Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.2%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
10 Nov 2022Comune di Villafranca di VeronaThe Comune di Villafranca di Verona was fined 4,000 EUR by the Garante for breaching data protection principles. The authority found that personal data linked to a sensitive private matter was improperly disclosed online.ITGaranteGDPR€4,000
14 Apr 2021Avalos Consultores, S.L.Avalos Consultores, S.L. was fined by the AEPD 4,000 EUR for transferring personal data to another company without the data subject's consent. The authority found this breached Article 6 of the GDPR.ESAEPDGDPR€4,000
02 Jul 2020Regione CampaniaRegione Campania was fined EUR 4,000 by the Garante. The authority found a breach of the data minimization principle after personal data was published online without a proper legal basis.ITGaranteGDPR€4,000
03 Feb 2025CENTRAL SINDICAL INDEPENDIENTE Y DE FUNCIONARIOS CSI-CSIFThe labor union CSI-CSIF was fined EUR 4,000 by the AEPD for failing to adequately protect personal data during a voting process. The authority found breaches of GDPR Articles 5(1)(f) and 32 relating to security and confidentiality.ESAEPDGDPR€4,000
02 Apr 2015Regione CampaniaThe Garante fined Regione Campania EUR 4,000 for failing to provide requested information related to a disciplinary procedure. The authority found a breach of data protection rules.ITGaranteGDPR€4,000
04 Jun 2015Centrex srlCentrex srl was fined by the Garante for conducting telemarketing activities without prior informed consent from individuals. The case involved promotional calls to numbers listed in the public opposition registry.ITGaranteGDPR€4,000
20 Nov 2008XYThe entity was fined by the Garante in the amount of 4,000 EUR for failing to respond to a request for information concerning unsolicited promotional emails. The case concerned non-compliance with data protection obligations.ITGaranteGDPR€4,000
31 Jan 2019Istituto Scolastico Superiore “Andrea Mantegna”Istituto Scolastico Superiore “Andrea Mantegna” was fined by the Garante €4,000 for unlawfully publishing personal data on its institutional website. The disclosure included health information about teaching staff, which is sensitive personal data.ITGaranteGDPR€4,000
17 Jul 2023HSSERVICE LIZCON SOLUTIONS, S.L.HSSERVICE LIZCON SOLUTIONS, S.L. was fined by the AEPD EUR 4,000 for failing to provide information about personal data processing when a customer brought in a TV for repair. The authority also found that the company’s website lacked the required data protection information.ESAEPDGDPR€4,000
24 Jul 2014Intermatica Holding s.r.l.Intermatica Holding s.r.l. was fined by the Italian Garante for failing to adopt minimum security measures. The company used passwords of seven characters instead of the required eight, breaching Article 33 of the Italian Data Protection Code.ITGaranteGDPR€4,000
26 Sept 2024CI & DI Food s.r.l.CI & DI Food s.r.l. was fined by the Garante 4,000 EUR for failing to respond to an employee’s request to access personal data related to employment. The request included work attendance records.ITGaranteGDPR€4,000
19 Mar 2015Liceo Statale "Farnesina"Liceo Statale Farnesina was fined EUR 4,000 by the Garante for unlawfully publishing lists of student names on its institutional website without a legal basis. The conduct breached data protection rules.ITGaranteGDPR€4,000
06 Sept 2024GESTIÓN DE VENTAS IBERIA S.L.GESTIÓN DE VENTAS IBERIA S.L. was fined 4,000 EUR by the AEPD for failing to provide access as required under Article 58.1 of the GDPR. The case concerns non-compliance with a supervisory authority request.ESAEPDGDPR€4,000
15 May 2013You & Me di Borille FabrizoYou & Me di Borille Fabrizo was fined EUR 4,000 by the Italian Garante. The sanction concerned the failure to respond to requests for information about surveillance cameras, which breached data protection rules.ITGaranteGDPR€4,000
04 Nov 2025SOCIETE EXERCANT UNE ACTIVITE DE CONSEIL ET AIDE A LA GESTION AUPRES DE CLUBS DE SPORTS SUBAQUATIQUES (procédure simplifiée)CNIL imposed an administrative fine of 4,000 EUR on SOCIETE EXERCANT UNE ACTIVITE DE CONSEIL ET AIDE A LA GESTION AUPRES DE CLUBS DE SPORTS SUBAQUATIQUES under a simplified procedure. The decision concerns a regulatory breach handled in administrative proceedings.FRCNILGDPR€4,000
20 Mar 2008MO.MA. s.r.l.MO.MA. s.r.l. was fined by the Garante for failing to comply with a request to confirm the conformity of personal data processing. The authority found a breach of Article 164 of the Italian Data Protection Code.ITGaranteGDPR€4,000
02 Feb 2019XX S.r.l.The company was fined EUR 4,000 by the Garante. The authority found that it processed personal data for promotional purposes without obtaining valid consent from the data subjects.ITGaranteGDPR€4,000
06 Feb 2020Liceo Artistico Statale di NapoliLiceo Artistico Statale di Napoli was fined EUR 4,000 by the Garante for publishing an outdated teacher ranking on its institutional website. The authority found this breached GDPR principles of lawfulness, fairness, transparency, and data minimization.ITGaranteGDPR€4,000
06 Jul 2016Sorec s.r.l.Sorec s.r.l. was fined EUR 4,000 by the Garante for inadequate password security in its data processing systems. The case concerned non-compliance with data protection requirements.ITGaranteGDPR€4,000
06 Feb 2014Genesis Consulting s.r.l.Genesis Consulting s.r.l. was fined EUR 4,000 by the Garante. The authority found that personal data collected through a website form were used for marketing purposes without adequate notice and without specific consent.ITGaranteGDPR€4,000