Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.2%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
09 Jun 2021Räddningstjänsten Östra SkaraborgIMY found that Räddningstjänsten Östra Skaraborg breached the GDPR by improperly using surveillance cameras in changing areas. The authority also identified excessive personal data processing and inadequate security measures.SEIMYGDPR€34,794
11 Jun 2015Quotidiano Il Tempo s.r.l.Quotidiano Il Tempo s.r.l. was fined by the Garante EUR 8,400 for processing personal data without providing adequate information to subscribers. The authority also found that the company used a video surveillance system without the simplified notice required under privacy rules.ITGaranteGDPR€8,400
13 Jan 2012QUOTATIS ESPAÑA S.L.QUOTATIS ESPAÑA S.L. was fined by the AEPD 30,001 EUR for sending unsolicited commercial emails despite requests to stop. The case concerned Article 21.1 of the LSSI, which prohibits such communications without prior consent.ESAEPDePrivacy€30,001
15 Oct 2024Quick Tax Claims LimitedThe ICO found that Quick Tax Claims Limited sent 7,863,547 unlawful text messages over one month, generating 66,793 complaints. In 93% of complaints, recipients said there was no opt-out option, and the company had bought personal data from suppliers without valid consent.GBICOGDPR€143,000
01 Jan 2019QUESERIA ARTESANAL AMECO S.L.QUESERIA ARTESANAL AMECO S.L. was fined by the AEPD 5,000 EUR for processing personal data without consent. Customers were unaware of how their data had been obtained, indicating a breach of transparency and lawful processing requirements.ESAEPDGDPR€5,000
01 Mar 2013QUARELY INDUSTRIAL S.L.QUARELY INDUSTRIAL S.L. was fined by the AEPD in the amount of EUR 600 for sending unsolicited commercial emails. The conduct breached Article 21 of the LSSI, which governs marketing communications without prior recipient consent.ESAEPDePrivacy€600
03 Jan 2023QUALITY-PROVIDER, S.A.QUALITY-PROVIDER, S.A. was fined by the AEPD in the amount of 30,000 EUR for processing personal data without consent. The data were then shared with third parties, who used them to contact the complainant via a personal social network.ESAEPDGDPR€30,000
02 Nov 2022QUALITY-PROVIDER S.A.QUALITY-PROVIDER S.A. was fined EUR 20,000 by the AEPD for processing personal data without a valid legal basis and for failing to comply with data deletion requests. The violations concerned Articles 6 and 17 of the GDPR.ESAEPDGDPR€20,000
27 Mar 2023QUALITY-PROVIDER S.A.QUALITY-PROVIDER S.A. was fined EUR 20,000 by the Spanish data protection authority, AEPD. The company failed to provide requested information, obstructing the authority’s investigative powers under Article 58(1) GDPR.ESAEPDGDPR€20,000
01 Jan 2023QUALITY-PROVIDER S.A.QUALITY-PROVIDER S.A. was fined 20,000 EUR by the AEPD for unlawfully obtaining personal data from a website. The data was then used for promotional purposes without the consent of the data subjects.ESAEPDGDPR€20,000
05 Oct 2017Qiu JunjieQiu Junjie was fined EUR 10,000 by the Garante for failing to protect video surveillance recordings with a password. The authority found this breached the minimum security measures required under the Italian Data Protection Code.ITGaranteGDPR€10,000
14 Jan 2016Q.12 s.r.l.Q.12 s.r.l. was fined EUR 2,400 by the Garante for failing to provide an adequate simplified privacy notice for its video surveillance system. The authority found a breach of the Italian Privacy Code.ITGaranteGDPR€2,400
13 Apr 2022PYRAMID CONSULTINGPYRAMID CONSULTING was fined by the AEPD EUR 30,000 for unlawful processing of personal data. The company incorrectly identified an individual as responsible for a traffic violation, which led to an improper administrative sanction.ESAEPDGDPR€30,000
01 Jan 2023PUNTO ROJO LIBROS, S.L.PUNTO ROJO LIBROS, S.L. was fined by the AEPD 1,000 EUR for failing to adequately respond to a data subject’s request for information about the origin of their personal data. The authority treated this as a breach of GDPR obligations.ESAEPDGDPR€1,000
12 Jul 2022PUNTO ROJO LIBROS, S.LPUNTO ROJO LIBROS, S.L was fined EUR 800 by the AEPD for sending commercial emails without the recipient’s consent. The conduct breached Article 21 of the LSSI, which requires prior consent for this type of communication.ESAEPDePrivacy€800
27 Jan 2016Punto Fermo s.r.l.Punto Fermo s.r.l. was fined by the Garante EUR 12,000 for retaining surveillance footage for 25 days. This exceeded the one-week limit set by the general rules on video surveillance.ITGaranteGDPR€12,000
13 Mar 2014Puglia Service s.r.l.Puglia Service s.r.l. was fined by the Garante €10,000 for making unsolicited promotional phone calls. The conduct violated the right of opposition of a subscriber registered in the public opt-out list.ITGaranteGDPR€10,000
08 Aug 2024PUERTO FOGONES SLPUERTO FOGONES SL was fined EUR 2,000 by the AEPD. The authority found a breach for failing to provide access to information as required under Article 58.1 of the GDPR.ESAEPDGDPR€2,000
05 Jul 2024PUBLICACIONES Y EDICIONES BARACA 208, S.L.The company published personal data, including health information, in a digital newspaper article. The authority found a breach of data minimisation and the rules on special category data under GDPR Articles 5(1)(c) and 9.ESAEPDGDPR€10,000
22 Mar 2013PUBLIACTIVOS COMUNICACION Y MARKETING, S.L.The entity was fined by the AEPD for sending unsolicited commercial emails. This conduct breached Article 21.1 of the LSSI, which prohibits marketing communications without prior consent.ESAEPDePrivacy€600