Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
24 Jun 2024WWPD CINVENTO INTERNATIONAL PATENT TRADING, S.L.The entity sent postal advertising to an individual without any prior commercial relationship, using data from the Official Industrial Property Bulletin. The authority found this to be a breach of data protection rules.ESAEPDGDPR€500
21 Jul 2022WUNSCHURLAUB S.L.WUNSCHURLAUB S.L. was fined by the AEPD 3,000 EUR for storing user passwords in plain text and sending them by email without encryption. The authority found this breached GDPR Article 32 on appropriate security measures.ESAEPDGDPR€3,000
01 Dec 2016Wu KuanzhaoWu Kuanzhao was fined EUR 2,400 by the Garante. The authority found that data subjects were not informed about the processing of personal data through a video surveillance system.ITGaranteGDPR€2,400
01 Jan 2014WUAKI TV, S.L.WUAKI TV, S.L. was fined by the AEPD EUR 2,300 for sending unsolicited commercial emails to a user. The emails were sent after the company had confirmed the user's unsubscribe request and request to stop processing their data.ESAEPDePrivacy€2,300
01 Oct 2023wspólnota mieszkaniowaUODO found that the housing community breached GDPR requirements. The case concerned improper processing of personal data and required supervisory intervention.PLUODOGDPR€1,080
06 Jun 2024WORLD 2 MEET, S.L.WORLD 2 MEET, S.L. was fined EUR 70,000 by the AEPD for requesting excessive personal data from guests during traveler registration. The company required full copies of identity documents, which breached the data minimization principle.ESAEPDGDPR€70,000
13 Jul 2006Work Safety Training Italia s.r.l.Work Safety Training Italia s.r.l. was fined by the Garante for sending unsolicited promotional emails. The authority found that the company failed to provide adequate information about data processing, breaching the information duty under data protection rules.ITGaranteGDPR€1,549
28 Sept 2010WORKING MARESME S.L.WORKING MARESME S.L. was fined by the AEPD in the amount of EUR 600 for sending unsolicited commercial emails. The conduct breached Article 21 of the LSSI, which prohibits marketing communications without prior consent.ESAEPDePrivacy€600
19 Nov 2021Working Capital Management España, S.L.Working Capital Management España, S.L. was fined by the AEPD 40,000 EUR for unlawfully processing personal data. The company included an individual's data in a credit information system without a valid contract, in connection with an identity theft case.ESAEPDGDPR€40,000
01 Dec 2022WoolenWoolen was fined EUR 3,000 by the Garante for a video surveillance system that did not meet transparency requirements. The authority cited a breach of GDPR Article 13 and Article 114 of the Italian Privacy Code.ITGaranteGDPR€3,000
03 Aug 2016WOLTERS KLUWER ESPAÑA, S.A.WOLTERS KLUWER ESPAÑA, S.A. was fined by the AEPD EUR 1,000 for sending unsolicited commercial emails to a complainant after confirming the cancellation of their data. The authority found this conduct breached Article 21.1 of the LSSI.ESAEPDePrivacy€1,000
01 Nov 2025Właścicielka lecznicy stomatologicznejThe owner of a dental clinic was fined 85,588 PLN by UODO for failing to notify affected patients in time after a personal data breach. The WSA and then the NSA upheld the penalty, finding that the required notices were sent too late.PLPresident of the Personal Data Protection Office (UODO)GDPR€20,110
11 Jan 2017WIZINK BANK, S.A.WIZINK BANK, S.A. was fined by the AEPD EUR 5,000 for sending unsolicited commercial emails despite a request to unsubscribe. The authority found a breach of Article 21 of the LSSI.ESAEPDePrivacy€5,000
17 Apr 2023WIZINK BANK, S.A.WIZINK BANK, S.A. was fined 5,000 EUR by the AEPD for sending commercial emails to a complainant who had opted out of receiving such communications. The authority found this conduct to be a breach of Article 21 of the LSSI.ESAEPDePrivacy€5,000
01 Jan 2016WIZINK BANK S.A.WIZINK BANK S.A. was fined by the AEPD €4,100 for sending unsolicited commercial communications by electronic means. The authority found that the legal requirements for such communications were not met.ESAEPDePrivacy€4,100
17 Apr 2017WIZINK BANK S.A.WIZINK BANK S.A. was fined by the AEPD in the amount of 5,000 EUR for sending unsolicited commercial communications by email. The conduct violated the recipient's request to opt out of advertising.ESAEPDePrivacy€5,000
06 Dec 2012Wire s.r.l.Wire s.r.l. was fined by the Garante in the amount of EUR 32,000 for making pre-recorded electoral propaganda calls without prior, specific, and informed consent from the recipients. The authority found this to be a breach of data protection rules.ITGaranteGDPR€32,000
12 Dec 2024Wind Tre S.p.A.Wind Tre S.p.A. was fined €347,520 by the Garante for violations related to processing personal data for promotional purposes and for inadequate technical and organizational measures. The case concerned telemarketing activities and the protection of the data involved.ITGaranteGDPR€347,000
29 Nov 2018Wind Tre S.p.A.Wind Tre S.p.A. was fined EUR 600,000 by the Garante for unsolicited promotional calls and SMS. The authority found breaches of several provisions of the Italian Data Protection Code.ITGaranteGDPR€600,000
09 Jul 2020Wind Tre S.p.A.Wind Tre S.p.A. was fined by the Garante 16,729,600 EUR for carrying out promotional activities without ensuring that contacts respected the wishes of individuals who did not want to receive marketing communications. The case concerns GDPR requirements on consent and the right to object to direct marketing.ITGaranteGDPR€16,729,000