Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.4%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
04 Nov 2010Casa di Cura Tortorella S.p.aCasa di Cura Tortorella S.p.a was fined by the Garante for failing to notify certain data processing activities and for providing inadequate information to data subjects. The case concerns breaches of the Italian Data Protection Code and points to deficiencies in basic notification and transparency obligations.ITGaranteGDPR€20,000
Lensa.roLensa.ro, operated by Tensa Art Design, was fined EUR 20,000 by Romania’s data protection authority, ANSPDCP. The case involved cookie-based tracking and behavioral advertising without clear user consent, as well as failure to respond to the authority’s official information requests.ROAutoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter PersonalGDPR€20,000
29 Oct 2020Gaypa s.r.l.Gaypa s.r.l. was fined EUR 20,000 by the Garante for continuing to use a personalized email account of a former employee after the employment ended. The authority found this conduct inconsistent with GDPR principles of lawfulness and purpose limitation.ITGaranteGDPR€20,000
07 Dec 2023N*** Gastronomie GmbHN*** Gastronomie GmbH was fined by the DSB EUR 20,000 for unlawfully processing personal data through video surveillance without a legal basis. The authority also found that the company failed to maintain a record of processing activities required under the GDPR.ATDSBGDPR€20,000
11 Sept 2025THE OBJECTIVE MEDIA, S.L.THE OBJECTIVE MEDIA, S.L. published an individual's personal data on its website without consent. The AEPD found this to be a breach of data protection principles and imposed a 20,000 EUR fine.ESAEPDGDPR€20,000
13 Sept 2024COMMUNE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 20,000 on COMMUNE (procédure simplifiée) and issued an injunction. The decision concerns a confirmed breach of rules supervised by the CNIL.FRCNILGDPR€20,000
10 Jun 2021aiComply S.r.l.aiComply S.r.l. was fined by the Garante in the amount of EUR 20,000 for failing to implement adequate security measures. In particular, it did not use a secure network protocol, which created a risk to the confidentiality and integrity of personal data.ITGaranteGDPR€20,000
05 Oct 2017Regione autonoma Valle d'AostaRegione autonoma Valle d'Aosta was fined by the Garante for publishing a regional council resolution on its website that contained personal evaluations and information about an employee. The authority found this to be a breach of data protection rules.ITGaranteGDPR€20,000
14 Mar 2023Dane anonimowe (Prokuraturę Rejonową w G. z siedzibą w G. przy ul.)UODO imposed an administrative fine of PLN 20,000 on the District Prosecutor's Office in G. The authority found that the entity failed to notify the supervisory authority of a personal data breach without undue delay and did not inform the affected individuals without undue delay.PLUODOGDPR€4,266
22 Jun 2017Adsalsa Italia Publicidad SucursalAdsalsa Italia Publicidad Sucursal was fined EUR 20,000 by the Garante. The authority found that personal data were processed without obtaining separate consent for each purpose, in breach of data protection rules.ITGaranteGDPR€20,000
14 Dec 2017SEMS – Servizi per la mobilità sostenibile S.r.l.SEMS – Servizi per la mobilità sostenibile S.r.l. was fined EUR 20,000 by the Garante. The authority found that the company failed to meet notification obligations linked to the installation of satellite tracking devices in its vehicle fleet, in breach of data protection rules.ITGaranteGDPR€20,000
20 Nov 2024Raiffeisen Bank S.A.Raiffeisen Bank S.A. was fined EUR 20,000 by ANSPDCP for violations of GDPR provisions. The case concerns non-compliance with personal data protection requirements.ROANSPDCPGDPR€20,000
21 Jan 2010Casa di cura privata Di Lorenzo s.p.a.The private clinic Casa di cura privata Di Lorenzo s.p.a. was fined by the Garante for breaching data protection rules. The authority found that it failed to comply with notification obligations under the Italian Privacy Code.ITGaranteGDPR€20,000
01 Oct 2020Università Campus Bio-medico di RomaThe Garante fined Università Campus Bio-medico di Roma 20,000 EUR for a data protection breach. Online medical reports were accessible to other patients, resulting in unauthorized disclosure of sensitive information.ITGaranteGDPR€20,000
13 May 2015ASL Napoli 2 NordASL Napoli 2 Nord was fined 20,000 EUR by the Garante for publishing personal data on its website. The disclosed information could reveal individuals' health status, which breached privacy rules.ITGaranteGDPR€20,000
16 Feb 2017Crabion s.r.l.Crabion s.r.l. was fined by the Garante in the amount of EUR 20,000 for processing genetic data without the required authorization. The case concerns breaches of the rules governing the lawful processing of sensitive personal data.ITGaranteGDPR€20,000
28 Apr 2022Istituto Nazionale Assicurazione Infortuni sul LavoroIstituto Nazionale Assicurazione Infortuni sul Lavoro was fined by the Garante EUR 20,000. The authority found that inadequate technical and organizational measures led to a data breach.ITGaranteGDPR€20,000
01 Feb 2018Transpe S.p.A.Transpe S.p.A. was fined by the Garante in the amount of 20,000 EUR for failing to notify the installation of a geolocation system on its vehicles. The authority treated this as a breach of data protection notification obligations.ITGaranteGDPR€20,000
19 Sept 2024ARMURERIE VENDANT SES ARTICLES EN LIGNE ET EN MAGASIN (procédure simplifiée)The CNIL imposed an administrative fine of EUR 20,000 on ARMURERIE VENDANT SES ARTICLES EN LIGNE ET EN MAGASIN. The case was handled under a simplified procedure.FRCNILGDPR€20,000
24 Nov 2015VACACIONES EDREAMS SOCIEDAD LIMITADA UNIPERSONALVACACIONES EDREAMS SOCIEDAD LIMITADA UNIPERSONAL was fined by the AEPD EUR 20,000 for sending unsolicited commercial communications by email. The conduct breached Article 21.1 of the LSSI and constituted unlawful marketing communication.ESAEPDePrivacy€20,000