Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.2%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
24 Mar 2022Anonymised (HDPA 17/2022)A fine of EUR 3,000 was imposed for sending unsolicited political communication by SMS without prior consent. The conduct was found to breach Article 11 of Law 3471/2006.GRHDPAePrivacy€3,000
11 Apr 2024Comune di MadignanoThe Garante fined Comune di Madignano EUR 3,000 for unlawfully using surveillance data in a disciplinary proceeding against an employee. The authority found breaches of data protection and transparency principles.ITGaranteGDPR€3,000
29 Jan 2019LOS SEIS MAESTROS S.L.LOS SEIS MAESTROS S.L. was fined by the AEPD EUR 3,000 for processing personal data without consent. The breach involved sending an email offering a discount for an event, contrary to Article 6.1 of the LOPD.ESAEPDePrivacy€3,000
02 Dec 2019IMNOVA RESORT, S.L.IMNOVA RESORT, S.L. was fined by the AEPD EUR 3,000 for installing cookies on its online store without obtaining user consent. The authority found this conduct to be in breach of the LSSI.ESAEPDePrivacy€3,000
01 Apr 2024Your Consulting SRLANSPDCP imposed a fine on Your Consulting SRL for GDPR violations related to insufficient technical and organizational security measures. The security gap allowed unauthorized access to personal data through one of the company’s applications.ROANSPDCPGDPR€3,000
21 Jul 2022Azienda Socio Sanitaria Territoriale RhodenseAzienda Socio Sanitaria Territoriale Rhodense was fined by the Garante EUR 3,000 for violations of data protection rules. The case concerned data breaches and inadequate security measures.ITGaranteGDPR€3,000
06 Apr 2020PETROLIS INDEPENDENTS, S.L.PETROLIS INDEPENDENTS, S.L. was fined by the AEPD in the amount of 3,000 EUR for failing to comply with data protection rules regarding cookie policies on its website. The case concerned information requirements and the compliance of cookie mechanisms with privacy rules.ESAEPDePrivacy€3,000
26 Nov 2020Charly Mike s.r.l.Charly Mike s.r.l. was fined by the Garante EUR 3,000 for improper use of a video surveillance system at Hotel Olimpo. The system was used for continuous monitoring and remote viewing of employees, in breach of data protection rules.ITGaranteGDPR€3,000
03 Nov 2023OTP BANK ROMANIA SAThe National Supervisory Authority for Personal Data Processing imposed a fine of EUR 3,000 on OTP BANK ROMANIA SA for GDPR violations. The case concerned non-compliance with personal data protection requirements.ROANSPDCPGDPR€3,000
13 Apr 2023Comune di Cogollo del CengioThe Garante fined Comune di Cogollo del Cengio EUR 3,000 for breaches of GDPR Articles 5, 6 and 9, as well as Articles 2-ter and 2-septies of the Italian Privacy Code. The case concerned the processing of an employee’s personal data without an adequate legal basis and in breach of data protection rules.ITGaranteGDPR€3,000
14 Sept 2006Pasquadibisceglie PaoloPasquadibisceglie Paolo was fined by the Garante 3,000 EUR for failing to provide adequate information to individuals recorded by a video surveillance system in a commercial establishment. The authority found a breach of privacy rules.ITGaranteGDPR€3,000
15 Sept 2022Comune di ThieneComune di Thiene was fined EUR 3,000 by the Garante for violating data protection principles. The authority found that personal data related to a disciplinary dismissal case was improperly disclosed online.ITGaranteGDPR€3,000
03 Feb 2022FLORAQUEEN FLOWERING THE WORLD S.L.FLORAQUEEN FLOWERING THE WORLD S.L. was fined 3,000 EUR by the AEPD for failing to provide requested information. The case concerned the duty to cooperate with the Spanish data protection authority under GDPR Article 58(1).ESAEPDGDPR€3,000
06 Feb 2025Omniasig Vienna Insurance Group S.A.A fine of 3,000 EUR was imposed for unauthorized access to personal data of a significant number of data subjects over a defined period. The case concerns a data security breach requiring appropriate access controls and protective measures.ROANSPDCPGDPR€3,000
01 Oct 2020Megareduceri TV S.R.L.Megareduceri TV S.R.L. was fined EUR 3,000 by ANSPDCP for violating GDPR provisions. The case concerned non-compliance with certain personal data protection obligations.ROANSPDCPGDPR€3,000
09 May 2024Caffetteria 77 di Dughetti BarbaraThe Garante fined Caffetteria 77 di Dughetti Barbara EUR 3,000 for operating a video surveillance system without meeting the legal requirements. The system captured both customers and employees, creating a data protection compliance breach.ITGaranteGDPR€3,000
19 Mar 2015Trust Center A.E.The company was fined for failing to adequately inform data subjects about the processing of their creditworthiness data. The authority found a breach of Article 11 of the Greek data protection law.GRHDPAGDPR€3,000
31 Jul 2020ASOCIACIÓN DE VIGILANTES DE SEGURIDAD DEL AEROPUERTO DE BARCELONAThe organization was fined by the AEPD in the amount of 3,000 EUR for sending an electoral census of workers to private phones via WhatsApp. The authority found a breach of data protection principles.ESAEPDGDPR€3,000
02 Apr 2025BINBOX GLOBAL SERVICES S.R.L.In March 2025, Romania’s data protection authority ANSPDCP completed an investigation into BINBOX GLOBAL SERVICES S.R.L. The authority found a GDPR violation and imposed a fine of EUR 3,000.ROANSPDCPGDPR€3,000
24 Nov 2022Ordine dei Medici Chirurghi e degli Odontoiatri della Provincia di CagliariOrdine dei Medici Chirurghi e degli Odontoiatri della Provincia di Cagliari was fined €3,000 by the Garante. The authority found breaches of lawfulness, fairness, transparency, and data minimization in the handling of personal data related to an individual's employment.ITGaranteGDPR€3,000