Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.2%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
31 Jan 2023PRESTAMER, S.L.PRESTAMER, S.L. sent an email to 472 recipients without using BCC, which exposed recipients’ personal data. The AEPD imposed a 3,000 EUR fine for breaching data protection rules.ESAEPDGDPR€3,000
14 Feb 2024PRENSA IBÉRICA MEDIA S.L.PRENSA IBÉRICA MEDIA S.L. was fined by the AEPD in the amount of 5,000 EUR for failing to obtain proper user consent for cookies on its website. The authority found that this practice breached the LSSI requirements on cookies.ESAEPDePrivacy€5,000
04 Oct 2017PRENATAL SAPRENATAL SA was fined by the AEPD EUR 20,000 for sending commercial SMS messages without providing recipients with an opt-out mechanism. The case concerns a breach of electronic communications rules and marketing consent requirements.ESAEPDePrivacy€20,000
13 Jan 2026PREMIER RESTAURANTS ROMANIA SRLThe National Supervisory Authority for Personal Data Processing imposed a fine on PREMIER RESTAURANTS ROMANIA SRL for GDPR violations. The case concerned non-compliance with personal data protection requirements.ROANSPDCPGDPR€8,000
01 Mar 2022PREICO JURÍDICOS, S.L.PREICO JURÍDICOS, S.L. was fined EUR 2,000 by the AEPD for deficiencies in its cookie policy. The authority found that the website did not provide the required information or obtain consent for storing and accessing data, in breach of Article 22.2 of the LSSI.ESAEPDePrivacy€2,000
26 May 2022PREICO JURIDICOS, S.L.PREICO JURIDICOS, S.L. was fined by the AEPD 3,000 EUR for failing to respond to information requests linked to a data breach investigation. The authority found a breach of Article 58(1) GDPR.ESAEPDGDPR€3,000
26 May 2022PREICO JURIDICOS S.L.PREICO JURIDICOS S.L. was fined EUR 6,000 by the AEPD for failing to provide required information. The case concerned a breach of Article 58(1) GDPR.ESAEPDGDPR€6,000
29 Sept 2021Prefettura - Ufficio Territoriale del Governo di GenovaPrefettura - Ufficio Territoriale del Governo di Genova was fined by the Garante for publishing personal data on its institutional website. The conduct breached GDPR requirements on lawful processing and protection of personal data.ITGaranteGDPR€11,000
19 Oct 2020PREDASE SERVICIOS INTEGRALES SOCIEDAD LIMITADAPREDASE SERVICIOS INTEGRALES S.L. was fined EUR 5,000 by the AEPD for failing to publish a privacy policy on its website and for misleadingly using the AEPD logo. The conduct could imply an association with the authority and influence user decisions.ESAEPDGDPR€5,000
04 Jun 2020PRA IBERIA, S.L.PRA IBERIA, S.L. was fined by the AEPD 60,000 EUR for unlawful processing of personal data and for failing to provide access to personal data information. The breaches concerned Articles 6(1) and 15 of the GDPR.ESAEPDGDPR€60,000
06 Jul 2006PR3 International s.r.l.PR3 International s.r.l. was fined by the Italian data protection authority, Garante, in the amount of EUR 258. The case concerned inadequate information provided to data subjects in job advertisements, which breached data protection rules.ITGaranteGDPR€258
23 Sept 2024PPC ENERGIE MUNTENIA S.A.In September 2024, ANSPDCP completed an investigation into PPC ENERGIE MUNTENIA S.A. and found violations of GDPR provisions. The company was fined EUR 2,000.ROANSPDCPGDPR€2,000
08 Nov 2024PPC Energie Muntenia S.AThe National Supervisory Authority for Personal Data Processing completed an investigation at PPC Energie Muntenia S.A and found a violation of GDPR provisions. As a result, a fine of EUR 1,000 was imposed.ROANSPDCPGDPR€1,000
10 Feb 2025PPC Energie Muntenia SAPPC Energie Muntenia SA was fined EUR 1,000 by ANSPDCP for violating GDPR provisions. The case concerned non-compliance with personal data protection requirements.ROANSPDCPGDPR€1,000
10 Feb 2025PPC Energie Muntenia SAThe operator was fined by ANSPDCP in the amount of EUR 2,000 for violating GDPR provisions. The case concerns non-compliance with personal data protection requirements.ROANSPDCPGDPR€2,000
16 Jan 2024Poxell LtdThe ICO found that Poxell Ltd made 2,647,805 unsolicited direct marketing calls between 31 March 2022 and 20 July 2022, breaching regulations 21 and 24 of PECR. This led to 413 complaints to the ICO and TPS, with recipients reporting persistent calls about energy-related products and home improvements.GBICOePrivacy€174,000
27 Jan 2021Powerplay S.r.l.Powerplay S.r.l. was fined by the Garante for making unsolicited promotional calls despite the recipient's clear request not to receive further communications. The company failed to place the number on a blacklist, which breached data protection rules.ITGaranteGDPR€20,000
01 Jan 2025Posti Jakelu OyPosti Jakelu Oy was fined EUR 2,400,000 by the Data Protection Ombudsman for deficiencies in data protection related to the OmaPosti service. The case concerned inadequate safeguards and failures to meet personal data protection requirements.FITietosuojavaltuutettuGDPR€2,400,000
10 Jul 2025Poste Vita S.p.a.Poste Vita S.p.a. was fined EUR 80,000 by the Garante for unlawfully disclosing personal data relating to life insurance policies to an unauthorized third party. The data were then used in judicial proceedings.ITGaranteGDPR€80,000
04 Jul 2024Postel S.p.A.Postel S.p.A. was fined by the Garante EUR 900,000 for a data breach following a ransomware attack. The attack exploited vulnerabilities in the Microsoft Exchange platform, resulting in unauthorized access to data and publication on the dark web.ITGaranteGDPR€900,000