Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
03 Sept 2025SheinCNIL imposed a 176,000,000 USD fine on Shein for using cookies without valid user consent. The case concerns breaches of consent and transparency requirements for online tracking.FRCNILePrivacy€151,034,000
14 Sept 2023Shardana Working Soc. Coop. a r.l.Shardana Working Soc. Coop. a r.l. was fined by the Garante 20,000 EUR for failing to fully comply with data access requests. The authority found a breach of Article 15 GDPR.ITGaranteGDPR€20,000
01 Jan 2018SHANA RETAIL S.L.SHANA RETAIL S.L. was fined by the AEPD for improperly disposing of documents containing personal data. The breach concerned data protection rules and the need to prevent unauthorized disclosure of information.ESAEPDGDPR€15,000
21 Sept 2023SGS Home Protect LtdSGS Home Protect Ltd made 24,214 marketing calls to individuals in breach of regulation 21 of PECR. The ICO imposed a fine of 70,000 GBP and issued an enforcement notice.GBICOePrivacy€80,724
01 Jan 2025SGKLegalThe Greek data protection authority, ΑΠΔΠΧ, imposed a fine of EUR 22,000 on SGKLegal for a GDPR violation. The case involved recorded conversations and deficiencies in personal data protection compliance.GRΑρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (ΑΠΔΠΧ)GDPR€22,000
14 Mar 2013Sfera s.r.l.Sfera s.r.l. was fined by the Garante 2,400 EUR for collecting personal data through a website form without providing the required privacy notice. The conduct breached the Italian Data Protection Code.ITGaranteGDPR€2,400
23 Feb 2021SFAM ESPAÑA GENERAL S.L.SFAM ESPAÑA GENERAL S.L. was fined by the AEPD in the amount of 5,000 EUR. The case concerned unauthorized charges to a customer's bank account after a purchase, raised in a complaint about data misuse.ESAEPDGDPR€5,000
02 Mar 2011Sestrieres S.p.A.Sestrieres S.p.A. was fined by the Italian Garante for failing to provide adequate information to individuals about the processing of their personal data when using ski lift turnstiles. The authority found a breach of data protection rules.ITGaranteGDPR€12,000
21 Jan 2010Servizi sanitari s.r.l. – Istituto cardiovascolare CamogliServizi sanitari s.r.l. was fined by the Garante 10,000 EUR for violations related to the processing of personal data without the required notification. The case concerned obligations under the Italian Data Protection Code.ITGaranteGDPR€10,000
06 Oct 2022Servizio Idrico Integrato S.c.p.a.Servizio Idrico Integrato S.c.p.a. was fined by the Garante EUR 15,000 for failing to implement adequate security measures to protect the personal data of users registered on its website. The case concerned insufficient safeguards for data processed online.ITGaranteGDPR€15,000
01 Oct 2013SERVITEL TEXNOX S.L.SERVITEL TEXNOX S.L. was fined EUR 600 by the AEPD for sending unsolicited commercial emails without recipient consent. The conduct breached Article 21 of the LSSI on electronic marketing communications.ESAEPDePrivacy€600
27 Sept 2016SERVIHABITAT SERVICIOS INMOBILIARIOS, S.L.SERVIHABITAT SERVICIOS INMOBILIARIOS, S.L. was fined by the AEPD EUR 2,000 for sending unsolicited commercial communications by email. The authority found this breached Article 21.1 of the LSSI.ESAEPDePrivacy€2,000
01 Jan 2015SERVICIOS VARIOS 8020, S.L.SERVICIOS VARIOS 8020, S.L. was fined by the AEPD in the amount of 5,000 EUR for sending unsolicited commercial emails. The messages did not include an unsubscribe option for recipients, which breached Article 21 of the LSSI.ESAEPDePrivacy€5,000
20 May 2022SERVICIOS PROFESIONALES LA PARADA S.L.The entity installed a video surveillance system that recorded public areas without informing the affected individuals. This breached data protection rules and led to a fine imposed by the AEPD.ESAEPDGDPR€800
19 Feb 2021SERVICIOS LOGÍSTICOS MARTORELL SIGLO XXI, S.L.The company was fined by the AEPD for deploying a biometric fingerprint system for employee attendance control without carrying out a data protection impact assessment. The authority found this to be a breach of Article 35 GDPR because the processing involved biometric data requiring prior risk assessment.ESAEPDGDPR€20,000
18 May 2022SERVICIOS INTEGRALES DEL HOGAR TENERIFE, S.L.The company was fined by the AEPD for unlawfully processing personal data. The breach involved sending a wage garnishment notice via WhatsApp without proper authorization or legal basis.ESAEPDGDPR€5,000
16 Apr 2025SERVICIOS INMOBILIARIOS Y GESTIÓN RCL-MADRID, S.L.SERVICIOS INMOBILIARIOS Y GESTIÓN RCL-MADRID, S.L. was fined 600 EUR by the AEPD. The authority found that the company did not provide access to personal data and other information requested during the investigation. The conduct breached Article 58(1) of the GDPR.ESAEPDGDPR€600
17 Jan 2022SERVICIOS FINANCIEROS CARREFOUR, EFC., S.A.SERVICIOS FINANCIEROS CARREFOUR, EFC., S.A. was fined 20,000 EUR by the AEPD. The authority found that the company failed to properly handle a data subject’s request for erasure, which led to continued processing of personal data despite the prior deletion request.ESAEPDGDPR€20,000
06 Aug 2025SERVICIOS FINANCIEROS CARREFOUR, E.F.C., S.ASERVICIOS FINANCIEROS CARREFOUR, E.F.C., S.A suffered a data breach involving unauthorized access to and exfiltration of customer personal data, including payment information. The incident was linked to phishing and account compromise, resulting in the loss of sensitive data.ESAEPDGDPR€2,500,000
25 Feb 2025SERVICIOS ESPECIALES, S.A.SERVICIOS ESPECIALES, S.A. was fined by the AEPD 200,000 EUR for disclosing the identity of a complainant in a workplace harassment case. The authority found a breach of personal data confidentiality principles.ESAEPDGDPR€200,000