Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
24 Apr 2013Free Time s.r.l.Free Time s.r.l. was fined EUR 54,000 by the Italian Garante. The case concerned the registration of numerous phone cards to unaware third parties without providing the required information on data processing.ITGaranteGDPR€54,000
20 Mar 2008GS S.p.A.GS S.p.A. was fined for collecting personal data in connection with a loyalty card program without providing adequate notice to data subjects. The authority found a breach of Article 13 of the Italian Data Protection Code.ITGaranteGDPR€54,000
11 Dec 2008Eutelia S.p.A.Eutelia S.p.A. was fined by the Garante for processing personal data without providing the required privacy notice. The breach occurred during the activation of an unsolicited telephone service and concerned Article 13 of the Italian Data Protection Code.ITGaranteGDPR€54,000
21 Mar 2013Compu & Games srlCompu & Games srl was fined EUR 54,000 by the Garante. The company registered numerous phone cards to unaware third parties without providing the required data protection information.ITGaranteGDPR€54,000
23 May 2022ANOIXISThe fine was imposed for sending unsolicited SMS messages for direct marketing without prior consent. The company also failed to provide a valid opt-out address, affecting data subjects’ rights of access and objection.GRHDPAePrivacy€54,000
08 Feb 2007RFI S.p.A.RFI S.p.A. was fined EUR 54,000 by the Garante for failing to provide the required data protection information to individuals covered by video surveillance at several train stations. The authority found a breach of data protection rules.ITGaranteGDPR€54,000
26 Feb 2019телекомуникационен операторThe telecommunications operator was fined BGN 53,000 by the CPDP for processing personal data without consent. The case involved changing a subscription plan to a prepaid service without the data subject's knowledge or agreement.BGCPDPGDPR€27,099
20 Jan 2015SYNERTEC GROUP S.L.SYNERTEC GROUP S.L. was fined by the AEPD in the amount of €52,000 for sending unsolicited commercial emails. The conduct breached Article 21 of the LSSI, which restricts marketing communications without prior consent.ESAEPDePrivacy€52,000
02 Apr 2020XFERA MÓVILES, S.A.XFERA MÓVILES, S.A. was fined EUR 52,000 by the AEPD for sending SMS messages to a complainant about another customer's unpaid bills. The authority found that this disclosure breached data protection rules.ESAEPDGDPR€52,000
24 Jan 2013Gruppo Finelco s.p.a.Gruppo Finelco s.p.a. was fined EUR 52,000 by the Garante for processing personal data without providing adequate information to data subjects. The company also failed to notify the Garante about profiling activities carried out through its websites.ITGaranteGDPR€52,000
16 Dec 2021LiikennevakuutuskeskusThe entity was fined for collecting patient data excessively for insurance claim resolution. The authority found breaches of data minimization and fairness principles.FITSVGDPR€52,000
01 Mar 2018Priolo Servizi S.c.p.A.Priolo Servizi S.c.p.A. was fined EUR 52,000 for the unlawful processing of biometric data of about 6,700 workers. The authority found that the company failed to properly notify the Garante and provided inadequate information to the data subjects.ITGaranteGDPR€52,000
01 Mar 2023Spółdzielnie Mieszkaniową „UODO imposed an administrative fine of PLN 51,876 on the controller for failing to notify the supervisory authority of a personal data breach without undue delay. The authority also found that the affected data subject was not informed about the breach.PLUODOGDPR€11,098
30 Jan 2026deținătorul site-ului evita-teparii.roANSPDCP imposed total fines of 51,000 lei, about 10,000 euro, on the operator, a natural person who runs the site evita-teparii.ro. The case involved multiple GDPR breaches, including the unlawful publication of identity, contact, sensitive, and alleged criminal data without a legal basis.ROANSPDCPGDPR€10,007
25 Mar 2021Centro diagnostico italiano di MilanoThe Italian Data Protection Authority imposed a fine of EUR 50,000 on Centro diagnostico italiano di Milano. The sanction concerned violations of data protection rules.ITGaranteGDPR€50,000
24 Apr 2025Darian Bishop trading as ECO4UBetween 9 January 2023 and 9 October 2023, 194,110 unsolicited direct marketing calls were made to subscribers registered with the TPS who had not indicated consent to receive such calls. The conduct generated 21 complaints to the Commissioner and the TPS, leading to an ICO fine.GBICOGDPR€58,480
05 Jun 2020EDP Energía, S.A.U.EDP Energía, S.A.U. was fined €50,000 by the AEPD for processing personal data without consent. The authority found this conduct to be in breach of Article 6(1) of the GDPR.ESAEPDGDPR€50,000
13 May 2022UNIDAD EDITORIAL INFORMACIÓN GENERAL, S.L.U.The entity published an audio recording of a victim's court testimony without consent. AEPD found this to be a breach of data protection law and imposed a 50,000 EUR fine.ESAEPDGDPR€50,000
29 Oct 2020Ministero dell’InternoThe Italian Data Protection Authority fined the Ministry of the Interior EUR 50,000 for the incorrect disclosure of personal data to a limited number of organizations. It also ordered the Ministry to consider training initiatives to improve data accuracy.ITGaranteGDPR€50,000
24 Jun 2021NEXTGEN FINANCIAL SERVICES S.L.NEXTGEN FINANCIAL SERVICES S.L. failed to update the address in a loan contract and did not correct inaccurate data in a credit file. The AEPD found this to be a breach of the right to data rectification and imposed a fine of 50,000 EUR.ESAEPDGDPR€50,000