Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.4%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
10 Jul 2024Dane anonimowe (Panią A. Z. prowadzącą działalność gospodarczą pod firmą B. z siedzibą w W przy ul.)The President of UODO imposed an administrative fine on an individual conducting business activity. The sanction resulted from failure to cooperate with the authority and from not providing access to personal data and information necessary for supervisory tasks.PLUODOGDPR€5,129
05 Jan 2021Dane anonimowe (M. Sp. z o.o. z siedzibą w Z. przy)The President of UODO imposed an administrative fine of PLN 21,397 on M. Sp. z o.o. The company failed to cooperate with the authority and did not provide information needed to assess a complaint concerning personal data processing.PLUODOGDPR€4,705
21 May 2025Menarini Silicon Biosystems SpAThe Garante imposed a 21,000 EUR fine on Menarini Silicon Biosystems SpA for violations related to personal data processing. The case involved inadequate safeguards in the use of algorithms to identify at-risk patients and online reports accessible to other patients.ITGaranteGDPR€21,000
20 Jul 2017Centro Laser s.r.l.Centro Laser s.r.l. was fined EUR 20,400 by the Garante for using inadequate password procedures and failing to provide required information on data processing to users. The case concerns breaches of data protection rules.ITGaranteGDPR€20,400
14 Sept 2006Banca Sella S.p.a.Banca Sella S.p.a. was fined EUR 20,000 by the Garante for processing biometric data without the notification required under the privacy code. The authority found this to be a breach of Italian privacy rules.ITGaranteGDPR€20,000
26 Oct 2023Edizioni Proposta Sud S.r.l.The Garante fined Edizioni Proposta Sud S.r.l. €20,000 for publishing false information about an individual's health status without verifying its accuracy. The authority found this breached GDPR principles on data protection and accuracy.ITGaranteGDPR€20,000
26 Apr 2018Gianluigi GuarinoGianluigi Guarino, director of the online newspaper Casertace.net, was fined by the Garante. The sanction concerned his failure to respond to an information request about data processing, which breached Article 164 of the Italian Privacy Code.ITGaranteGDPR€20,000
31 Jan 2026SC Tensa Art Design SAThe Romanian data protection authority fined SC Tensa Art Design SA, operator of the Lensa brand, EUR 20,000 under the GDPR. The sanction followed the company’s failure to respond to the authority’s investigative request concerning cookie tracking and behavioral advertising on its website.ROAutoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter PersonalGDPR€20,000
08 Jul 2024COMERCIAL GIRONA DE LLIBRES, S.L.COMERCIAL GIRONA DE LLIBRES, S.L. was fined by the AEPD 20,000 EUR for inadequate security measures. The authority cited, among other issues, the sending of credentials by email, which breached Article 32 of the GDPR.ESAEPDGDPR€20,000
15 Mar 2018Directafin s.p.a.Directafin s.p.a. was fined by the Garante in the amount of EUR 20,000 for using a single consent flag for multiple processing purposes. This included marketing and sharing personal data with third parties without valid consent.ITGaranteGDPR€20,000
01 Jan 2018VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined 20,000 EUR by the AEPD for sending unsolicited marketing emails. The authority found that recipients were not given an effective unsubscribe option, despite a request to be removed from the mailing list.ESAEPDePrivacy€20,000
15 Nov 2025Państwowego Powiatowego Inspektora Sanitarnego w M., ul.UODO imposed a PLN 20,000 administrative fine on the State District Sanitary Inspector in M. The authority found that appropriate technical and organizational measures based on a risk assessment were not implemented, and that the effectiveness of safeguards for data processed on external media was not regularly tested. The case concerned a breach of the integrity and confidentiality principle.PLUODOGDPR€4,725
07 Apr 2022Made in Italy s.r.l.s.Made in Italy s.r.l.s. was fined EUR 20,000 by the Garante for carrying out promotional contacts without obtaining consent. The authority also found that the company failed to respond to data subject rights requests, which is a breach of data protection obligations.ITGaranteGDPR€20,000
01 Jun 2023Cooperjob S.p.A.Cooperjob S.p.A. was fined EUR 20,000 by the Garante for failing to respond within the required timeframe to a job applicant’s request to delete personal data. The authority found a breach of GDPR Article 12 on timely handling of data subject requests.ITGaranteGDPR€20,000
09 Oct 2019Vreau Credit S.R.L.Vreau Credit S.R.L. was fined by ANSPDCP in the amount of 20,000 EUR for failing to notify a personal data breach without undue delay. The company had been aware of the incident since December 2018 but did not inform the supervisory authority promptly.ROANSPDCPGDPR€20,000
01 Jan 2016EASYVOYAGE SASEASYVOYAGE SAS was fined by the AEPD in the amount of 20,000 EUR for sending unsolicited commercial emails. The conduct continued despite requests for data cancellation, which breached Article 21.1 of the LSSI.ESAEPDePrivacy€20,000
27 Jan 2025Orange România SAOrange România SA was fined EUR 20,000 by ANSPDCP for GDPR violations. The case concerns non-compliance with personal data protection requirements.ROANSPDCPGDPR€20,000
26 Jul 2012Comune di MilanoThe Garante fined Comune di Milano EUR 20,000 for failing to implement minimum security measures on two computer stations at a primary school. The case concerned non-compliance with data protection requirements.ITGaranteGDPR€20,000
16 Dec 2021FCA Italy s.p.a.FCA Italy s.p.a. was fined 20,000 EUR by the Garante for breaching GDPR provisions on the right of access and transparency obligations. The case arose from a complaint by an English citizen about the handling of their personal data.ITGaranteGDPR€20,000
13 Sept 2017Coleman s.p.a.Coleman s.p.a. was fined by the Garante 20,000 EUR for failing to implement minimum security measures for online booking requests. This allowed access to personal data without authentication.ITGaranteGDPR€20,000