Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
29 May 2023SERVICIOS E INTERVENCIONES EN EDIFICACION DEL MEDITERRÁNEO, S.L.The company published an image on its website without the individual's express consent. The authority treated the case as a repeat infringement because the company had previously been sanctioned for the same conduct.ESAEPDGDPR€2,000
06 Mar 2025SERVICIOS DE INTEGRACIÓN DE ANDALUCÍASERVICIOS DE INTEGRACIÓN DE ANDALUCÍA was fined €2,000 by the AEPD for adding an employee’s personal phone number to a work WhatsApp group without consent. The authority found a breach of the GDPR lawful-basis requirement under Article 6(1).ESAEPDGDPR€2,000
01 Jan 2017SERVICIOS DE INFORMACIÓN SOBRE LOS FICHEROS DE MOROSOS S.L.The entity sent commercial emails and SMS without proper consent and did not honor recipients’ objections. These actions breached data protection rules.ESAEPDePrivacy€1,000
04 Aug 2014SERVICIOS DE DEPILACION BLOC, S.L.SERVICIOS DE DEPILACION BLOC, S.L. was fined by the AEPD EUR 3,000 for sending unsolicited commercial SMS messages to a former client. The authority found that this conduct breached Article 21 of the LSSI on marketing communications.ESAEPDePrivacy€3,000
04 Aug 2014SERVICIOS DE DEPILACION BLOC, S.L.SERVICIOS DE DEPILACION BLOC, S.L. was fined by the AEPD 4,000 EUR for sending unsolicited commercial SMS messages to a former client. The conduct breached Article 21 of the LSSI on marketing communications without prior consent.ESAEPDePrivacy€4,000
08 Oct 2020Servicio de Alojamientos Responsables, S.L.The entity was fined by the AEPD 6,000 EUR for processing personal data without a legal basis. The breach involved signing a contract on behalf of an individual without authorization.ESAEPDGDPR€6,000
10 Oct 2024Service Box Group LimitedService Box Group Limited made 5,361 marketing calls to individuals in breach of regulation 21 of PECR. The ICO imposed a fine of GBP 40,000 and issued an enforcement notice.GBICOePrivacy€47,796
13 Sept 2017Serval s.r.l.Serval s.r.l. was fined by the Garante in the amount of €10,000 for failing to adopt minimum security measures. The authority also found that employees were not appointed as data processors, in breach of the Italian Data Protection Code.ITGaranteGDPR€10,000
01 Oct 2024SERVACE, S.L.SERVACE, S.L. was fined by the AEPD EUR 1,400 for using an employee’s personal email address for work purposes without consent. The authority found this breached GDPR Articles 6(1) and 5(1)(f).ESAEPDGDPR€1,400
12 Nov 2014Sergio FioreseSergio Fiorese was fined EUR 2,400 by the Garante for failing to provide data subjects with the required information about the processing of personal data. The breach concerned a video surveillance system at the association “Sottosopra”.ITGaranteGDPR€2,400
17 Oct 2024Serfin 97 S.r.l.Serfin 97 S.r.l. was fined EUR 60,000 by the Garante for unlawful processing of personal data. The company used a third party’s email address to contact a debtor for debt recovery purposes, which breached data protection rules.ITGaranteGDPR€60,000
29 Mar 2018SERCOM S.r.l.SERCOM S.r.l. was fined EUR 20,000 by the Garante. The authority found that the company failed to notify changes to its name and the cessation of data processing activities related to economic solvency risk.ITGaranteGDPR€20,000
04 Aug 2022Sephora Cosmetics România SASephora Cosmetics România SA was fined EUR 2,000 by ANSPDCP for violating GDPR provisions. The case concerned non-compliance with personal data protection requirements.ROANSPDCPGDPR€2,000
07 Jul 2022Senseonics Inc.Senseonics Inc. was fined EUR 45,000 by the Garante for violations related to the processing of personal data. The authority cited issues with data integrity and confidentiality, including health data.ITGaranteGDPR€45,000
07 Mar 2025SENDING TRANSPORTE Y COMUNICACIÓN, S.A.SENDING TRANSPORTE Y COMUNICACIÓN, S.A. was fined EUR 80,000 by the AEPD for breaching GDPR Articles 28(2) and 28(4). The company subcontracted data processing without the required authorization.ESAEPDGDPR€80,000
14 Dec 2017SEMS – Servizi per la mobilità sostenibile S.r.l.SEMS – Servizi per la mobilità sostenibile S.r.l. was fined EUR 20,000 by the Garante. The authority found that the company failed to meet notification obligations linked to the installation of satellite tracking devices in its vehicle fleet, in breach of data protection rules.ITGaranteGDPR€20,000
01 Oct 2015Semplice viaggi s.r.l.Semplice viaggi s.r.l. was fined EUR 6,400 by the Garante for providing insufficient information to users on its website and for pre-setting consent to the processing of personal data for promotional purposes. The authority found these practices to be in breach of data protection rules.ITGaranteGDPR€6,400
08 Jul 2025Selgros Cash & Carry SRLIn June 2025, ANSPDCP completed an investigation at Selgros Cash & Carry SRL and found a GDPR violation. The operator was fined EUR 3,000.ROANSPDCPGDPR€3,000
15 Sept 2016SELF TRADE BANK, SAUSELF TRADE BANK, SAU was fined by the AEPD EUR 2,000 for sending unsolicited commercial emails to a customer. The customer had not authorized the use of their personal data for promotional purposes, which breached Article 21.1 of the LSSI.ESAEPDePrivacy€2,000
06 Jul 2006Selework s.a.s.Selework s.a.s. was fined EUR 258 by the Garante for failing to provide candidates with adequate information about the processing of their personal data in job advertisements. The authority found a breach of Article 13 of the Codice Privacy.ITGaranteGDPR€258