Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.2%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
02 Jul 2021PODEMOS PARTIDO POLÍTICOPODEMOS PARTIDO POLÍTICO was fined by the AEPD for irregularities in its video surveillance system. The cameras excessively captured public space without justification, and proper signage was missing.ESAEPDGDPR€4,000
23 Oct 2024SNOW INK SIERRA NEVADA, S.L.SNOW INK SIERRA NEVADA, S.L. was fined by the AEPD 4,000 EUR for using surveillance cameras that captured public areas, which breached data protection principles. Privacy masks were implemented during the sanctioning process.ESAEPDGDPR€4,000
01 Feb 2024HOGAR LUZ Y GAS S.L.HOGAR LUZ Y GAS S.L. was fined EUR 4,000 by the Spanish Data Protection Agency (AEPD). The case concerned the failure to provide requested information, which breaches Article 58.1 of the GDPR.ESAEPDGDPR€4,000
20 Jun 2024Provvedimento del 20 giugno 2024 [10037411]The Garante imposed a fine on a healthcare entity for delays in providing preoperative photographs. The delay affected the complainant's legal position in ongoing proceedings.ITGaranteGDPR€4,000
02 Apr 2015Comune di MontefrancoComune di Montefranco was fined EUR 4,000 by the Garante. The authority found that the role of Mercurio service s.r.l. was not properly regulated, although it processed personal data relating to traffic violations without proper authorization.ITGaranteGDPR€4,000
01 Jan 2022FUNDACIÓN CIPRI GÓMESFUNDACIÓN CIPRI GÓMES was fined EUR 4,000 by the AEPD for failing to provide information on personal data processing to athletes or their guardians. The authority also found unlawful processing of a minor's personal data after the parents had withdrawn him from the gym.ESAEPDGDPR€4,000
27 May 2021Società Cavourese S.p.A.Società Cavourese S.p.A. was fined EUR 4,000 by the Italian data protection authority, Garante. The case concerned improper handling of personal data related to employee disciplinary proceedings, in breach of the GDPR and national privacy rules.ITGaranteGDPR€4,000
26 Mar 2015Comune di Santa NinfaComune di Santa Ninfa was fined EUR 4,000 by the Garante for unlawfully publishing personal data on its institutional website. The data remained available for longer than the legally permitted 15 days, constituting a data protection breach.ITGaranteGDPR€4,000
23 Oct 2024ASSOCIATION PARTICIPANT AUX ACTIVITES DES ORGANISATIONS POLITIQUES (procédure simplifiée)CNIL imposed a EUR 4,000 penalty on ASSOCIATION PARTICIPANT AUX ACTIVITES DES ORGANISATIONS POLITIQUES under a simplified procedure. The case concerns liquidation of an astreinte, indicating that a prior obligation was not fulfilled on time.FRCNILGDPR€4,000
30 Jan 2020Liceo Nobel di Torre del GrecoLiceo Nobel di Torre del Greco was fined EUR 4,000 by the Garante for publishing a teacher ranking list on its website. The conduct breached GDPR principles of lawfulness, fairness, transparency, and data minimization.ITGaranteGDPR€4,000
27 Jan 2021Istituto Comprensivo Villanova D’AstiIstituto Comprensivo Villanova D’Asti was fined EUR 4,000 by the Garante for publishing personal data online. The disclosed information could reveal health status and economic-social conditions, breaching data minimization and transparency principles.ITGaranteGDPR€4,000
06 Nov 2014Comune di VeronellaComune di Veronella was fined by the Garante for unlawfully publishing personal data on its online notice board for longer than the legally permitted 15 days. This constituted a breach of data protection rules.ITGaranteGDPR€4,000
10 Apr 2025Gioele MagaldiThe Garante fined Gioele Magaldi, the manager of a blog, EUR 4,000 for publishing defamatory articles. The authority found that the content contained false information and exceeded the limits of the right to report because it lacked social utility.ITGaranteGDPR€4,000
05 Nov 2020DR MARÍN CIRUGIA PLÁSTICA, S.L.P.DR MARÍN CIRUGIA PLÁSTICA, S.L.P. was fined EUR 4,000 by the AEPD. The authority found that the company failed to provide a privacy policy on its website and used personal data for marketing purposes without consent.ESAEPDePrivacy€4,000
06 Nov 2014Comune di GerenzanoThe Municipality of Gerenzano was fined 4,000 EUR by the Garante for failing to appoint a socially useful worker as a data processor. The authority found this breached the minimum security measures required under the data protection code.ITGaranteGDPR€4,000
22 Jul 2022MAX2PROTECT, S.L.MAX2PROTECT, S.L. was fined EUR 4,000 by the AEPD for sending commercial emails without the required authorization. The case concerned a breach of Article 21 of the LSSI and involved unauthorized marketing communications.ESAEPDePrivacy€4,000
05 Jun 2014Comune di TerniThe Garante fined Comune di Terni €4,000 for publishing personal data on its website for longer than the legally permitted 15 days. The authority found this to be a breach of data protection rules.ITGaranteGDPR€4,000
20 Dec 2021INSEKT FOOD S.L.INSEKT FOOD S.L. was fined by the AEPD EUR 4,000 for sharing an individual's personal data in WhatsApp group chats without consent. The authority found that the processing lacked a lawful basis under Article 6 of the GDPR.ESAEPDGDPR€4,000
06 Oct 2016Comune di FurnariComune di Furnari was fined for publishing personal data on its institutional website. It also failed to respond to information requests from the Garante.ITGaranteGDPR€4,000
25 Jun 2015Comune di ParmaComune di Parma was fined EUR 4,000 by the Garante for unlawfully publishing candidates' personal data on its institutional website. The authority found a breach of data protection rules.ITGaranteGDPR€4,000