICA MÉDICA, S.L.INFORMÁTICA MÉDICA, S.L. was fined by the AEPD 60,000 EUR for failing to have a proper data processing agreement with its processor, OUTENUVE. The authority treated this as a breach of Article 28 GDPR.ESAEPDGDPR€60,000
18 Jan 2018C.S. GROUP S.p.a.C.S. GROUP S.p.a. was fined by the Italian Garante in the amount of €60,000. The case concerned profiling and the processing of personal data without a proper legal basis in connection with vehicle rental services.ITGaranteGDPR€60,000
25 Jan 2018Avis Budget Italia s.p.a.Avis Budget Italia s.p.a. was fined EUR 60,000 by the Garante for improper installation and notification of geolocation devices on its vehicle fleet. The authority found that the company did not comply with data protection requirements.ITGaranteGDPR€60,000
01 Jan 2020XFERA MÓVILES, S.A. (MASMOVIL)XFERA MÓVILES, S.A. (MASMOVIL) was fined by the AEPD for processing personal data without a lawful basis, in breach of Article 6 GDPR. The case indicates that the company lacked a valid legal ground for the processing activity.ESAEPDGDPR€60,000
02 Dec 2021Teaching CouncilThe Irish DPC fined Teaching Council EUR 60,000 in inquiry IN-20-4-1. The fine has been collected.IEDPCGDPR€60,000
17 May 2023Fabio Giovanni PettaFabio Giovanni Petta was fined by the Garante 60,000 EUR for the unauthorized publication of personal data, including names, addresses, and phone numbers, on www.trovanumeri.com. The authority also noted continued processing of the data despite a prior prohibition. The case constitutes a GDPR violation.ITGaranteGDPR€60,000