Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
01 Jan 2026CloudflareAGCOM issued an ordinanza ingiunzione against Cloudflare under the Digital Services Act. The fine is 100,000 EUR and relates to a breach of DSA obligations.ITAGCOMDSA€100,000
22 Nov 2024CLUB BALONCESTO TELDEClub Baloncesto Telde was fined for publishing images of a minor on social media without obtaining the required consent. The authority found a breach of Article 6(1) of the GDPR.ESAEPDGDPR€1,000
07 Jun 2024Club Balonmano GijónClub Balonmano Gijón was fined EUR 1,000 by the AEPD for unlawfully processing personal data by publishing images of minors on its website without a legal basis. The case indicates a breach of the lawfulness principle and the protection of children's image rights.ESAEPDGDPR€1,000
17 Feb 2025CLUB DE GOLF VILLA DE CUÉLLARCLUB DE GOLF VILLA DE CUÉLLAR was fined by the AEPD EUR 400 for failing to inform an employee about the installation and operation of surveillance cameras. The authority found a breach of Article 13 GDPR.ESAEPDGDPR€400
01 Jan 2021CLUB DEPORTIVO RITMO DE ANDALUCÍAThe club was fined by the AEPD 4,000 EUR for failing to adequately inform users about the processing of their personal data. The authority also found that users were not given the opportunity to provide free and voluntary consent for each specific processing purpose.ESAEPDGDPR€4,000
19 Nov 2024CLUB ESPORTIU VILA OLÍMPICAThe club pressured a parent to obtain consent for collecting images of a minor child. AEPD found this to be a breach of data protection rules.ESAEPDGDPR€1,000
04 May 2021CLUB GIMNASIA RÍTMICA SAN ANTONIOThe club was fined by the AEPD for publishing images of minors on social media without proper consent. The authority found a breach of GDPR Article 6 on lawful processing.ESAEPDGDPR€5,000
01 Mar 2022CLUB NATACIO LLEIDACLUB NATACIO LLEIDA installed a surveillance camera in a rented bar/restaurant without informing the tenant or displaying the required signage. The AEPD found this to be a breach of data protection rules.ESAEPDGDPR€1,200
07 Jun 2021CLUB NÁUTICO EL ESTACIOThe entity published personal data on its website without access restrictions. This breached confidentiality and data security principles.ESAEPDGDPR€3,000
19 Dec 2024CLUB RÁPIDO DE BOUZASThe club was fined by the AEPD for leaving documents containing players’ personal data, including minors’ data, in a public trash container. The authority found this breached data protection principles, especially confidentiality and security.ESAEPDGDPR€1,000
01 Jan 2023CLUB VOLEIBOL ***CLUB.1The club was fined by the AEPD in the amount of EUR 500 for publishing minors' images without proper consent. The authority also found that the club failed to provide access to personal data requested by a parent.ESAEPDGDPR€500
15 Aug 2024Coastal Windows & Conservatories (UK) LimitedCoastal Windows & Conservatories (UK) Limited made more than 18,000 unsolicited marketing calls between 1 January and 1 June 2023 to numbers registered with the TPS. The ICO and TPS received numerous complaints from people who said they had not consented to the calls or continued to receive them after asking for the calls to stop.GBICOGDPR€46,720
06 Oct 2022Codess Sociale, Soc. Coop. socialeCodess Sociale, Soc. Coop. sociale was fined EUR 10,000 by the Garante. The authority found that the company failed to respond to a data subject's request to exercise GDPR rights.ITGaranteGDPR€10,000
10 Nov 2011C.O.E.STRA. S.p.A.C.O.E.STRA. S.p.A. was fined EUR 30,000 by the Italian data protection authority, Garante. The sanction concerned the failure to appoint data processing officers, which breached the minimum security measures required under the Italian Data Protection Code.ITGaranteGDPR€30,000
05 Nov 2025COFIDIS S.A., SUCURSAL EN ESPAÑACOFIDIS S.A., Sucursal en España was fined €5,000 by the AEPD for mixing a complainant’s personal data with unrelated information and sending a third party’s debt statement. The case concerns a breach of the data accuracy principle.ESAEPDGDPR€5,000
25 Feb 2016COF Lanzo Hospital SpaCOF Lanzo Hospital Spa was fined by the Garante for failing to respond to an information request concerning the handling of patient medical records. The authority found a breach of Article 164 of the Italian Data Protection Code.ITGaranteGDPR€4,000
27 Oct 2016Coledan EmanuelaColedan Emanuela was fined EUR 2,400 by the Garante for failing to inform data subjects about the processing of personal data through a video surveillance system at a private club. The case concerns a breach of transparency and information obligations toward individuals under surveillance.ITGaranteGDPR€2,400
26 Sept 2023COLEGIO ALONAI, S.L.COLEGIO ALONAI, S.L. was fined by the AEPD 5,000 EUR for installing surveillance cameras inside classrooms and outside the school without properly informing employees. The authority also found inadequate signage, constituting a breach of data protection rules.ESAEPDGDPR€5,000
29 Jan 2020COLEGIO ARENALES CARABANCHELThe school was fined by the AEPD 5,000 EUR for unlawfully sharing and publishing images of children without consent. The case involved a breach of data protection rules and the need for valid consent to process minors’ images.ESAEPDGDPR€5,000
30 Oct 2024COLEGIO NOTARIAL DE ARAGÓNCOLEGIO NOTARIAL DE ARAGÓN was fined by the AEPD for implementing a fingerprint-based time control system without carrying out a data protection impact assessment. The authority found breaches of GDPR Articles 9 and 35.ESAEPDGDPR€10,000