Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
21 Apr 2016Ditta individuale Fang WeiweiDitta individuale Fang Weiwei was fined 2,400 EUR by the Garante. The authority found that the video surveillance system was used without providing the information required under privacy rules.ITGaranteGDPR€2,400
15 Dec 2016Stireria Rosa di HU XINStireria Rosa di HU XIN was fined 2,400 EUR by the Garante. The authority found that the company failed to inform data subjects about the processing of personal data through a video surveillance system covering public areas.ITGaranteGDPR€2,400
22 Jun 2016Società Territorio Turismo & Sport s.r.l.Società Territorio Turismo & Sport s.r.l. was fined by the Garante 2,400 EUR. The case concerned collecting personal data, including name and email, via its website without providing users with the required information notice.ITGaranteGDPR€2,400
01 Dec 2016L'ABBONDANZA s.r.l.L'ABBONDANZA s.r.l. was fined 2,400 EUR by the Garante. The authority found that the company failed to provide data subjects with information about the processing of personal data through a video surveillance system.ITGaranteGDPR€2,400
05 Jun 2014Ing. Claudio ZiniThe individual enterprise of Ing. Claudio Zini was fined for sending unsolicited promotional emails. The authority also found that the required information notice under Article 13 of the Italian Privacy Code was not provided.ITGaranteGDPR€2,400
31 Mar 2016Pia GiordanoPia Giordano was fined by the Garante for collecting personal data through her website without providing users with the required information notice. The authority found a breach of Article 13 of the Italian Data Protection Code.ITGaranteGDPR€2,400
11 Feb 2016Circolo ricreativo D.D. PeckerCircolo ricreativo D.D. Pecker was fined by the Garante for providing inadequate information to data subjects about the processing of their personal data. The breach concerned Article 13 of the Italian Data Protection Code.ITGaranteGDPR€2,400
27 Oct 2023Asociația de Proprietari bloc A1The homeowners association was fined by ANSPDCP for failing to implement measures ordered by the authority and for unlawfully disclosing owners’ names on maintenance lists without consent. The case concerns breaches of personal data protection rules and non-compliance with supervisory instructions.ROANSPDCPGDPR€501
29 Nov 2019GRUPO VALSOR Y LOSAN, S.L.The real estate management company improperly disclosed personal data of third parties during a property purchase process. This constituted a breach of data protection rules and led to a fine imposed by the AEPD.ESAEPDGDPR€2,500
24 Sept 2021B.B.B.The entity was fined for operating a video surveillance system aimed at public and private spaces without sufficient justification. The authority found this to be a breach of data protection rules.ESAEPDGDPR€2,500
01 Jan 2019ELECTRIC RENTING GROUP, S.L.ELECTRIC RENTING GROUP, S.L. was fined by the AEPD EUR 2,500 for sending a promotional email without using BCC. This exposed recipients’ email addresses and breached data protection rules.ESAEPDGDPR€2,500
28 Apr 2022Liceo Statale “Isabella Gonzaga”Liceo Statale “Isabella Gonzaga” was fined by the Garante 2,500 EUR for publishing information on teachers' Law 104 benefits in an electronic register. The register was accessible to other teachers, which breached the GDPR and national privacy code provisions.ITGaranteGDPR€2,500
13 Dec 2022Anonymisé (CNPD decision-18-fr-2022)The company unlawfully transmitted personal data to third parties without prior authorization. The authority also found breaches of GDPR data processing principles and data subject rights.LUCNPDGDPR€2,500
01 Jan 2019VODAFONE ESPAÑA, S.A.UVodafone España, S.A.U was fined by the AEPD in the amount of 2,500 EUR for sending unsolicited advertising messages to a business phone number without consent. The case concerned Article 21 of the LSSI, which governs marketing communications without prior recipient consent.ESAEPDePrivacy€2,500
11 Jan 2023Azienda Sanitaria Locale di BrindisiAzienda Sanitaria Locale di Brindisi was fined by the Garante 2,500 EUR for failing to respond to a data access request. The authority found a breach of GDPR Article 15.ITGaranteGDPR€2,500
27 Feb 2025Comune di SciaccaThe Garante fined Comune di Sciacca EUR 2,500 for violations related to the processing of personal data. The case concerned the communication of data to third parties without a proper legal basis.ITGaranteGDPR€2,500
27 Mar 2025Comune di PolinoComune di Polino was fined by the Garante for breaches of transparency and information obligations in data processing under GDPR Articles 6, 12, 13, and 14. The case concerned insufficient information provided to data subjects about how their personal data was processed.ITGaranteGDPR€2,500
30 Apr 2026BLUE PROJECTS INDUSTRIES S.R.L.ANSPDCP completed an investigation in April 2026 into BLUE PROJECTS INDUSTRIES S.R.L. and found a GDPR violation. A fine of EUR 2,500 was imposed.ROANSPDCPGDPR€2,500
22 Feb 2019VODAFONE ONO, S.A.U.VODAFONE ONO, S.A.U. was fined by the AEPD €2,500 for sending commercial communications by phone and SMS without the complainant’s consent. This breached Article 21 of the LSSI.ESAEPDePrivacy€2,500
13 Apr 2023Suditaly Imprese Meridionali Soc. coop.The Garante imposed a 2,500 EUR fine on Suditaly Imprese Meridionali Soc. coop. for publishing detailed health data without the data subjects' consent. The case concerned Article 9 of the GDPR, which restricts processing of special categories of personal data.ITGaranteGDPR€2,500