Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.2%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
28 Sept 2023Asl Napoli 3 SudThe Garante fined Asl Napoli 3 Sud EUR 30,000 for inadequate security measures that led to a data breach. The incident caused limited service disruption.ITGaranteGDPR€30,000
28 Jun 2023Fortis Insolvency LimitedFortis Insolvency Limited sent 558,354 direct marketing SMS messages without valid consent, of which 527,481 were received by subscribers between 26 July 2020 and 26 July 2021. This breached regulation 22 of PECR. The company was fined £30,000 and issued with an enforcement notice.GBICOePrivacy€34,713
20 Feb 2026VodafoneThe Greek Data Protection Authority fined Vodafone EUR 30,000 for GDPR breaches related to a subscriber’s request to access recorded phone conversations. The authority found violations of transparency obligations under Article 12 and of the rights of access and restriction of processing under Articles 15 and 18 GDPR.GRΑρχή Προστασίας Δεδομένων Προσωπικού ΧαρακτήραGDPR€30,000
14 Oct 2024National Debt Advice LimitedNational Debt Advice Limited sent 129,902 unsolicited direct marketing text messages, breaching regulation 22 of PECR. The activity generated more than 4,000 complaints to the 7726 spam reporting service. The ICO imposed a £30,000 fine and issued an enforcement notice.GBICOePrivacy€35,856
05 Oct 2017Comune di CivitavecchiaComune di Civitavecchia was fined by the Garante for unlawfully transmitting sensitive data revealing the health status of disabled students to service providers without a proper legal basis. The authority found that the processing breached data protection and confidentiality requirements.ITGaranteGDPR€30,000
14 Jul 2011Il Tarì società consortile per azioniIl Tarì società consortile per azioni was fined €30,000 by the Garante for failing to provide adequate information and notification about the processing of personal data using biometric systems. The case concerned a breach of the Italian Data Protection Code.ITGaranteGDPR€30,000
29 Sept 2021GEDI News Network S.p.A.GEDI News Network S.p.A. was fined 30,000 EUR by the Garante for publishing personal data and detailed information about an individual involved in a workplace accident. The authority found a breach of data protection rules.ITGaranteGDPR€30,000
16 Dec 2021Progetto Udire S.r.l.Progetto Udire S.r.l. was fined by the Garante 30,000 EUR. The authority found that the company sent unsolicited marketing communications without proper consent and failed to provide information on the origin of personal data when requested by the data subject.ITGaranteGDPR€30,000
20 Mar 2015IANO OIKONOMIKE EKDOSEIS AEIANO OIKONOMIKE EKDOSEIS AE was fined EUR 30,000 by the HDPA for sending unsolicited electronic communications. The company collected a large number of email addresses without consent, breaching data protection rules.GRHDPAePrivacy€30,000
16 Apr 202520 MINUTOS EDITORA, S.L.20 MINUTOS EDITORA, S.L. was fined by the AEPD for the unauthorized dissemination of a video containing personal data. The authority found a breach of the data minimization principle under Article 5(1)(c) GDPR.ESAEPDGDPR€30,000
16 Dec 2009Casa di cura Villa Russo s.p.a.Casa di cura Villa Russo s.p.a. was fined by the Garante for processing personal data without proper notification. The authority found violations of articles 37 and 38 of the Italian Data Protection Code.ITGaranteGDPR€30,000
22 Feb 2018FAMAS S.R.L.FAMAS S.R.L. was fined by the Garante for using a biometric system based on fingerprint recognition to record employee attendance without a proper legal basis. The case concerned the processing of biometric data in an employment context, where specific lawful grounds are required.ITGaranteGDPR€30,000
09 May 2024Unicredit S.p.a.Unicredit S.p.a. was fined EUR 30,000 by the Garante for failing to respond to a personal data access request submitted by an heir. The authority found a breach of GDPR Article 15 and the Italian privacy code.ITGaranteGDPR€30,000
29 Nov 2012G & W Invest s.r.l.G & W Invest s.r.l. was fined €30,000 by the Italian data protection authority, Garante. The case concerned processing biometric data without timely notification, in breach of the Italian Data Protection Code.ITGaranteGDPR€30,000
21 Sept 2018Anonymizováno (ÚOOÚ UOOU-01895/18-25)The entity was fined by the UOOU for processing personal data without consent and for failing to implement adequate security measures. The authority found these actions to be in breach of Czech data protection law.CZUOOUGDPR€1,173
21 Aug 2014GROUPON SPAIN, S.L.U.Groupon Spain, S.L.U. was fined by the AEPD EUR 30,000 for sending unsolicited commercial emails to the complainant. The authority found that the conduct breached the Spanish LSSI requirements governing marketing communications.ESAEPDePrivacy€30,000
05 Dec 2019VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD EUR 30,000 for inaccurately processing personal data. The company claimed a debt for a service that had already been terminated and had no outstanding balance.ESAEPDGDPR€30,000
08 Jun 2023L’Editoriale Nazionale S.r.l.The Garante fined L’Editoriale Nazionale S.r.l. EUR 30,000 for publishing articles that breached privacy rules. The company disclosed personal and sensitive data relating to a deceased minor without showing that the information was essential.ITGaranteGDPR€30,000
13 May 2015Gelpi Elettrodomestici S.r.l.Gelpi Elettrodomestici S.r.l. was fined 30,000 EUR by the Garante. The case concerned the activation of SIM cards in individuals' names without their knowledge, which breached data protection rules.ITGaranteGDPR€30,000
22 Jul 2021Flowbird s.r.l.Flowbird s.r.l. was fined EUR 30,000 by the Garante for processing personal data through parking meters in Rome without a legal basis. The authority also found that the company failed to maintain a record of processing activities.ITGaranteGDPR€30,000