Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.4%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
19 Dec 2024CENTRE D'APPEL (procédure simplifiée)CNIL imposed an administrative fine of EUR 20,000 on CENTRE D'APPEL under a simplified procedure. The case concerned a confirmed regulatory breach, with no further details provided in the record.FRCNILGDPR€20,000
04 Nov 2015VACACIONES EDREAMS SOCIEDAD LIMITADA UNIPERSONALVACACIONES EDREAMS was fined by the AEPD €20,000 for sending unauthorized commercial communications to a user after they had unsubscribed from the newsletter. The case indicates a failure to respect consent and opt-out requirements for marketing communications.ESAEPDePrivacy€20,000
23 Oct 2025Hearst Magazines Italia S.p.A.Hearst Magazines Italia S.p.A. was fined EUR 20,000 by the Garante for publishing personal data relating to an individual's health without a legal basis. The authority found a breach of the principles of lawfulness and fairness in processing.ITGaranteGDPR€20,000
19 Jan 2017Perrone Rosaria e Azienda Universitaria Ospedaliera Ospedali Riuniti di TriestePerrone Rosaria and Azienda Universitaria Ospedaliera Ospedali Riuniti di Trieste were fined by the Garante 20,000 EUR. The sanction concerned unauthorized access by medical staff to personal health data, in breach of data protection rules.ITGaranteGDPR€20,000
01 Jan 2019IBERIA LÍNEAS AÉREAS DE ESPAÑA, S.A. OPERADORA UNIPERSONALIberia was fined by the AEPD 20,000 EUR for continuing to send emails to a customer who had requested removal from the loyalty program and deletion of personal data. The authority found this conduct to be a breach of GDPR Article 6.ESAEPDGDPR€20,000
28 Mar 2023SOCIETE DE PROGRAMMATION INFORMATIQUE (procédure simplifiée)The CNIL imposed a EUR 20,000 fine on SOCIETE DE PROGRAMMATION INFORMATIQUE under a simplified procedure. The record only indicates the financial sanction and does not provide further details on the underlying breach.FRCNILGDPR€20,000
29 May 2025IMMUCURA MED, S.L.IMMUCURA MED, S.L. was fined EUR 20,000 by the AEPD for failing to provide access to personal data and the information requested by the data protection authority. The conduct was found to breach Article 58(1) of the GDPR.ESAEPDGDPR€20,000
17 Jan 2022SERVICIOS FINANCIEROS CARREFOUR, EFC., S.A.SERVICIOS FINANCIEROS CARREFOUR, EFC., S.A. was fined 20,000 EUR by the AEPD. The authority found that the company failed to properly handle a data subject’s request for erasure, which led to continued processing of personal data despite the prior deletion request.ESAEPDGDPR€20,000
11 Dec 2025ETABLISSEMENT PUBLIC EXERCANT UNE ACTIVITE DE GESTION LOCATIVE DE LOGEMENTS (procédure simplifiée)The CNIL imposed an administrative fine of EUR 20,000 on ETABLISSEMENT PUBLIC EXERCANT UNE ACTIVITE DE GESTION LOCATIVE DE LOGEMENTS and issued an injunction. The case concerns a regulatory breach in the area of data protection.FRCNILGDPR€20,000
20 Feb 2018Anonymizováno (ÚOOÚ UOOU-12027/17-24)The entity was fined CZK 20,000 for disclosing sensitive personal data of a witness and a victim in a criminal case during a TV report. The authority found that the processing took place without explicit consent and without a valid legal exception.CZUOOUGDPR€790
01 Jun 2023Ew Business Machines S.p.A.Ew Business Machines S.p.A. was fined 20,000 EUR by the Garante. The authority found that the company used a surveillance system without proper notice, collected employee fingerprints, and tracked employee locations through mobile apps without adequate transparency.ITGaranteGDPR€20,000
19 Jul 2018Idroservice Italia s.r.l.Idroservice Italia s.r.l. was fined by the Garante for failing to respond to a request for information. The authority treated this as a breach of data protection rules.ITGaranteGDPR€20,000
04 Jun 2015Comune di Vico EquenseThe Municipality of Comune di Vico Equense was fined 20,000 EUR by the Garante. The authority found that the security program document was not updated and data processing officers were not appointed, which allowed unauthorized access to sensitive data.ITGaranteGDPR€20,000
21 Feb 2024SOCIEDAD CONJUNTA PARA LA EMISIÓN Y GESTIÓN DE MEDIOS DE PAGO EFC SAIberia Cards was fined by the AEPD for failing to properly delete customer data after confirming cancellation. This caused issues when a former customer reapplied for a card.ESAEPDGDPR€20,000
22 Oct 2025AXARNET COMUNICACIONES, S.L.AXARNET COMUNICACIONES, S.L. suffered a data breach caused by a vulnerability in a third-party program. The incident exposed personal data of 50,250 clients, including names, email addresses, and bank account details, leading to a fine by the AEPD.ESAEPDGDPR€20,000
23 Nov 2017AMAT PALERMO S.P.A.AMAT PALERMO S.P.A. was fined by the Garante 20,000 EUR for failing to properly notify the use of a geolocation system to track vehicles. The authority found a breach of the Italian data protection code.ITGaranteGDPR€20,000
18 Apr 2018Anas S.p.A.Anas S.p.A. was fined by the Garante in the amount of 20,000 EUR for failing to designate employees as data processors and for not issuing instructions on the proper use of surveillance and geolocation systems. The authority found that these omissions breached data protection rules.ITGaranteGDPR€20,000
24 Jan 2024CAJA RURAL DEL SUR, S.C.C.CAJA RURAL DEL SUR, S.C.C. was fined EUR 20,000 by the AEPD for breaching data protection principles. The authority found that confidentiality and integrity of personal data were not adequately ensured, resulting in unauthorized access by third parties.ESAEPDGDPR€20,000
29 Mar 2018SERCOM S.r.l.SERCOM S.r.l. was fined EUR 20,000 by the Garante. The authority found that the company failed to notify changes to its name and the cessation of data processing activities related to economic solvency risk.ITGaranteGDPR€20,000
09 Jul 2020Burgo Group S.p.A.Burgo Group S.p.A. was fined EUR 20,000 by the Garante for violating GDPR principles. The case concerned improper restriction of access to an employee’s corporate email account, which was accessible to other staff members without the employee’s consent.ITGaranteGDPR€20,000