Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.2%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
01 Jan 2024MAD COOL FESTIVAL, S.L.MAD COOL FESTIVAL, S.L. was fined 3,500 EUR by the AEPD for a data breach on its website. The incident exposed users’ personal data, indicating non-compliance with GDPR Articles 5(1)(f) and 32.ESAEPDGDPR€3,500
10 Mar 2022Anonymisé (CNPD decision-07-fr-2022)The CNPD found that Société A breached the GDPR by failing to comply with data minimization, retention limitation, and information provision requirements. The case concerned improper personal data processing in relation to compliance obligations.LUCNPDGDPR€3,500
27 Mar 2025Comune di MilazzoThe Garante fined the Comune di Milazzo €3,600 for failing to provide adequate data protection information on its website. The authority found a breach of GDPR principles of lawfulness, fairness, and transparency.ITGaranteGDPR€3,600
13 Dec 2022Anonymisé (CNPD decision-21-fr-2022)The company was fined EUR 3,700 by the CNPD for breaching the transparency obligations under Article 12(1) of the GDPR. The authority found that information was not sufficiently accessible to users.LUCNPDGDPR€3,700
13 Dec 2022Anonymisé (CNPD decision-24-fr-2022)The entity failed to meet GDPR transparency obligations, particularly regarding the accessibility and comprehensibility of information provided to data subjects. CNPD imposed a fine of EUR 3,700.LUCNPDGDPR€3,700
10 Oct 2016ROCK INTERNET S.L.ROCK INTERNET S.L. was fined 3,800 EUR by the AEPD. The case concerned sending unsolicited commercial emails without recipient consent, in breach of Article 21.1 of the LSSI.ESAEPDePrivacy€3,800
13 Jan 2015LEROY MERLIN ESPAÑA S.L.U.LEROY MERLIN ESPAÑA S.L.U. was fined by the AEPD EUR 3,900 for sending unsolicited commercial SMS messages without recipient consent. The authority found this conduct breached Article 21 of the LSSI.ESAEPDePrivacy€3,900
13 Jun 2022SOCIETE D'ENTRETIEN ET REPARATION DE VEHICULESCNIL imposed a liquidation of the penalty payment against SOCIETE D'ENTRETIEN ET REPARATION DE VEHICULES in the amount of EUR 3,900. The measure relates to failure to comply with a prior obligation within the required deadline.FRCNILGDPR€3,900
28 May 2026Action Fit di MilanoThe Garante fined Action Fit di Milano EUR 3,930 for sending unsolicited commercial emails to a customer without consent. The authority found this to be a breach of data protection rules.ITGaranteGDPR€3,930
25 Sept 2025Comune di PazzanoThe Garante imposed a fine of 3,960 EUR on Comune di Pazzano for failing to meet data protection obligations. The case concerned, among other issues, the improper provision of the Data Protection Officer’s contact details and other GDPR requirements.ITGaranteGDPR€3,960
09 Oct 2025SOCIETE EXERCANT UNE ACTIVITE DE VENTE A DISTANCE SUR CATALOGUE GENERAL (procédure simplifiée)The CNIL imposed an administrative fine of EUR 4,000 on SOCIETE EXERCANT UNE ACTIVITE DE VENTE A DISTANCE SUR CATALOGUE GENERAL. The case was handled under a simplified procedure.FRCNILGDPR€4,000
23 Apr 2015Soprintendenza per i Beni Architettonici e Paesaggistici di Venezia e LagunaThe Soprintendenza per i Beni Architettonici e Paesaggistici di Venezia e Laguna was fined 4,000 EUR by the Garante. The authority found that personal data had been unlawfully communicated to private entities without an appropriate legal basis, in breach of Article 19 of the Italian Data Protection Code.ITGaranteGDPR€4,000
25 Mar 2021Comune di MonteiasiComune di Monteiasi was fined by the Garante €4,000 for breaching the data minimization principle. The municipality published personal data on its website, including names and IBANs, that were not necessary for transparency purposes.ITGaranteGDPR€4,000
13 Oct 2022B.B.B.A tenant complained that the landlord installed a surveillance camera in the kitchen of the rented property without consent. The AEPD found a breach of data protection rules and imposed a EUR 4,000 fine.ESAEPDGDPR€4,000
13 Feb 2025Comune di TuscaniaThe Garante imposed a 4,000 EUR fine on Comune di Tuscania for violating data protection rules. The authority took into account the limited financial resources of the small municipality when setting the sanction.ITGaranteGDPR€4,000
27 Mar 2014Comune di ConversanoComune di Conversano was fined 4,000 EUR by the Garante for failing to update the annual Security Policy Document. The breach concerned compliance with data protection obligations.ITGaranteGDPR€4,000
07 Nov 2018Comune di BuccinoComune di Buccino was fined for unlawfully publishing personal data online without a legal basis. This violated Article 19 of the Italian Data Protection Code.ITGaranteGDPR€4,000
06 Oct 2016Comune di FurnariThe Municipality of Furnari was fined 4,000 EUR by the Garante. The authority found that personal data remained published on the institutional website beyond the legally permitted period.ITGaranteGDPR€4,000
18 Nov 2015G.M.C. - Giuseppe Marra Communications s.a.p.a.G.M.C. - Giuseppe Marra Communications s.a.p.a. was fined by the Garante in the amount of €4,000 for unlawfully obtaining consent for data processing through a newsletter subscription. The form included marketing purposes beyond the stated intent, which breached Article 23 of the Italian Data Protection Code.ITGaranteGDPR€4,000
11 Dec 2014Progetto Acqua Firenze s.r.l.Progetto Acqua Firenze s.r.l. was fined by the Garante for making an unsolicited promotional phone call. The conduct infringed the complainant's right to object as recorded in the public opt-out list.ITGaranteGDPR€4,000