Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
15 Jun 2022S.C.In May 2022, the Romanian supervisory authority ANSPDCP completed an investigation into the operator S.C. and found a violation of GDPR provisions. A fine of 3,000 EUR was imposed.ROANSPDCPGDPR€3,000
17 Apr 2026Provvedimento del 17 aprile 2026 [10254325]The supervisory authority found that a video surveillance system with 25 cameras operated without the required informational signage. The breach concerned GDPR information obligations.ITGaranteGDPR€3,000
09 Mar 2023Aesse S.r.l.s.Aesse S.r.l.s. was fined by the Italian Garante in the amount of €3,000. The case concerned unsolicited telemarketing calls made without consent and insufficient information provided about the source of personal data.ITGaranteGDPR€3,000
09 Mar 2023Stefano MolenaThe Garante imposed a EUR 3,000 fine on Stefano Molena for operating a surveillance camera without the required informational signage. The breach concerned privacy rules and the duty to properly inform individuals subject to monitoring.ITGaranteGDPR€3,000
18 Aug 2021EULEN SEGURIDAD, S.A.EULEN SEGURIDAD, S.A. was fined by the AEPD 3,000 EUR for disclosing employees' DNI numbers in a workplace notice. The authority found a breach of confidentiality and data security principles.ESAEPDGDPR€3,000
15 Dec 2022B.B.B.The entity was fined for operating surveillance cameras directed at public areas without the required authorization or signage. The authority found this to be a breach of data protection rules.ESAEPDGDPR€3,000
29 May 2008Circolo privato 'Astoria'The private club “Astoria” was fined 3,000 EUR by the Garante for failing to provide the required data protection notice to individuals identified through its video surveillance system. The breach concerned Article 13 of the Italian Data Protection Code.ITGaranteGDPR€3,000
27 Mar 2025Comune di Palma di MontechiaroThe Municipality of Comune di Palma di Montechiaro was fined EUR 3,000 by the Italian data protection authority, Garante. The sanction concerned the failure to communicate the contact details of its Data Protection Officer to the authority, as required by Article 37 GDPR.ITGaranteGDPR€3,000
25 Nov 2022OTP LEASING ROMANIA IFN SAOTP LEASING ROMANIA IFN SA was fined by ANSPDCP for breaching data security provisions. The penalty followed a data breach notification indicating that personal data had not been adequately protected.ROANSPDCPGDPR€3,000
08 Feb 2023MEDECIN GENERALISTE (procédure simplifiée)The CNIL imposed a EUR 3,000 fine on MEDECIN GENERALISTE under a simplified procedure. The authority also issued an injunction to remedy the identified deficiencies.FRCNILGDPR€3,000
12 Nov 2025Fan Courier Express S.R.L.Fan Courier Express S.R.L. was fined by ANSPDCP in the amount of €3,000 for processing personal data in breach of GDPR. The case concerned unlawful handling of personal data by the company.ROANSPDCPGDPR€3,000
24 Jun 2025I ASPIDA TOU DAVIDThe entity did not satisfy a minor's request to access personal data, which constitutes a breach of GDPR principles. HDPA imposed a fine of EUR 3,000.GRHDPAGDPR€3,000
16 Oct 2024Your Consulting SRLThe national supervisory authority completed an investigation into Your Consulting SRL and found violations of GDPR provisions. As a result, a fine of EUR 3,000 was imposed.ROANSPDCPGDPR€3,000
20 Nov 2008G.F.A. marketing di Cavezzali PatriziaG.F.A. marketing di Cavezzali Patrizia was fined EUR 3,000 by the Italian Garante for failing to provide the required data protection notice to recipients of promotional faxes. The conduct breached Article 13 of the Italian Data Protection Code.ITGaranteGDPR€3,000
01 Mar 2017FRONTERA SISTEMAS DE ESPAÑA SLFRONTERA SISTEMAS DE ESPAÑA SL was fined EUR 3,000 by the AEPD for installing cookies on users' devices without prior consent. The authority found this breached the information and consent requirements for data storage and retrieval devices.ESAEPDePrivacy€3,000
12 Jun 2021MERCEDES GERENCIA, S.L.MERCEDES GERENCIA, S.L. was fined by the AEPD in the amount of 3,000 EUR for breaching Article 58.1 of the GDPR. The case concerned non-compliance with obligations related to the supervisory authority’s powers.ESAEPDGDPR€3,000
12 Apr 2021INSTAPACK, S.L.INSTAPACK, S.L. was fined by the AEPD for sending unsolicited SMS messages without valid consent. The authority also found that the company failed to respond to a deletion request, constituting a breach of GDPR Article 6(1)(a).ESAEPDGDPR€3,000
01 May 2025SC Piramida Trade Invest SRLThe Romanian DPA ANSPDCP imposed a total fine of EUR 3,000 on SC Piramida Trade Invest SRL for unlawful audio-video monitoring of employees and inadequate staff information. It also found that the company failed to respond to access, erasure, and objection requests within the legal deadline; a separate email-forwarding issue resulted only in a warning.ROAutoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter PersonalGDPR€3,000
28 Sept 2023Palombaro s.r.l.Palombaro s.r.l. was fined by the Garante in the amount of 3,000 EUR for operating a video surveillance system without adequate informational signage. The authority found a breach of GDPR transparency requirements toward individuals being recorded.ITGaranteGDPR€3,000
30 Sept 2024ASSOCIATION AYANT POUR OBJET LA CREATION D'UN RESEAU DE SANTE PSYCHIATRIQUE (procédure simplifiée)CNIL imposed an administrative fine of EUR 3,000 on ASSOCIATION AYANT POUR OBJET LA CREATION D'UN RESEAU DE SANTE PSYCHIATRIQUE. The case concerns a breach of personal data protection rules under a simplified procedure.FRCNILGDPR€3,000