Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
07 Jul 2021Anonymizováno (ÚOOÚ UOOU-04873/20-24)The entity was fined for unlawfully publishing personal data on YouTube. The authority found a breach of GDPR principles of lawfulness, fairness, and transparency.CZUOOUGDPR€117
08 Mar 2017Elliniki Etaireia Systimikon MeletonThe company was fined by the HDPA for illegally collecting and using personal data for direct marketing purposes. The infringement involved unsolicited electronic communications sent without prior consent from the data subjects.GRHDPAePrivacy€3,000
30 Mar 2025MODEL REYNA, C.B.MODEL REYNA, C.B. was fined by the AEPD EUR 3,000 for failing to provide access to personal data and related information. The authority found a breach of Article 58.1 of the GDPR.ESAEPDGDPR€3,000
18 Dec 2013Anonymised (HDPA 154/2013)The HDPA imposed a fine of EUR 3,000 on the company for unlawfully collecting an individual's creditworthiness data. The case concerned processing without a valid legal basis, which breaches data protection rules.GRHDPAGDPR€3,000
29 Jul 2015LEIPZIG COMUNICACIONES, S.L.LEIPZIG COMUNICACIONES, S.L. was fined by the AEPD for sending six unsolicited advertising SMS messages without prior consent. The authority also found that no opt-out mechanism was provided, which breached Article 21 of the LSSI.ESAEPDePrivacy€3,000
20 Jun 2023CARRETERAS Y ASFALTOS, S.L.The company installed surveillance cameras that recorded both image and audio without proper signage or informing employees. This breached data protection requirements.ESAEPDGDPR€3,000
17 Sept 2024Constanța South Container Terminal SRLConstanța South Container Terminal SRL was fined by ANSPDCP EUR 3,000 after a third party gained unauthorized access to employees’ personal data. The breach resulted from inadequate security measures on a publicly accessible file management platform.ROANSPDCPGDPR€3,000
18 Jan 2022BAZARDELALEGION.COMBAZARDELALEGION.COM was fined by the AEPD for failing to provide the required information on its website under Article 13 GDPR. The breach concerned the website’s information duties toward individuals whose data are collected online.ESAEPDGDPR€3,000
28 May 2026Regione Autonoma della SardegnaThe Garante fined Regione Autonoma della Sardegna EUR 3,000 for sharing disciplinary sanction information with unauthorized internal units. The authority found this breached the GDPR and national data protection rules.ITGaranteGDPR€3,000
05 Mar 2020Comune di San Giorgio JonicoComune di San Giorgio Jonico was fined by the Garante for publishing personal data on its institutional website. The authority found breaches of lawfulness, fairness, transparency, and data minimization principles.ITGaranteGDPR€3,000
11 Dec 2023Veranda Obor S.A.The National Supervisory Authority for Personal Data Processing imposed a fine on Veranda Obor S.A. for violating GDPR provisions. The case concerned non-compliance with personal data protection requirements.ROANSPDCPGDPR€3,000
13 May 2015HellastatHellastat was fined EUR 3,000 by the HDPA for failing to inform data subjects. The authority found a breach of data protection rules requiring transparent notice to individuals.GRHDPAGDPR€3,000
19 Apr 2023Partidul Uniunea Salvați RomâniaThe National Supervisory Authority imposed a fine on Partidul Uniunea Salvați România (USR) for publishing personal data of persons with disabilities on its website without a legal basis. The authority found a breach of personal data processing principles.ROANSPDCPGDPR€3,000
15 Dec 2022Scuola Statale Secondaria di I^ grado “Bianco-Pascoli”, di Fasano (BR)The school was fined by the Garante 3,000 EUR for violations in the processing of personal data, including minors' health information. The authority found that the processing lacked a proper legal basis and sufficient transparency.ITGaranteGDPR€3,000
26 Mar 2026Ordine degli Avvocati di PiacenzaOrdine degli Avvocati di Piacenza was fined EUR 3,000 by the Garante for improper handling of disciplinary sanctions in its professional register. The authority found that the processing did not comply with data protection requirements.ITGaranteGDPR€3,000
15 Jul 2022FEDERACIÓN DE ATENCIÓN A LA CIUDADANÍA DE LA UNIÓN SINDICAL OBRERA (FAC-USO)The organization continued sending emails to an individual after they requested deletion of their personal data. The AEPD found a breach of Article 6 of the GDPR and imposed a EUR 3,000 fine.ESAEPDGDPR€3,000
17 Oct 2024CHIRURGIEN DENTISTE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 3,000 on CHIRURGIEN DENTISTE under a simplified procedure. The authority also issued an injunction, indicating that remedial action is required.FRCNILGDPR€3,000
25 Sept 2025Comune di Isola del Gran Sasso d’ItaliaThe Garante fined the Comune di Isola del Gran Sasso d’Italia EUR 3,000 for unlawfully publishing personal data on its institutional website, including information related to criminal proceedings. The authority found breaches of lawfulness, fairness, transparency, and data minimization.ITGaranteGDPR€3,000
21 Jul 2022WUNSCHURLAUB S.L.WUNSCHURLAUB S.L. was fined by the AEPD 3,000 EUR for storing user passwords in plain text and sending them by email without encryption. The authority found this breached GDPR Article 32 on appropriate security measures.ESAEPDGDPR€3,000
12 Aug 2021NATURAL LOGISTICS, S.L.NATURAL LOGISTICS, S.L. was fined by the AEPD EUR 3,000 for sending unsolicited commercial emails despite the recipient's objection. This breached Article 21 of the LSSI on marketing communications without consent.ESAEPDePrivacy€3,000