Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
13 Apr 2023Retimedia S.r.l.Retimedia S.r.l. was fined 2,500 EUR by the Garante for publishing detailed health data of an individual without consent. The conduct breached GDPR Article 9 on special categories of personal data.ITGaranteGDPR€2,500
21 Jan 2019XFERA MÓVILES, S.A.XFERA MÓVILES, S.A. was fined by the AEPD in the amount of 2,500 EUR for sending unsolicited commercial SMS messages. The authority found that this conduct breached Article 21.1 of the LSSI.ESAEPDePrivacy€2,500
31 Mar 2015VACACIONES EDREAMS, S.L.U.VACACIONES EDREAMS, S.L.U. was fined by the AEPD 2,500 EUR for sending unsolicited commercial emails despite the recipient’s request to unsubscribe. The case concerned a breach of Article 21.1 of the LSSI and shows failure to respect an opt-out request for direct marketing.ESAEPDePrivacy€2,500
01 Jan 2016ORANGE ESPAGNE S.A.U.ORANGE ESPAGNE S.A.U. was fined by the AEPD 2,500 EUR for sending unsolicited commercial communications by electronic means without the recipient's consent. The case indicates a breach of electronic marketing rules and the requirement for prior consent.ESAEPDePrivacy€2,500
12 Feb 2026Anconambiente S.P.A.Anconambiente S.P.A. was fined by the Garante for failing to ensure that personal data processing was lawful, fair, and transparent. The authority also found that the company did not have a proper contract with a data processor, as required by Article 28 GDPR.ITGaranteGDPR€2,500
12 Sept 2019VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD EUR 2,500 for sending unsolicited commercial SMS messages without prior consent. The authority found this breached Article 21.1 of the LSSI.ESAEPDePrivacy€2,500
23 Aug 2022Geanonimiseerd (APD 129/2022)The Litigation Chamber imposed a fine for insufficient technical and organizational measures to protect data security. This led to unauthorized access to personal documents.BEAPDGDPR€2,500
20 Sept 2023DREAM HOUSE SISTEMAS DE DESCANSO, S.L.DREAM HOUSE SISTEMAS DE DESCANSO, S.L. was fined EUR 2,500 by the AEPD for sending unsolicited advertising SMS messages to a customer who had previously objected. The authority found this conduct breached Article 21 of the LSSI.ESAEPDePrivacy€2,500
01 Jan 2019LINEA DIRECTA ASEGURADORA, S.A.LINEA DIRECTA ASEGURADORA, S.A. was fined by the AEPD for sending unsolicited advertising emails without a prior relationship with the recipient. The authority found this breached Article 21 of the LSSI.ESAEPDePrivacy€2,500
07 Oct 2025Anonymisiert (DSB 2025-0.778.661)An individual unlawfully accessed and processed personal data from a secured hard drive without a legitimate purpose. The authority found this to be a breach of core GDPR principles, including lawfulness and purpose limitation.ATDSBGDPR€2,500
08 Jun 2017THE PHONE HOUSE SPAIN, S.L.U.THE PHONE HOUSE SPAIN, S.L.U. was fined by the AEPD 2,500 EUR for sending commercial text messages without providing recipients with a simple and free way to object to the processing of their data for promotional purposes. The case concerned non-compliance with the LSSI rules on marketing communications.ESAEPDePrivacy€2,500
29 Apr 2009Altea Servizi s.r.l.Altea Servizi s.r.l. was fined by the Garante 2,580 EUR for sending promotional faxes without obtaining specific and informed consent from consumers. The conduct breached the consumer code and data protection rules.ITGaranteGDPR€2,580
06 Jul 2006Korallina Tours s.r.l.Korallina Tours s.r.l. was fined EUR 2,582 by the Garante for sending unsolicited promotional emails. The case concerns a breach of data protection obligations, including the duty to provide information to the authority under applicable law.ITGaranteGDPR€2,582
13 Jul 2006Comune di NapoliThe Municipality of Naples was fined by the Garante in the amount of 2,582 EUR. The sanction resulted from failing to provide requested information and documents, which constituted a breach of data protection rules.ITGaranteGDPR€2,582
13 Jul 2006Ministero dell'istruzione (Ufficio regionale per la Campania)The Campania Regional Office of the Ministry of Education was fined by the Garante for failing to provide requested information and documents. The authority found this to be a breach of data protection rules.ITGaranteGDPR€2,582
13 Feb 2015LA QUINIELA INTELIGENTE S.L.LA QUINIELA INTELIGENTE S.L. was fined by the AEPD EUR 2,600 for sending unsolicited commercial emails. The authority found that the messages did not provide recipients with an effective way to object to further communications, breaching Article 21 of the LSSI.ESAEPDePrivacy€2,600
24 Sept 2015KREDITECH SPAIN S.L.KREDITECH SPAIN S.L. was fined by the AEPD in the amount of 2,600 EUR for sending unsolicited commercial emails to a complainant. The authority found this conduct to be in breach of Article 21.1 of the LSSI.ESAEPDePrivacy€2,600
01 Jan 2015LA QUINIELA INTELIGENTE S.L.LA QUINIELA INTELIGENTE S.L. was fined by the AEPD 2,600 EUR for sending unsolicited commercial emails. The authority found that recipients were not given a means to object to further communications, breaching Article 21 of the LSSI.ESAEPDePrivacy€2,600
12 May 2021Anonymisé (CNPD decision-14-fr-2021)The company was fined by the CNPD in the amount of 2,600 EUR for breaching GDPR requirements on data minimization, data retention, and information obligations. The case concerned non-compliant personal data processing and a failure to provide the required information to data subjects.LUCNPDGDPR€2,600
01 Jan 2020DOUGLAS SPAIN, S.A.U.DOUGLAS SPAIN, S.A.U. was fined by the AEPD 2,700 EUR for continuing to send advertising emails to a complainant after confirming deletion of the complainant’s personal data. The authority found this breached Article 21 of the LSSI.ESAEPDePrivacy€2,700