Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
02 Jul 2020GTL s.r.l.GTL s.r.l. was fined EUR 3,000 by the Garante for failing to respond to an individual's data access request. The authority treated this as a breach of GDPR obligations.ITGaranteGDPR€3,000
04 Apr 2023Tensa Art Design SRLThe company was fined for sending commercial messages to individuals by phone and email despite their requests to stop contact. The case concerned failure to respect opt-out requests against further marketing communication.ROANSPDCPGDPR€3,000
19 Dec 2024SOCIETE GERANT UNE SALLE DE SPORT (procédure simplifiée)The CNIL imposed an administrative fine of EUR 3,000 on SOCIETE GERANT UNE SALLE DE SPORT under a simplified procedure. The case concerns a breach of rules covered by the supervisory authority’s decision.FRCNILGDPR€3,000
07 Mar 2024Hotel Milano di Foschi Eros e Righini Rina & C. SncThe Garante fined Hotel Milano EUR 3,000 for improper installation of surveillance cameras. The cameras captured public streets and third-party properties, and the informational signage was inadequate.ITGaranteGDPR€3,000
07 Apr 2022Анонимизирано (CPDP решение-по-жалба-с-рег-№-ппн-01-101136-0)The CPDP imposed fines on two individuals for unlawful video surveillance in a co-owned property. The authority found breaches of GDPR principles of lawfulness and data minimization.BGCPDPGDPR€1,534
28 Apr 2022Comune di Monte Sant’AngeloThe Municipality of Monte Sant’Angelo was fined 3,000 EUR by the Garante for breaching data protection principles. The authority found that personal data had been made accessible online in violation of lawfulness, fairness, transparency, and data minimization.ITGaranteGDPR€3,000
01 Jan 2020JUST LANDED, S.L.JUST LANDED, S.L. was fined EUR 3,000 by the AEPD for failing to provide a privacy policy and a cookie policy on its website. The authority cited a breach of GDPR Article 13 and LSSI Article 22.2.ESAEPDePrivacy€3,000
04 Aug 2014SERVICIOS DE DEPILACION BLOC, S.L.SERVICIOS DE DEPILACION BLOC, S.L. was fined by the AEPD EUR 3,000 for sending unsolicited commercial SMS messages to a former client. The authority found that this conduct breached Article 21 of the LSSI on marketing communications.ESAEPDePrivacy€3,000
12 Feb 2021KUKIMBIA S.L.KUKIMBIA S.L. was fined EUR 3,000 by the AEPD for leaving documents containing personal data unattended. The authority found this to be a breach of data security obligations under Article 32(1) of the GDPR.ESAEPDGDPR€3,000
06 Feb 2025ALPHA BANK ANONYMI ETAIREIAAlpha Bank was fined by the HDPA for failing to implement adequate security measures. This led to unauthorized access to the personal data of 6,176 employees after a system administrator role was not revoked following an internal transfer.GRHDPAGDPR€3,000
06 Jun 2021FLY FUT, S.L.FLY FUT, S.L. was fined by the AEPD in the amount of 3,000 EUR for recording a minor during football matches without prior consent. The case concerns a breach of data protection rules and the requirement to obtain consent before processing a child’s image.ESAEPDGDPR€3,000
18 Jul 2025LEIVA BUS, S.L.LEIVA BUS, S.L. was fined by the AEPD 3,000 EUR for disclosing the personal data of a claimant and a third party in a damage assessment document. The case concerned a breach of data protection rules and unauthorized disclosure of information.ESAEPDGDPR€3,000
01 Dec 2022WoolenWoolen was fined EUR 3,000 by the Garante for a video surveillance system that did not meet transparency requirements. The authority cited a breach of GDPR Article 13 and Article 114 of the Italian Privacy Code.ITGaranteGDPR€3,000
19 Sept 2016CONVERSALES INNOVA, S.L.CONVERSALES INNOVA, S.L. was fined by the AEPD €3,000 for sending unsolicited commercial emails without prior consent from recipients. This conduct breached Article 21 of the LSSI.ESAEPDePrivacy€3,000
08 Feb 2007Comune di FirenzeGarante imposed a EUR 3,000 fine on Comune di Firenze for failing to provide adequate information to individuals about the processing of personal data through a video surveillance system. The authority found a breach of Article 13 of the Italian Data Protection Code.ITGaranteGDPR€3,000
29 Apr 2026Consiglio Nazionale dei Periti Industriali e dei Periti Industriali LaureatiThe Consiglio Nazionale dei Periti Industriali e dei Periti Industriali Laureati was fined €3,000 by the Garante. The authority found that the organization failed to ensure transparency in data processing, breaching GDPR principles of lawfulness, fairness, and transparency.ITGaranteGDPR€3,000
22 Feb 2024Comune di Civita CastellanaComune di Civita Castellana was fined EUR 3,000 by the Garante for improper handling of personal data during COVID-19 data transmission. The authority found that GDPR formalities were not properly complied with.ITGaranteGDPR€3,000
19 Nov 2025Greencorp S.R.L.Greencorp S.R.L. was fined EUR 3,000 by ANSPDCP. The authority found that the company failed to notify a personal data security breach.ROANSPDCPGDPR€3,000
18 Jan 2023CONSEJERÍA DE CULTURA DE LA RIOJACONSEJERÍA DE CULTURA DE LA RIOJA was fined for failing to implement corrective measures after the unauthorized recording and dissemination of surveillance footage from the Museo de La Rioja. The authority found a breach of Article 32 GDPR concerning appropriate security measures.ESAEPDGDPR€3,000
22 Nov 2021COMUNIDAD DE PROPIETARIOS R.R.R.The entity was fined by the AEPD for operating a video surveillance system that recorded public transit areas without a justified basis. The authority found a breach of data protection principles.ESAEPDGDPR€3,000