Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
16 Dec 2025Anonymisé (CNPD decision-04-fr-2025)The company did not maintain a complete and accurate record of processing activities under Article 30 GDPR. CNPD treated this as a breach of documentation obligations and imposed an administrative fine.LUCNPDGDPR€2,784
01 Jan 2015TELEFÓNICA DE ESPAÑA S.A.U.TELEFÓNICA DE ESPAÑA S.A.U. was fined by the AEPD EUR 2,900 for sending unsolicited advertising emails. The conduct breached Article 21 of the LSSI, which restricts marketing communications without prior consent.ESAEPDePrivacy€2,900
12 Jun 2015JAZZ TELECOM S.A.U.JAZZ TELECOM S.A.U. was fined by the AEPD EUR 2,900 for continuing to send advertising SMS messages to a user despite multiple requests to stop. The authority found a breach of Article 21 of the LSSI on unsolicited marketing communications.ESAEPDePrivacy€2,900
01 Jan 2015JAZZ TELECOM SAUJAZZ TELECOM SAU was fined by the AEPD 2,900 EUR for sending unsolicited SMS advertisements to a complainant. The conduct breached Article 21 of the LSSI on commercial communications without prior consent.ESAEPDePrivacy€2,900
08 Sept 2014MUCHODESTINO, S.L.MUCHODESTINO, S.L. was fined by the AEPD €2,900 for sending unsolicited commercial emails. The conduct breached Article 21.1 of the LSSI, which restricts marketing communications without prior consent.ESAEPDePrivacy€2,900
25 Apr 2016PARABEBES SERVICIOS INFANTILES Y PREMAMÁ, S.L.The entity was fined by the AEPD for sending unsolicited commercial emails to a complainant. The authority found a breach of Article 21.1 of the LSSI.ESAEPDePrivacy€2,900
12 May 2021Anonymisé (CNPD decision-15-fr-2021)The CNPD imposed a EUR 2,900 fine for breaching the data minimization principle in connection with video surveillance. The camera’s field of view covered areas that were not necessary for the processing purpose, contrary to Article 5(1)(c) GDPR.LUCNPDGDPR€2,900
22 Aug 2024Sancțiuni pentru încălcarea RGPDThe ANSPDCP fined the company EUR 3,000 for violating Article 2 of the GDPR. The case concerned non-compliance with data protection requirements.ROANSPDCPGDPR€3,000
22 Aug 2024Kaufland România SCSKaufland România SCS was fined EUR 3,000 by ANSPDCP for a data security breach. The case concerns an incident involving personal data protection that resulted in an administrative sanction.ROANSPDCPGDPR€3,000
28 Apr 2026RESIDENCIAL ETXE-LAN, S.L.RESIDENCIAL ETXE-LAN, S.L. was fined by the AEPD for failing to provide the required information to the supervisory authority. The breach concerned Article 58(1) GDPR and hindered the authority’s supervisory powers.ESAEPDGDPR€3,000
26 Feb 2026Groupharma s.r.l.s.Groupharma s.r.l.s. was fined EUR 3,000 by the Italian supervisory authority, Garante. The case concerned the company’s failure to respond to a former employee’s request to access and delete personal data, including photos and contact details, from its website after employment ended.ITGaranteGDPR€3,000
30 Jan 2021DEGOM, S.A.DEGOM, S.A. was fined EUR 3,000 by the AEPD for failing to display cookie warnings and data protection acceptance checkboxes on its website. The case concerned deficiencies in online transparency and user consent requirements.ESAEPDePrivacy€3,000
08 Apr 2022B.B.B.The entity was fined for installing security cameras that recorded audio and covered areas such as the restroom without proper notice to employees or customers. The authority found this breached GDPR rules on data processing and transparency of information.ESAEPDGDPR€3,000
01 Jan 2021LA MAISON DU BAMBOULA MAISON DU BAMBOU was fined EUR 3,000 by the AEPD for sending commercial emails without the recipient's consent. The conduct breached Article 21 of the LSSI.ESAEPDePrivacy€3,000
01 Jan 2014COMERCIAL POLINDUS 21 S.L.COMERCIAL POLINDUS 21 S.L. was fined by the AEPD EUR 3,000 for sending unsolicited spam messages without providing an opt-out mechanism. The conduct breached Article 21 of the LSSI and failed to meet basic requirements for marketing communications.ESAEPDePrivacy€3,000
02 Dec 2019GARANTIZA AUTOMOCIÓN, S.L.The company was fined by the AEPD in the amount of EUR 3,000 for failing to provide information or obtain consent for the use of cookies on its website. The breach concerned LSSI requirements on transparency and user consent.ESAEPDePrivacy€3,000
07 Jul 2022E Software Concept SRLE Software Concept SRL was fined EUR 3,000 by ANSPDCP. The authority found that the company had not implemented adequate technical and organizational measures to ensure a level of security appropriate to the processing risk.ROANSPDCPGDPR€3,000
29 Apr 2021Comune di PutifigariComune di Putifigari was fined EUR 3,000 by the Garante for publishing special-category personal data online. The disclosed information could reveal individuals' health status, which breached GDPR requirements on data protection and privacy.ITGaranteGDPR€3,000
14 Mar 2022LISMARTSA, S.L.LISMARTSA, S.L. was fined EUR 3,000 by the AEPD for improperly sending the personal data of 74 employees by email. The authority found a breach of data protection rules.ESAEPDGDPR€3,000
01 Jan 2021AD735 DATA MEDIA ADVERTISING S.L.AD735 DATA MEDIA ADVERTISING S.L. was fined €3,000 by the AEPD for failing to comply with information requests. The case concerned Article 58(1) GDPR and the duty to cooperate with the supervisory authority.ESAEPDGDPR€3,000