Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
01 Mar 2017ESPASA CALPE, S.A.ESPASA CALPE, S.A. was fined EUR 2,500 by the AEPD for continuing to send commercial emails to a customer after confirming deletion of the customer’s personal data. The authority found this to be a breach of electronic communications and data protection rules.ESAEPDePrivacy€2,500
25 Jul 2019CONTAPUBLI RIOJA, S.L. (GESTIRIOJA)CONTAPUBLI RIOJA, S.L. was fined by the AEPD 2,500 EUR for sending unsolicited commercial emails. The conduct continued despite the recipient's objection and request for data deletion.ESAEPDePrivacy€2,500
27 Jun 2023Farmacia Ardealul SRLFarmacia Ardealul SRL was fined by ANSPDCP EUR 2,500 for a data security breach on its website. Unauthorized malware installation led to the compromise of personal data confidentiality, including banking data, of a significant number of clients.ROANSPDCPGDPR€2,500
01 Jan 2017MAS MOVIL TELECOM 3.0 S.A.U. (actualmente XFERA MOVILES, S.A.)The entity was fined by the AEPD in the amount of 2,500 EUR for sending unsolicited marketing messages without providing an opt-out option. This conduct breached article 21.2 of the LSSI, which requires recipients to be able to refuse such communications.ESAEPDePrivacy€2,500
03 Apr 2026BLUE PROJECTS S.R.L.In March 2026, the Romanian supervisory authority ANSPDCP completed an investigation into BLUE PROJECTS S.R.L. and found a GDPR violation. The company was fined EUR 2,500.ROANSPDCPGDPR€2,500
03 Feb 2017CAIXABANK, S.A.CAIXABANK, S.A. was fined by the AEPD EUR 2,500 for sending a customer an unsolicited advertising SMS. The recipient had not consented to receive commercial communications, which breached Article 21.1 of the LSSI.ESAEPDePrivacy€2,500
17 Apr 2026Carlo Maria Antonio ParisiThe Garante fined Carlo Maria Antonio Parisi, owner of the online newspaper “giornalistitalia.it”, EUR 2,500. The authority found inadequate technical and organizational measures to support data subject rights and delays in handling requests without undue delay.ITGaranteGDPR€2,500
09 Jan 2019TOM TOM SALES BV SUCURSAL EN ESPAÑATOM TOM SALES BV SUCURSAL EN ESPAÑA was fined by the AEPD 2,500 EUR for sending a promotional email to a user after confirming the deletion of their data. The authority found this conduct breached Article 21 of the LSSI.ESAEPDePrivacy€2,500
15 Dec 2022BENOTAC, S.L.BENOTAC, S.L. was fined by the AEPD EUR 2,500 for operating a video surveillance system without proper signage and for capturing public areas without authorization. The authority also noted the sharing of recordings without the consent of the data subjects.ESAEPDGDPR€2,500
29 Sept 2020GABINETE PARAPSICOLÓGICO MYSTIC S.L.The entity was fined for sending unsolicited advertising SMS messages without the recipient's consent. This conduct breached Article 21 of the LSSI and constituted unlawful marketing communication.ESAEPDePrivacy€2,500
01 Jan 2019LA ROCA NETWORKS, S.L.LA ROCA NETWORKS, S.L. was fined by the AEPD 2,500 EUR for sending unsolicited commercial emails without proper consent. The conduct breached Article 21 of the LSSI, which governs electronic marketing communications.ESAEPDePrivacy€2,500
02 Apr 2020HAPPY FRIDAY, S.L.HAPPY FRIDAY, S.L. was fined by the AEPD in the amount of 2,500 EUR for failing to comply with data protection rules on the use of cookies. The authority found that the company did not provide the required information or obtain user consent.ESAEPDePrivacy€2,500
26 Mar 2026Comune di CassinoComune di Cassino was fined for unlawfully publishing personal data online. The case concerns a breach of data protection rules and indicates a need to review procedures for publishing public information.ITGaranteGDPR€2,500
12 Feb 2026Velletri ServiziVelletri Servizi was fined EUR 2,500 by the Garante for inadequate technical and organizational measures in data processing. The authority found that the company did not meet the requirements of GDPR Article 32.ITGaranteGDPR€2,500
01 Jan 2016TELE PIZZA S.A.U.TELE PIZZA S.A.U. was fined EUR 2,500 by the AEPD for sending commercial emails without providing a valid electronic address for exercising ARCO rights. This breached Article 21.2 of the LSSI and indicates a failure to meet required recipient information obligations.ESAEPDePrivacy€2,500
01 Apr 2019EL GYM IBERIA, S.L.EL GYM IBERIA, S.L. was fined by the AEPD 2,500 EUR for sending unsolicited marketing emails. This occurred despite a prior request to cancel personal data.ESAEPDePrivacy€2,500
26 Jun 2017LEAD CONVERSION S.L.LEAD CONVERSION S.L. was fined by the AEPD 2,500 EUR for sending unsolicited commercial emails without prior recipient consent. The conduct breached electronic communications rules and marketing consent requirements.ESAEPDePrivacy€2,500
01 Oct 2023Anonymised (IDPC CDP_COMP_344_2022)The IDPC imposed a EUR 2,500 fine on the anonymised entity for breaches of multiple GDPR provisions. The case concerned, among others, lawfulness and transparency, information duties, and controller accountability.MTIDPCGDPR€2,500
11 Dec 2025CANDIDAT AUX ELECTIONS LEGISLATIVES DE 2024 (procédure simplifiée)The CNIL imposed an administrative fine of EUR 2,500 on CANDIDAT AUX ELECTIONS LEGISLATIVES DE 2024. The case was handled under a simplified procedure and concerned a confirmed regulatory breach.FRCNILGDPR€2,500
16 Aug 2022Dane anonimowe (N. Ośrodek Kultury z siedzibą w N. przy ul.)UODO imposed an administrative fine of PLN 2,500 on the Cultural Centre. The authority found that personal data were entrusted for processing without a written data processing agreement and without verifying whether the processor provided sufficient technical and organizational safeguards under the GDPR.PLUODOGDPR€531