Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
19 Feb 2020CITRICOS Y FRUTALES DEL SURESTE, S.L.CITRICOS Y FRUTALES DEL SURESTE, S.L. was fined by the AEPD 3,000 EUR for installing video surveillance in common areas without approval from the property owners' association and without obtaining explicit consent from affected individuals. The authority found breaches of GDPR Articles 5(1)(c) and 13.ESAEPDGDPR€3,000
17 Mar 2023PLAY FUL KIDS, S.L.PLAY FUL KIDS, S.L. was fined by the AEPD EUR 3,000 for breaching Article 6(1) of the GDPR, which requires a lawful basis for processing personal data. The infringement was classified as very serious.ESAEPDGDPR€3,000
23 Mar 2023Comune di PulsanoComune di Pulsano was fined by the Garante for unlawfully publishing personal data related to an employee’s disciplinary proceedings on its institutional website. The authority found breaches of data minimization and transparency principles.ITGaranteGDPR€3,000
18 Dec 2019GRUPO CAROLIZANGRUPO CAROLIZAN was fined EUR 3,000 by the AEPD for installing a video surveillance system that disproportionately captured public space. The authority found no sufficient justification for the scope of monitoring, which infringed the rights of third parties.ESAEPDGDPR€3,000
20 Mar 2008PromofaxPromofax was fined by the Italian authority Garante in the amount of EUR 3,000. The case concerned sending advertising material by fax without providing recipients with prior and adequate information, in breach of data protection rules.ITGaranteGDPR€3,000
10 Jun 2024SOCIETE DIFFUSANT DES CONTENUS JOURNALISTIQUES (procédure simplifiée)The CNIL imposed an administrative fine of EUR 3,000 on SOCIETE DIFFUSANT DES CONTENUS JOURNALISTIQUES and issued an injunction. The case was handled under a simplified procedure.FRCNILGDPR€3,000
17 Jan 2008Proemotion s.r.l.Proemotion s.r.l. was fined EUR 3,000 by the Italian data protection authority, Garante. The case concerned promotional activities for travel, vacations, weddings, and meetings, where personal data were collected through website forms without adequate prior information.ITGaranteGDPR€3,000
03 Jul 2025MEDECIN (procédure simplifiée)The CNIL imposed an administrative fine of 3,000 EUR on MEDECIN and issued an injunction. The case was handled under a simplified procedure.FRCNILGDPR€3,000
04 Jan 2023Apă Canal Ilfov SAThe company was fined EUR 3,000 by ANSPDCP for a data security breach. User information was exposed because email addresses were entered in the “To” field instead of “BCC”.ROANSPDCPGDPR€3,000
11 Dec 2023PERSONNALITE POLITIQUE (procédure simplifiée)The CNIL imposed a EUR 3,000 fine on PERSONNALITE POLITIQUE and issued an injunction. The case was handled under a simplified procedure.FRCNILGDPR€3,000
11 Jul 2022S.C. (Sameday)S.C. (Sameday) was fined EUR 3,000 by ANSPDCP for failing to implement adequate technical and organizational security measures. The deficiency led to unauthorized access to the personal data of 26,566 individuals.ROANSPDCPGDPR€3,000
21 Jul 2025VIVLIOPOLEION TIS ESTIAS, I.D. KOLLAROU & SIA A.E.The company was fined by the HDPA 3,000 EUR for failing to implement appropriate technical and organizational measures to secure personal data. The deficiency resulted in unauthorized disclosure of personal data.GRHDPAGDPR€3,000
24 Jun 2025I ASPIDA TOU DAVIDThe entity failed to provide the required information and to implement adequate data protection measures. HDPA imposed a fine of EUR 3,000 for breach of GDPR principles.GRHDPAGDPR€3,000
05 Dec 2024SOCIETE VENDANT DES PRODUITS COSMETIQUES (procédure simplifiée)The CNIL imposed an administrative fine of EUR 3,000 on SOCIETE VENDANT DES PRODUITS COSMETIQUES. The case was handled under a simplified procedure.FRCNILGDPR€3,000
20 Jun 2024Rețele Electrice Muntenia SARețele Electrice Muntenia SA was fined by ANSPDCP in the amount of 3,000 EUR for violations of GDPR provisions. The case concerns non-compliance with personal data protection requirements.ROANSPDCPGDPR€3,000
24 Apr 2024I.N.P.A.S.The Garante imposed a fine on I.N.P.A.S. for violations related to the processing of employees' personal data, including sensitive data. The authority found that the processing did not ensure lawfulness, fairness, transparency, and data minimization.ITGaranteGDPR€3,000
21 Apr 2021Ministero dell’Istruzione, dell’Università e della Ricerca, Ufficio Scolastico Regionale per la Toscana, Ufficio VIII Ambito territoriale della provincia di LivornoThe Italian Ministry of Education was fined 3,000 EUR by the Garante. The case concerned personal data of teachers remaining accessible online in breach of GDPR principles of lawfulness, fairness, transparency, and data minimization.ITGaranteGDPR€3,000
12 Feb 2021A*** GmbHA*** GmbH was fined by the Austrian Data Protection Authority for failing to cooperate in three separate complaint procedures. The authority found a breach of Article 31 GDPR, which requires cooperation with the supervisory authority.ATDSBGDPR€3,000
18 Sept 2008Eurolaurea Caserta s.r.l.Eurolaurea Caserta s.r.l. was fined EUR 3,000 by the Garante. The authority found that the company failed to provide data subjects with the information required under Article 13 of the Italian Data Protection Code.ITGaranteGDPR€3,000
01 Jan 2015JYCTEL ESPAÑA SLJYCTEL ESPAÑA SL was fined by the AEPD in the amount of 3,000 EUR for sending unsolicited SMS and WhatsApp messages. The company did not provide information on how to exercise the right to object, which breaches Article 21 of the LSSI.ESAEPDePrivacy€3,000