Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
05 Jul 2022Global Greece MEPEThe company was fined for sending unsolicited marketing emails without obtaining the recipients’ prior explicit consent. The authority found this conduct to be in breach of Article 11 of Law 3471/2006.GRHDPAePrivacy€3,000
07 Feb 2020SOLO EMBRAGUE, S.L.SOLO EMBRAGUE, S.L. was fined by the AEPD 3,000 EUR for failing to provide information about its privacy policy and for not obtaining consent for cookies on its website. The case concerns breaches of transparency obligations and consent requirements under data protection rules.ESAEPDePrivacy€3,000
17 Jun 2020LA CASA COMPROMETIDA, S.Coop.The entity was fined by the AEPD in the amount of 3,000 EUR for failing to comply with data protection rules regarding its website cookie policy. The case concerned deficiencies in the required information or consent related to cookies.ESAEPDePrivacy€3,000
01 Jan 2021LYNGUAL GMBHLYNGUAL GMBH was fined by the AEPD 3,000 EUR for sending unsolicited commercial emails. The messages continued despite the recipient’s attempts to unsubscribe and requests to stop communications.ESAEPDePrivacy€3,000
14 Mar 2023Tinmar Energy SATinmar Energy SA was fined EUR 3,000 by ANSPDCP after unauthorized access to its email server. The incident resulted in a personal data breach.ROANSPDCPGDPR€3,000
14 Sept 2006De.Mo. s.r.l.De.Mo. s.r.l. was fined 3,000 EUR by the Garante for failing to provide the required information to data subjects under Article 13 of the Italian Data Protection Code. The breach occurred in connection with the company’s marketing activities.ITGaranteGDPR€3,000
03 Dec 2025FUNDACIÓN TRILEMAFUNDACIÓN TRILEMA was fined 3,000 EUR by the AEPD for publishing a minor’s image on social media without parental consent. The authority found this to be a breach of data protection rules.ESAEPDGDPR€3,000
11 Mar 2020SALAD MARKET S.L.SALAD MARKET S.L. was fined by the AEPD €3,000 for using video cameras to monitor employees without informing them. The company also added employees to WhatsApp groups without consent, which breached data protection rules.ESAEPDePrivacy€3,000
22 May 2014SOFTWARE INFORMÁTICA VEDCOR S.L.SOFTWARE INFORMÁTICA VEDCOR S.L. was fined by the AEPD EUR 3,000 for sending unsolicited commercial emails despite the recipient’s request to stop. The conduct breached Article 21 of the LSSI on unsolicited electronic communications.ESAEPDePrivacy€3,000
20 Nov 2006Anonymised (HDPA 61/2006)A hospital was fined for failing to properly inform the complainant about the transmission of sensitive health data. The case concerns a breach of the duty to provide clear information to the data subject.GRHDPAGDPR€3,000
22 Jun 2020ARANOW PACKAGING MACHINERY, S.L.ARANOW PACKAGING MACHINERY, S.L. was fined by the AEPD for non-compliance of its website with data protection rules. The breach concerned the absence of compliant Privacy and Cookie Policies.ESAEPDePrivacy€3,000
26 Mar 2026SOCIÉTÉ AYANT POUR ACTIVITÉ L'HÉBERGEMENT DE TOURISME (procédure simplifiée)CNIL imposed an administrative fine of EUR 3,000 on SOCIÉTÉ AYANT POUR ACTIVITÉ L'HÉBERGEMENT DE TOURISME under a simplified procedure. The case concerns a confirmed breach of rules supervised by CNIL.FRCNILGDPR€3,000
01 Mar 2023ILUROBOX, S.L.ILUROBOX, S.L. was fined by the AEPD EUR 3,000 for including individuals in a WhatsApp group without their consent. The authority found that this breached Article 6(1) GDPR because there was no lawful basis for the processing.ESAEPDGDPR€3,000
28 Jun 2022ALPA 57 PRODUCCIONES, S.L.ALPA 57 PRODUCCIONES, S.L. failed to provide the required information to the Spanish Data Protection Agency, which constitutes a breach of Article 58.1 of the GDPR. The AEPD imposed a fine of 3,000 EUR.ESAEPDGDPR€3,000
15 Apr 2021Ordine degli Avvocati di LagonegroOrdine degli Avvocati di Lagonegro was fined EUR 3,000 by the Garante for publishing the content of a PEC email on its institutional website. The authority found breaches of lawfulness, fairness, transparency, and data minimization.ITGaranteGDPR€3,000
27 Jul 2018Anonymizováno (ÚOOÚ UOOU-08596/17-64)The individual was fined for publishing the personal data of a municipal social department employee on Facebook. The authority found a breach of confidentiality obligations under Czech law.CZUOOUGDPR€117
15 Jan 2024CUBILLO GALLEGO, S.L.CUBILLO GALLEGO, S.L. was fined by the AEPD 3,000 EUR for failing to provide adequate information about personal data processing on its website. The authority found a breach of Article 13 GDPR, which requires clear notice to data subjects.ESAEPDGDPR€3,000
08 May 2024Genpact România SRLThe ANSPDCP imposed a fine of EUR 3,000 on Genpact România SRL. The sanction concerned sending a file containing recruitment data to an unauthorized employee email address. The incident indicates a failure to control access to personal data and maintain confidentiality.ROANSPDCPGDPR€3,000
06 Jul 2023Comune di AvianoThe Garante fined Comune di Aviano EUR 3,000 for publishing employees’ personal data, including names and productivity bonuses, on its institutional website. The authority found a breach of data minimization and transparency principles.ITGaranteGDPR€3,000
22 Nov 2019CENTRAL SINDICAL INDEPENDIENTE Y DE FUNCIONARIOS CSI-CSIFThe union CSI-CSIF was fined EUR 3,000 by the AEPD for publishing an electoral census list containing personal data, including DNI numbers, in a public WhatsApp group. The authority found this breached data protection principles.ESAEPDGDPR€3,000