Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.4%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
02 Dec 2021Ica s.r.l.Ica s.r.l. was fined by the Garante EUR 30,000 for failing to implement adequate security measures in its online traffic-fine payment service. The weakness allowed unauthorized access to the personal data of fined citizens.ITGaranteGDPR€30,000
20 Jun 2023Dante International SADante International SA was fined EUR 30,000 by the Romanian authority ANSPDCP. The sanction concerned violations linked to complaints filed by three individuals from Hungary.ROANSPDCPGDPR€30,000
01 Jan 2019TWITTER INTERNATIONAL COMPANY (TWITTER SPAIN, S.L.)Twitter International Company (Twitter Spain, S.L.) was fined EUR 30,000 by the AEPD. The authority found inadequate cookie information and the use of cookies without obtaining user consent, in breach of the LSSI.ESAEPDePrivacy€30,000
28 Oct 2021TPER Trasporto Passeggeri Emilia Romagna S.p.A.TPER Trasporto Passeggeri Emilia Romagna S.p.A. was fined by the Garante EUR 30,000 for violations related to the processing of personal data of call center employees. The case involved potential unauthorized monitoring and insufficient data protection measures.ITGaranteGDPR€30,000
14 Nov 2014Geniki TrapezaThe bank failed to ensure the accuracy of personal data and did not respond adequately to a data access request. The case concerns breaches of data quality obligations and the handling of data subject rights.GRHDPAGDPR€30,000
23 Mar 2023CAAF CGIL Lombardia s.r.l.CAAF CGIL Lombardia s.r.l. was fined EUR 30,000 by the Garante for unlawful processing of personal data. The company sent promotional emails despite a prior request to delete the data.ITGaranteGDPR€30,000
04 Mar 2021CEDICO, CENTRO DE DIAGNÓSTICO POR LA IMÁGEN, S.L.CEDICO, a diagnostic imaging center, was fined EUR 30,000 by the AEPD. The authority found that the company unlawfully shared a patient's MRI report with a mutual insurance company, breaching data protection principles.ESAEPDGDPR€30,000
24 Sept 2019VUELING AIRLINES, S.L.VUELING AIRLINES, S.L. was fined by the AEPD 30,000 EUR for failing to comply with cookie consent requirements on its website. The authority found that the company did not provide the required information and did not properly obtain user consent.ESAEPDePrivacy€30,000
24 Jul 2020IBERIA LÍNEAS AÉREAS DE ESPAÑA, S.A. OPERADORA UNIPERSONALThe AEPD fined Iberia Líneas Aéreas de España, S.A. Operadora Unipersonal 30,000 EUR. The authority found that the website did not provide users with an option to reject cookies in line with consent requirements.ESAEPDePrivacy€30,000
23 Jan 2020Azienda Ospedaliero Universitaria Integrata di VeronaAzienda Ospedaliero Universitaria Integrata di Verona was fined by the Garante EUR 30,000 for employees' unauthorized access to patient health records. The authority found a breach of GDPR principles on data protection and security measures.ITGaranteGDPR€30,000
23 Oct 2025Zephiromedia S.r.l.Zephiromedia S.r.l. was fined EUR 30,000 by the Garante for sending unsolicited promotional emails. The authority also found that recipients were not given an effective way to unsubscribe or exercise their rights.ITGaranteGDPR€30,000
05 Nov 2025RAMÓN GRAU, S.L.RAMÓN GRAU, S.L. was fined by the AEPD for installing a video surveillance system that recorded audio without informing employees. The authority found breaches of GDPR Articles 6(1) and 13 due to the lack of a valid legal basis and required transparency information.ESAEPDGDPR€30,000
14 Jan 2021Azienda sanitaria provinciale di EnnaAzienda sanitaria provinciale di Enna was fined by the Garante €30,000 for unlawfully processing employees’ biometric data to monitor attendance. The conduct breached GDPR requirements on lawful processing and data minimisation.ITGaranteGDPR€30,000
24 Jun 2021Soluzione Tasse S.p.A.Soluzione Tasse S.p.A. was fined by the Garante 30,000 EUR for sending unsolicited emails without proper consent. The case concerned GDPR principles on data processing and transparency.ITGaranteGDPR€30,000
23 May 2025OCI CINE, S.L.OCI CINE, S.L. was fined EUR 30,000 by the AEPD after an incident in which a user's personal information was auto-filled with another person's details in its app. The authority found a breach of data accuracy and processing security principles.ESAEPDGDPR€30,000
12 Oct 2017Roma Gestioni s.r.l.Roma Gestioni s.r.l. was fined EUR 30,000 by the Garante. The authority found that the company retained surveillance footage longer than permitted under privacy rules.ITGaranteGDPR€30,000
01 Feb 2018Iqbal QuasimIqbal Quasim was fined EUR 30,000 by the Garante. The case concerned registering phone SIM cards to third parties without their consent, which breached data protection rules.ITGaranteGDPR€30,000
24 Apr 2024Gestore Dei Servizi Energetici - Gse S.p.A.The Garante fined Gestore Dei Servizi Energetici - Gse S.p.A. 30,000 EUR for failing to respond to a data subject access request. The request concerned the individual's personal performance evaluation records for 2019 and 2020.ITGaranteGDPR€30,000
09 Feb 2011Istituto Ninetta Rosano s.r.lIstituto Ninetta Rosano s.r.l was fined EUR 30,000 by the Garante for violating data protection rules. The authority found non-compliance with the requirements of Article 37 of the Italian Data Protection Code.ITGaranteGDPR€30,000
25 Nov 2021Ordinanza ingiunzione - 25 novembre 2021 [9733002]A healthcare professional was fined by the Garante EUR 30,000 for unlawfully disclosing a patient's personal data, including unpaid medical bills and health information, to third parties. The authority found that the processing lacked a legal basis and breached the principles of lawfulness, fairness, and transparency.ITGaranteGDPR€30,000