Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
01 Jan 2022B.B.B.B.B.B. was fined 2,000 EUR by the AEPD. The authority found that the company forwarded emails containing personal data without proper authorization, in breach of Article 6 of the GDPR.ESAEPDGDPR€2,000
12 May 2020B.B.B.B.B.B. was fined by the AEPD in the amount of 2,000 EUR for installing a video surveillance system without justified cause. The measure infringed a tenant’s privacy and resulted in unlawful processing of personal data.ESAEPDGDPR€2,000
16 Feb 2023BOX 24 2050 S.L.BOX 24 2050 S.L. was fined by the AEPD 2,000 EUR for making misleading advertising calls without prior explicit consent. The conduct breached data protection rules and the requirement for lawful processing.ESAEPDGDPR€2,000
23 Dec 2021Federación Estatal de Servicios, Movilidad y Consumo de la UGT (FESMC-UGT)FESMC-UGT was fined 2,000 EUR by the AEPD for sending emails to employees’ corporate addresses without proper authorization. The authority found this to be a breach of data protection rules.ESAEPDGDPR€2,000
15 Jan 2026CANDIDATS AUX ÉLECTIONS LÉGISLATIVES (procédure simplifiée)CNIL imposed an administrative fine of 2,000 EUR on CANDIDATS AUX ÉLECTIONS LÉGISLATIVES (procédure simplifiée) and issued an injunction. The case concerns a breach of rules supervised by CNIL.FRCNILGDPR€2,000
15 Mar 2021Geanonimiseerd (APD 36/2021)A school used Smartschool to conduct a “well-being” survey among minor students without parental consent. The authority found that several GDPR provisions governing the processing of children’s data were breached.BEAPDGDPR€2,000
13 Feb 2025ADVFAST s.r.l.s.ADVFAST s.r.l.s. was fined by the Garante for failing to respond to information requests concerning repeated unsolicited telemarketing calls. The case indicates a failure to cooperate with the supervisory authority.ITGaranteGDPR€2,000
07 Nov 2022Compania Națională Poșta Română SAIn October 2022, ANSPDCP completed an investigation into Compania Națională Poșta Română SA and found a breach of GDPR provisions. The company was fined EUR 2,000 following a data security incident reported by a data operator.ROANSPDCPGDPR€2,000
13 Feb 2023B.B.B.B.B.B. was fined by the AEPD in the amount of EUR 2,000 for breaching Article 6 of the GDPR. The case concerned the unauthorized dissemination of a video on social media platforms, including Twitter.ESAEPDGDPR€2,000
19 Dec 2024MEDECIN GENERALISTE (procédure simplifiée)The CNIL imposed EUR 2,000 on MEDECIN GENERALISTE under a simplified procedure as a liquidation of a penalty payment. The decision relates to failure to comply with a prior obligation within the required timeframe.FRCNILGDPR€2,000
20 Apr 2021B.B.B.The entity was fined for not providing an adequate privacy policy on its website. This constituted a breach of Article 13 of the GDPR, which requires proper information to be provided to data subjects.ESAEPDGDPR€2,000
21 Dec 2023Impresa individuale Macelleria Salumeria HalalThe Garante fined the owner of Impresa individuale Macelleria Salumeria Halal EUR 2,000 for operating a video surveillance system without adequate informational signage. The authority found a breach of GDPR transparency and data processing requirements.ITGaranteGDPR€2,000
11 Jun 2024DIGITAL FLOW, S.L.DIGITAL FLOW, S.L. was fined EUR 2,000 by the AEPD for sending emails without an unsubscribe option. The authority also found that the company failed to provide a valid contact for exercising data deletion rights.ESAEPDePrivacy€2,000
20 May 2021B.B.B.The entity did not provide the complainant with information about data processing or the ability to exercise rights after receiving a CV via WhatsApp in response to a job offer. AEPD imposed a fine of EUR 2,000 for breaching transparency obligations.ESAEPDGDPR€2,000
18 Sept 2024Paula Stradiņa klīniskā universitātes slimnīcaA fine of EUR 2,000 was imposed. The decision has entered into force.LVDVIGDPR€2,000
15 Nov 2022GESTIÓN DE PATRIMONIOS ANFIPOLIS SL.The entity was fined for sending unsolicited commercial emails despite the recipient's explicit objection. The authority found a breach of Article 21 of the LSSI.ESAEPDePrivacy€2,000
07 Sept 2023ISRA Center Marketing Research SRLIn August 2023, the Romanian supervisory authority ANSPDCP completed an investigation into ISRA Center Marketing Research SRL. It found a GDPR violation and imposed a fine of EUR 2,000.ROANSPDCPGDPR€2,000
07 Dec 2023Hora Credit IFN SAThe authority fined Hora Credit IFN SA for sending documents containing another client's personal data to the complainant's email address. The incident indicates a breach of confidentiality and proper personal data processing requirements.ROANSPDCPGDPR€2,000
12 Mar 2026Hanako s.r.l.Hanako s.r.l. was fined by the Garante EUR 2,000 for operating a video surveillance system without ensuring GDPR compliance. The authority cited inadequate security measures and failure to provide sufficient information to employees.ITGaranteGDPR€2,000
11 Feb 2022MOVALIA TRASLADOS, S.L.U.MOVALIA TRASLADOS, S.L.U. was fined EUR 2,000 by the AEPD for failing to allow users to give free and voluntary consent for data processing. The authority also found that the company did not properly inform affected individuals about the processing of their data, in breach of GDPR and LOPDGDD requirements.ESAEPDGDPR€2,000