Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.4%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
02 Nov 2022QUALITY-PROVIDER S.A.QUALITY-PROVIDER S.A. was fined EUR 20,000 by the AEPD for processing personal data without a valid legal basis and for failing to comply with data deletion requests. The violations concerned Articles 6 and 17 of the GDPR.ESAEPDGDPR€20,000
16 Nov 2017S.T.E.A.T. S.p.a.S.T.E.A.T. S.p.a. was fined by the Garante for failing to properly notify the installation of electronic monitoring and localization devices on public transport buses. The authority found a breach of data protection notification obligations.ITGaranteGDPR€20,000
29 Mar 2018Fin Solution Italia S.p.a.Fin Solution Italia S.p.a. was fined EUR 20,000 by the Garante for inadequate security measures in the processing of personal data. The authority found that weak passwords were used on company PCs, increasing the risk of unauthorized access.ITGaranteGDPR€20,000
02 Jun 2016TELEFONICA MOVILES ESPAÑA, S.A.U.Telefónica Móviles España was fined €20,000 by the AEPD for using “supercookies” without properly informing users or obtaining their consent. The authority found this conduct to be in breach of Article 22.2 of the LSSI.ESAEPDePrivacy€20,000
17 Oct 2024SOCIETE AYANT POUR ACTIVITE LA FOURNITURE DE PRESTATIONS DE SERVICE (GESTION APPELS TELEPHONIQUES) (procédure simplifiée)The CNIL imposed an administrative fine of EUR 20,000 on SOCIETE AYANT POUR ACTIVITE LA FOURNITURE DE PRESTATIONS DE SERVICE (GESTION APPELS TELEPHONIQUES). The case was handled under a simplified procedure.FRCNILGDPR€20,000
26 Oct 2017M&M Centro analisi s.r.l.M&M Centro analisi s.r.l. was fined by the Garante 20,000 EUR for failing to notify the processing of sensitive health data. The obligation arose under the Italian Data Protection Code.ITGaranteGDPR€20,000
29 Apr 2025Cooperativa Sociale QuadrifoglioThe Garante imposed a fine of EUR 20,000 on Cooperativa Sociale Quadrifoglio for violations related to data processing. The case concerned non-compliance with personal data protection requirements.ITGaranteGDPR€20,000
18 Feb 2020ZSZZS.440.768.2018StatusuchylonaTytuUODO found a breach related to the processing of children’s biometric data in connection with use of the school canteen. A fine of PLN 20,000 was imposed.PLUODOGDPR€4,679
28 Sept 2023SOCIETE DE FABRICATION DE PRODUITS DE CONSOMMATION COURANTE EN MATIERES PLASTIQUES (procédure simplifiée)The CNIL imposed a fine of EUR 20,000 on SOCIETE DE FABRICATION DE PRODUITS DE CONSOMMATION COURANTE EN MATIERES PLASTIQUES under a simplified procedure. The decision concerns a breach of the rules covered by the administrative proceeding.FRCNILGDPR€20,000
27 Mar 2023QUALITY-PROVIDER S.A.QUALITY-PROVIDER S.A. was fined EUR 20,000 by the Spanish data protection authority, AEPD. The company failed to provide requested information, obstructing the authority’s investigative powers under Article 58(1) GDPR.ESAEPDGDPR€20,000
13 May 2021Synlab Med srlSynlab Med srl was fined EUR 20,000 by the Garante. The authority found that personal data were improperly transmitted to an entity not competent to process them, breaching the principles of data minimization and integrity.ITGaranteGDPR€20,000
24 Jan 2024ACTIVITE DE COMMERCE DE GROS PHARMACEUTIQUES (procédure simplifiée)The CNIL imposed an administrative fine of EUR 20,000 on ACTIVITE DE COMMERCE DE GROS PHARMACEUTIQUES. The case was handled under a simplified procedure.FRCNILGDPR€20,000
08 Oct 2024SEAT, S.A.SEAT, S.A. was fined by the AEPD €20,000 for using cookies on its website without obtaining user consent. The authority found this conduct to be in breach of the LSSI.ESAEPDePrivacy€20,000
11 Dec 2025SOCIETE AYANT POUR ACTIVITE L'ACCOMPAGNEMENT, L'ORIENTATION ET L'EDUCATION DE VICTIMES D'INCESTES (procédure simplifiée)The CNIL imposed an administrative fine of EUR 20,000 on SOCIETE AYANT POUR ACTIVITE L'ACCOMPAGNEMENT, L'ORIENTATION ET L'EDUCATION DE VICTIMES D'INCESTES and issued an injunction. The case was handled under a simplified procedure.FRCNILGDPR€20,000
25 Jan 2024ASSOCIATION A CARACTERE POLITIQUE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 20,000 on ASSOCIATION A CARACTERE POLITIQUE. The case was handled under a simplified procedure.FRCNILGDPR€20,000
21 Apr 2021Isinc S.r.l.s.Isinc S.r.l.s. was fined 20,000 EUR by the Garante for sending promotional emails using personal data taken from public databases without proper consent. The authority found this conduct to be in breach of GDPR Article 5.ITGaranteGDPR€20,000
21 Apr 2011Azienda USL della Valle D'AostaAzienda USL della Valle D'Aosta was fined for processing personal data during phone bookings without providing the required information notice and for failing to update the security program document. The authority found these actions breached data protection rules.ITGaranteGDPR€20,000
23 Jan 2024CAJA RURAL DE NAVARRA, S.C.C.CAJA RURAL DE NAVARRA was fined EUR 20,000 by the AEPD for a personal data breach. The incident compromised the confidentiality and integrity of personal data, breaching Article 5(1)(f) of the GDPR.ESAEPDGDPR€20,000
09 May 2018Amiu S.p.a.Amiu S.p.a. was fined by the Garante 20,000 EUR for improper processing of personal data through its video surveillance systems. The authority found that the company failed to properly designate data processing personnel and to implement adequate data protection measures.ITGaranteGDPR€20,000
31 Jan 2024EDITEUR DE SITE WEB - ACTUALITES DANS LE DOMAINE DES NOUVELLES TECHNOLOGIES (procédure simplifiée)The CNIL imposed an administrative fine of EUR 20,000 on EDITEUR DE SITE WEB - ACTUALITES DANS LE DOMAINE DES NOUVELLES TECHNOLOGIES under a simplified procedure. The case concerned a breach of personal data protection rules.FRCNILGDPR€20,000