Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.2%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
01 Jan 2012REED EXHIBITIONS IBERIA, S.A.REED EXHIBITIONS IBERIA, S.A. was fined by the AEPD 1,200 EUR for sending unsolicited commercial emails. The conduct breached Article 21.1 of the LSSI despite the recipient’s requests to unsubscribe.ESAEPDePrivacy€1,200
14 Nov 2012RED UNIVERSAL DE MARKETING Y BOOKINGS ONLINE, S.A. (RUMBO)RED UNIVERSAL DE MARKETING Y BOOKINGS ONLINE, S.A. (RUMBO) was fined by the AEPD EUR 600 for sending commercial SMS and email messages without recipient consent. The conduct breached Article 21.2 of the LSSI, which requires prior consent for such communications.ESAEPDePrivacy€600
12 May 2017RED UNIVERSAL DE MARKETING Y BOOKINGS ONLINE S.A.The entity sent unsolicited commercial emails. It continued sending them despite requests to delete the data, which breached electronic communications rules.ESAEPDePrivacy€4,500
27 Feb 2025RED ESPAÑOLA DE IDENTIFICACIÓN DE ANIMALES DE COMPAÑÍAREIAC was fined EUR 600 by the AEPD for failing to provide the required information to the data protection authority. The case concerns Article 58(1) GDPR and reflects a failure to cooperate with the supervisory authority.ESAEPDGDPR€600
24 Feb 2026Reddit, Inc.The ICO imposed a GBP 14.5 million UK GDPR fine on Reddit, Inc. for failures related to age-gating and the protection of children’s data. The matter was initially misfiled as an enforcement notice and later refiled as a monetary penalty notice.GBInformation Commissioner's OfficeGDPR€16,606,000
23 Feb 2026Reddit, Inc.The ICO imposed a penalty of 14,472,500 GBP on Reddit, Inc. for breaches of Articles 5(1)(a), 6, 8, and 35 of the UK GDPR. The case concerned unlawful personal data processing and failures to implement appropriate safeguards and a data protection impact assessment.GBICOGDPR€16,571,000
01 Jan 2021RECLAMADOR, S.L.RECLAMADOR, S.L. was fined €2,000 by the AEPD for sending a commercial electronic communication after the recipient had exercised the right to erasure. The authority found this conduct breached GDPR and LSSI requirements.ESAEPDGDPR€2,000
13 Nov 2023RECICLAJES LOGROÑO, S.L.RECICLAJES LOGROÑO, S.L. was fined by the AEPD 10,000 EUR for photocopying a customer's ID without consent and for failing to provide privacy policy information. The authority found breaches of GDPR data minimization and transparency principles.ESAEPDGDPR€10,000
21 Feb 2022RECICLAJES ECOLÓGICOS MELJACAN, S.L.The company was fined by the AEPD for breaching data protection rules. The authority found that the website did not meet the required information and consent standards for data processing and cookie policies.ESAEPDePrivacy€7,000
07 Apr 2022Rebirth s.r.l.Rebirth s.r.l. was fined by the Garante EUR 15,000 for operating a video surveillance system at “Caffè Antica Roma” in a manner that did not comply with data protection rules. The conduct breached the GDPR and provisions of the Italian Privacy Code.ITGaranteGDPR€15,000
16 Jun 2020REAL SPORTING DE GIJÓN, S.A.D.REAL SPORTING DE GIJÓN, S.A.D. was fined EUR 5,000 by the AEPD for breaching GDPR Article 7 on consent requirements. The case arose from a complaint by the Ministry of Finance concerning advertising practices.ESAEPDGDPR€5,000
09 Jul 2025REAL SOCIEDAD DE FUTBOL S.A.D.REAL SOCIEDAD DE FUTBOL S.A.D. suffered a ransomware attack that led to a data breach affecting 60,000 individuals, including biometric, identification, financial, and health data. The AEPD fined the company for failing to implement adequate technical and organizational measures to protect data security.ESAEPDGDPR€60,000
08 Sept 2022Realmedia Network SARealmedia Network SA was fined EUR 8,000 by ANSPDCP for a data processing security breach. The incident involved a service used to operate the imobiliare.ro platform.ROANSPDCPGDPR€8,000
19 May 2025REAL FEDERACIÓN ESPAÑOLA DE TENIS DE MESAREAL FEDERACIÓN ESPAÑOLA DE TENIS DE MESA was fined by the AEPD 2,000 EUR for publishing personal data of individuals involved in an electoral process on its website. This conduct breached data protection principles.ESAEPDGDPR€2,000
14 Jan 2020REAL CLUB NAÚTICO DE RIBADEOREAL CLUB NAÚTICO DE RIBADEO was fined by the AEPD 6,000 EUR for publishing a court judgment containing personal data on its website and Facebook without anonymization. This constituted a breach of data protection rules.ESAEPDGDPR€6,000
03 May 2016REAL AUTOMOVIL CLUB DE ESPAÑAREAL AUTOMOVIL CLUB DE ESPAÑA was fined by the AEPD EUR 1,000 for sending unsolicited commercial emails despite the recipient's requests to unsubscribe. The authority found a breach of Article 21.1 of the LSSI.ESAEPDePrivacy€1,000
25 Sept 2025RCS MediaGroup S.p.a.RCS MediaGroup S.p.a. was fined by the Italian data protection authority, Garante, in the amount of EUR 100,000. The case concerned the publication of images of a person in a private setting without consent, which infringed privacy rights.ITGaranteGDPR€100,000
08 Jun 2023RCS Mediagroup S.p.a.RCS Mediagroup S.p.a. was fined EUR 40,660 by the Italian Garante. The case concerned the publication of unauthorized photographs of a private individual taken inside her home, which infringed her privacy rights.ITGaranteGDPR€40,660
31 Aug 2023RCS Mediagroup S.p.a.RCS Mediagroup S.p.a. was fined by the Garante EUR 10,000 for publishing an article on the Corriere della Sera website. The article included a photograph of a holographic will that disclosed a witness’s personal data without consent.ITGaranteGDPR€10,000
01 Jul 2022RCI BANQUE, S.A. SUCURSAL EN ESPAÑARCI Banque, S.A. Sucursal en España was fined by the AEPD for failing to properly handle a request for erasure under Article 17 GDPR. As a result, the data subject received unwanted communications about a debt they did not owe.ESAEPDGDPR€20,000