Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
12 Mar 2015Hayat KhizerHayat Khizer was fined EUR 3,000 by the Garante for improper registration of SIM cards. The cards were used by persons other than the formal registrants in connection with a criminal investigation into drug trafficking.ITGaranteGDPR€3,000
07 May 2015Burger Joint/Maria Galioni I.K.E.The company was fined for unlawfully operating a video surveillance system in the workplace. The authority found a privacy violation because employees and customers were monitored without proper justification.GRHDPAGDPR€3,000
20 Mar 2008Scuola College di Cagno Abbrescia s.r.l.Scuola College di Cagno Abbrescia s.r.l. was fined EUR 3,000 by the Garante. The case concerned the failure to provide access to personal data requested by the parents of a minor, in breach of the Italian data protection code.ITGaranteGDPR€3,000
27 Jun 2012OKANAOKANA was fined by the HDPA in the amount of 3,000 EUR for failing to adequately protect special-category personal data. Documents containing patients’ health data were found in trash bins, indicating a breach of data protection rules.GRHDPAGDPR€3,000
22 Feb 2021B.B.B.The entity was fined by the AEPD for a video surveillance system that was improperly oriented toward private areas. The authority also found that the area was not adequately signposted, breaching data protection rules.ESAEPDGDPR€3,000
01 Jan 2025MONUMENTAL FORMA SPORT, S.L.MONUMENTAL FORMA SPORT, S.L. was fined by the AEPD EUR 3,000 for requesting excessive personal data, including banking information, in connection with a free gym access promotion. The authority found that the data requested breached the GDPR data minimisation principle under Article 5(1)(c).ESAEPDGDPR€3,000
18 Jul 2023ING BANK NV Amsterdam Sucursala BucureștiING Bank NV Amsterdam Sucursala București received a fine from ANSPDCP for GDPR violations. The case concerned non-compliance with personal data protection requirements.ROANSPDCPGDPR€3,000
16 Jun 2010Anonymised (HDPA 29/2010)The company was fined EUR 3,000 by the HDPA for sending unsolicited marketing emails and faxes without subscriber consent. This conduct breached ePrivacy rules on electronic marketing communications.GRHDPAePrivacy€3,000
01 Mar 2017A.A.A.A.A.A. was fined €3,000 by the AEPD. The authority found that cookies were installed on its websites without prior information and consent, in breach of Article 22.2 of the LSSI.ESAEPDePrivacy€3,000
09 May 2024Ordine dei Tecnici Sanitari di Radiologia Medica e delle Professioni Sanitarie Tecniche, della Riabilitazione e della Prevenzione della provincia di MantovaThe Garante imposed a 3,000 EUR fine on the Ordine dei Tecnici Sanitari di Radiologia Medica e delle Professioni Sanitarie Tecniche, della Riabilitazione e della Prevenzione della provincia di Mantova for breaches of data protection principles. The authority found non-compliance with lawfulness, fairness, transparency, and data minimization. The infringement affected a significant number of data subjects.ITGaranteGDPR€3,000
23 Mar 2023Consiglio Nazionale dell'Ordine degli Assistenti SocialiConsiglio Nazionale dell'Ordine degli Assistenti Sociali was fined EUR 3,000 by the Garante for breaching data protection principles. The case involved improper handling of personal data during a recruitment process, including disclosure of information about a candidate's exclusion.ITGaranteGDPR€3,000
15 Feb 2022ASOCIACIÓN DE AFICIONADOS Y PEQUEÑOS ACCIONISTAS UNIDAD HERCULANAThe organization was fined by the AEPD 3,000 EUR for failing to provide a privacy policy compliant with Article 13 of the GDPR on its website. It collected personal data through various forms but did not provide the required information to data subjects.ESAEPDGDPR€3,000
13 Mar 2025ImmosanremoImmosanremo was fined EUR 3,000 by the Garante for sending unsolicited marketing messages via WhatsApp without valid consent. The authority found that the conduct breached GDPR rules on processing personal data for promotional purposes.ITGaranteGDPR€3,000
12 Feb 2026Comune di AnconaThe Garante fined Comune di Ancona EUR 3,000 for failing to ensure lawful, fair, and transparent processing of personal data. The authority also found that no proper contract was in place with a data processor, in breach of GDPR Articles 5 and 28.ITGaranteGDPR€3,000
30 Apr 2014COMERCIAL POLINDUS 21 S.L.COMERCIAL POLINDUS 21 S.L. was fined by the AEPD 3,000 EUR for sending unsolicited and misleading commercial messages by electronic means. The authority found a breach of Article 21 of the LSSI on marketing communications without prior consent.ESAEPDePrivacy€3,000
01 Jun 2023Comune di NapoliComune di Napoli was fined for improperly communicating performance evaluation results of former employees. The authority found breaches of lawfulness, fairness, transparency, and data minimization principles.ITGaranteGDPR€3,000
02 Oct 2020INSTITUTO DEL DAÑO CEREBRAL Y PSÍQUICO, S.L.The entity did not provide timely access to clinical records, which constituted a breach of data protection obligations. Deficiencies were also identified in the website's cookie policy, leading the AEPD to impose a fine.ESAEPDePrivacy€3,000
24 Oct 2023Mensajero SRLMensajero SRL was fined EUR 3,000 by ANSPDCP for a data security breach on its website. A link allowed access to downloadable files containing customer invoices and product warranty certificates.ROANSPDCPGDPR€3,000
09 May 2024Polisportiva Mimmo Ferrito s.r.l.The Garante fined Polisportiva Mimmo Ferrito s.r.l. EUR 3,000 for failing to respond to a data subject's request to exercise their rights. The case concerns non-compliance with data protection obligations.ITGaranteGDPR€3,000
11 Dec 2008Comune di PontenureComune di Pontenure was fined EUR 3,000 by the Garante for failing to provide the required data protection notice when sending a questionnaire about waste management tariffs. The authority found a breach of Article 13 of the Italian Data Protection Code.ITGaranteGDPR€3,000