Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
07 Sept 2011Aga s.r.l.Aga s.r.l. was fined EUR 8,000 by the Garante for processing online customers' personal data without ensuring freely given and specific consent. The authority found this to be a breach of data protection rules.ITGaranteGDPR€8,000
30 May 2025AG-BROKER ASIGURARE S.R.L.AG-BROKER ASIGURARE S.R.L. was fined 5,000 EUR by ANSPDCP. The sanction concerned the failure to notify a personal data security breach.ROANSPDCPGDPR€5,000
30 Dec 2022A&G Couriers Limited T/A Fastway Couriers (Ireland)The Irish DPC fined A&G Couriers Limited T/A Fastway Couriers (Ireland) 15,000 EUR in inquiry IN-21-6-2. The penalty has been collected.IEDPCGDPR€15,000
12 Dec 2024AGENCE DE COMMUNICATION ET DE PRODUCTION AUDIOVISUELLE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 6,000 on AGENCE DE COMMUNICATION ET DE PRODUCTION AUDIOVISUELLE under a simplified procedure. The case concerns a confirmed breach of rules supervised by the CNIL.FRCNILGDPR€6,000
22 Oct 2025Agency for Control of Outstanding Debts S.R.L.The company was fined EUR 2,000 by ANSPDCP for breaching multiple GDPR provisions. The case followed a complaint alleging deficiencies in personal data protection compliance.ROANSPDCPGDPR€2,000
12 Dec 2024Agenzia delle Dogane e dei MonopoliAgenzia delle Dogane e dei Monopoli was fined by the Garante in the amount of EUR 40,000 for violations related to data processing. The case concerned non-compliance with Art. 2-ter of the Italian Data Protection Code.ITGaranteGDPR€40,000
07 Mar 2019Agenzia delle Dogane e dei MonopoliAgenzia delle Dogane e dei Monopoli was fined for unlawfully processing judicial data by communicating information about an ongoing criminal proceeding without a legal basis. The case concerned a breach of the rules governing the lawful processing of sensitive data.ITGaranteGDPR€10,000
27 Jan 2016Agenzia di promozione economica della ToscanaAgenzia di promozione economica della Toscana was fined 10,000 EUR by the Garante for publishing lists of disabled candidates admitted to competitive exams on its institutional websites. The authority found that this disclosure breached data protection rules.ITGaranteGDPR€10,000
13 May 2021Agenzia di Tutela della Salute della Città metropolitana di MilanoAgenzia di Tutela della Salute della Città metropolitana di Milano was fined by the Garante 80,000 EUR for violations linked to data processing during an emergency. The authority found inadequate data protection measures and a failure to provide required information to data subjects.ITGaranteGDPR€80,000
21 May 2025Agenzia di Tutela della Salute, della Città Metropolitana di Milano, Servizio Prevenzione e Sicurezza Ambienti di Lavoro Milano Città NordAgenzia di Tutela della Salute was fined EUR 7,000 by the Garante for improperly sending medical reports and certificates. The authority found a breach of data protection rules.ITGaranteGDPR€7,000
11 Dec 2008agenzia funebre floricoltura Rampura di Loi AlessandroThe funeral agency was fined by the Garante for providing clients with inadequate information. The authority found this to be a breach of data protection rules.ITGaranteGDPR€3,000
10 Apr 2025Agenzia Mobilità Ambiente e Territorio S.r.l.The Garante fined Agenzia Mobilità Ambiente e Territorio S.r.l. 9,000 EUR for failing to provide sufficient transparency to data subjects. The authority found a breach of the GDPR principles of lawfulness, fairness, and transparency.ITGaranteGDPR€9,000
29 Sept 2011Agenzia per le erogazioni in agricoltura (AGEA)The Italian Data Protection Authority fined Agenzia per le erogazioni in agricoltura (AGEA) EUR 40,000 for violations related to the processing of personal data within the National Agricultural Information System (Sian). The case concerned compliance of the processing activities with personal data protection requirements.ITGaranteGDPR€40,000
10 Mar 2022Agenzia Regionale per la Tutela dell'Ambiente dell'AbruzzoThe Regional Agency for Environmental Protection of Abruzzo was fined by the Garante €8,000 for breaches of data protection principles. The violations concerned lawfulness, fairness, transparency, and data minimization.ITGaranteGDPR€8,000
14 Jan 2021Agenzia regionale protezione ambientale Campania (ARPAC)ARPAC was fined by the Garante EUR 8,000 for violations concerning data security measures and data breach notification obligations. The case involved non-compliance with GDPR Articles 5 and 32.ITGaranteGDPR€8,000
08 Feb 2024Agenzia territoriale della Regione Puglia per il servizio di gestione dei rifiuti (AGER)The Garante fined Agenzia territoriale della Regione Puglia per il servizio di gestione dei rifiuti (AGER) EUR 6,000. The authority found that the organization failed to appoint a Data Protection Officer in a timely manner, despite the GDPR requirement being in force for about three years.ITGaranteGDPR€6,000
28 May 2026AgID – Agenzia per l’Italia digitaleThe Italian Data Protection Authority fined AgID €55,000 for failing to adequately inform professionals about the automatic registration of their digital domiciles. The authority found breaches of transparency and data processing principles.ITGaranteGDPR€55,000
04 Sept 2025A*** GmbHA*** GmbH did not report a personal data breach to the Austrian Data Protection Authority within the 72-hour deadline required by Article 33 GDPR. As a result, a fine of EUR 870 was imposed.ATDSBGDPR€870
12 Feb 2021A*** GmbHA*** GmbH was fined by the Austrian Data Protection Authority for failing to cooperate in three separate complaint procedures. The authority found a breach of Article 31 GDPR, which requires cooperation with the supervisory authority.ATDSBGDPR€3,000
12 Oct 2016AG Preziosi Banco Metalli s.r.l.AG Preziosi Banco Metalli s.r.l. was fined by the Garante for collecting personal data through a website contact form without providing the required privacy notice. This constituted a breach of Article 13 of the Italian Privacy Code.ITGaranteGDPR€2,400