Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.4%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
11 Apr 2013Sound station s.a.s.Sound station s.a.s. was fined 30,000 EUR by the Garante for registering numerous phone SIM cards to unaware third parties. The conduct breached data protection requirements.ITGaranteGDPR€30,000
18 Jun 2020BANCO BILBAO VIZCAYA ARGENTARIA, S.A.Banco Bilbao Vizcaya Argentaria, S.A. was fined by the AEPD in the amount of EUR 30,000 for consulting personal data in credit files without an existing contractual relationship. The authority found that this conduct breached data processing principles.ESAEPDGDPR€30,000
10 Jan 2020XFERA MÓVILES, S.A.XFERA MÓVILES, S.A. was fined by the AEPD EUR 30,000 for a data protection breach. A customer's data was incorrectly linked to another person, which allowed unauthorized access to personal information.ESAEPDGDPR€30,000
28 Mar 2022VUELING AIRLINES, S.A.Vueling Airlines, S.A. was fined EUR 30,000 by the AEPD for breaching data protection rules. The company required customers to accept commercial data sharing in order to purchase tickets on its website, without providing an option to refuse cookies.ESAEPDePrivacy€30,000
10 Jul 2025Centro Medico Italiano S.r.l.Centro Medico Italiano S.r.l. was fined by the Garante 30,000 EUR for failing to provide an adequate response to a data subject’s request for access to health data and information about its processing. The authority found a breach of GDPR Article 15.ITGaranteGDPR€30,000
04 Oct 2011Villa Azzurra Hospital s.r.l.Villa Azzurra Hospital s.r.l. was fined by the Garante in the amount of 30,000 EUR for failing to comply with data processing notification requirements. The breach concerned obligations under the Italian Data Protection Code.ITGaranteGDPR€30,000
22 Dec 2016Planetel s.r.l.Planetel s.r.l. was fined by the Garante in the amount of EUR 30,000 for using inadequate authentication procedures to access telecommunication traffic data. The authority also found that required security measures for data storage were not implemented.ITGaranteGDPR€30,000
29 Apr 2025Ordine professionale degli psicologi della LombardiaOn 2025-04-29, the Italian Data Protection Authority fined the Ordine professionale degli psicologi della Lombardia EUR 30,000. The sanction concerned breaches of Articles 5(1)(f) and 32 GDPR following a data breach and the failure to implement adequate security measures.ITGarante per la protezione dei dati personaliGDPR€30,000
16 Feb 2016ROCK INTERNET, S.L.ROCK INTERNET, S.L. was fined EUR 30,000 by the AEPD for sending unsolicited commercial emails despite the recipient’s repeated requests to unsubscribe. The authority found this conduct breached Article 21.1 of the LSSI.ESAEPDePrivacy€30,000
21 Oct 2010Giomi s.p.a. - Gestione Istituti Ortopedici nel mezzogiorno d'ItaliaGiomi s.p.a. was fined €30,000 by the Italian data protection authority, Garante. The case concerned data processing activities carried out without the required notification under the Italian data protection code.ITGaranteGDPR€30,000
22 Feb 2018Comune di FiumicinoComune di Fiumicino was fined by the Garante for failing to notify a data breach within the required timeframe. The authority found a violation of the Italian Data Protection Code.ITGaranteGDPR€30,000
04 Apr 2025MEDCENTER SRLMEDCENTER SRL was fined EUR 30,000 by ANSPDCP for breaching GDPR requirements. The company failed to inform affected individuals about a personal data security breach.ROANSPDCPGDPR€30,000
27 Apr 2023Tiziana Life Science LimitedTiziana Life Science Limited was fined by the Italian Garante in the amount of EUR 30,000. The case concerned failure to provide information and obtain consent for processing personal and genetic data acquired from the bankrupt company Shar.Dna S.p.A. for scientific research purposes.ITGaranteGDPR€30,000
23 Jan 2023ENFOKA SISTEMAS GLOBALES, S.L.ENFOKA SISTEMAS GLOBALES, S.L. was fined by the AEPD 30,000 EUR for processing personal data without consent. The company signed an energy supply contract in the complainant's name without their knowledge, which breaches Article 6(1) of the GDPR.ESAEPDGDPR€30,000
15 Dec 2022Eurosanità S.P.A.Eurosanità S.P.A. was fined by the Garante in the amount of 30,000 EUR for violations related to the processing of health data. The authority cited inadequate personal data protection measures.ITGaranteGDPR€30,000
29 Sept 2021Comune di FormiaComune di Formia was fined for processing personal data linked to parking subscription services without providing adequate information to data subjects. The authority also found excessive data collection and a failure to clearly define the role of the external data processor.ITGaranteGDPR€30,000
31 Mar 2023APOLLONIA TOPCO, S.L.APOLLONIA TOPCO, S.L. was fined by the AEPD EUR 30,000 for improperly requesting copies of clients’ ID documents. The authority also noted a failure to respond to a data protection complaint, in breach of data minimization and purpose limitation principles.ESAEPDGDPR€30,000
15 Feb 2022Organismos Limenos Irakleiou A.E.Organismos Limenos Irakleiou A.E. was fined 30,000 EUR by the HDPA for breaching the data subject’s right of access. The company failed to provide requested video footage and incorrectly claimed that the data had been deleted.GRHDPAGDPR€30,000
01 Mar 2018Comune di San Mango PiemonteComune di San Mango Piemonte was fined for unlawfully using a biometric system based on fingerprint processing to record employee attendance. The authority found that this processing breached data protection rules.ITGaranteGDPR€30,000
12 Jun 2015ALPHA BANKALPHA BANK was fined 30,000 EUR by the HDPA. The authority found that the bank failed to notify the location and facilities used for ICAP data processing.GRHDPAGDPR€30,000