Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.4%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
04 Aug 2025Azienda Ospedaliero Universitaria CareggiAzienda Ospedaliero Universitaria Careggi was fined by the Garante EUR 20,000 for violations related to the management of electronic health records. The authority found non-compliance with data protection requirements.ITGaranteGDPR€20,000
13 May 2021ATS di Bergamo, Agenzia di Tutela della saluteATS di Bergamo was fined by the Garante 20,000 EUR for violations involving the improper handling of sensitive health data. The case concerned the use of email to transmit data, which did not provide an adequate level of protection.ITGaranteGDPR€20,000
01 Apr 2025EL LEÓN DE EL ESPAÑOL PUBLICACIONES, S.A.The AEPD fined EL LEÓN DE EL ESPAÑOL PUBLICACIONES, S.A. 20,000 EUR for publishing unnecessary personal data in a news article. A video in the article revealed the identity of a minor, which was considered disproportionate and unnecessary for the informational purpose.ESAEPDGDPR€20,000
08 Mar 2018Riacetech S.r.l.Riacetech S.r.l. was fined for failing to notify the Garante about the installation of a biometric data processing system for employees. The case concerned obligations under the Italian Data Protection Code.ITGaranteGDPR€20,000
03 Nov 2015VACACIONES EDREAMS SOCIEDAD LIMITADA UNIPERSONALVACACIONES EDREAMS was fined by the AEPD EUR 20,000 for continuing to send marketing emails to a user who had repeatedly requested to unsubscribe. The authority found this to be a breach of Article 21.1 of the LSSI.ESAEPDePrivacy€20,000
28 Jun 2018Azienda sanitaria locale di BariAzienda sanitaria locale di Bari was fined by the Garante €20,000 for sharing access credentials among employees. The authority found this to be a breach of data protection rules and access control requirements.ITGaranteGDPR€20,000
01 Jan 2016PROCTER & GAMBLE ESPAÑAProcter & Gamble España was fined 20,000 EUR by the AEPD for continuing to send marketing emails to a complainant after unsubscribe requests. The authority found this conduct breached the LSSI rules on electronic communications.ESAEPDePrivacy€20,000
18 Dec 2025SOCIETE EXERCANT UNE ACTIVITE DE COLLECTE DE DONNEES PROVENANT DE JEUX CONCOURS, DE PROSPECTION COMMERCIALE ET DE TRANSMISSION DE DONNEES A SES CLIENTS (procédure simplifiée)CNIL imposed an administrative fine of 20,000 EUR on a company engaged in collecting data from prize contests, commercial prospecting, and data transmission to clients. The case was handled under a simplified procedure.FRCNILGDPR€20,000
16 Oct 2025SOCIETE EXERCANT UNE ACTIVITE DE GESTION DE CENTRES DE SPORTS ET DE LOISIRS (procédure simplifiée)The CNIL imposed an administrative fine of EUR 20,000 on SOCIETE EXERCANT UNE ACTIVITE DE GESTION DE CENTRES DE SPORTS ET DE LOISIRS. The authority also issued an injunction to remedy the identified deficiencies.FRCNILGDPR€20,000
30 Nov 2017CAR SHARING TRENTINO Società CooperativaCAR SHARING TRENTINO Società Cooperativa was fined by the Garante 20,000 EUR. The authority found failures to comply with notification obligations related to vehicle geolocation, constituting a breach of data protection rules.ITGaranteGDPR€20,000
28 Apr 2026CROWD ENTERTAINMENT LIMITEDCROWD ENTERTAINMENT LIMITED was fined EUR 20,000 by the Romanian authority ANSPDCP. The sanction concerned violations of GDPR requirements.ROANSPDCPGDPR€20,000
16 Sept 2010Provincia di FoggiaProvincia di Foggia was fined by the Garante for making health-related personal data publicly accessible through Google and its website. The case involved improper disclosure of sensitive data, which breached data protection rules.ITGaranteGDPR€20,000
01 Jul 2022RCI BANQUE, S.A. SUCURSAL EN ESPAÑARCI Banque, S.A. Sucursal en España was fined by the AEPD for failing to properly handle a request for erasure under Article 17 GDPR. As a result, the data subject received unwanted communications about a debt they did not owe.ESAEPDGDPR€20,000
12 Dec 2024Provvedimento del 12 dicembre 2024 [10095836]A doctor was fined EUR 20,000 for breaching core data protection principles. The authority cited failures relating to lawfulness, fairness, transparency, purpose limitation, data minimization, and integrity and confidentiality.ITGaranteGDPR€20,000
25 Sept 2023OASAThe Athens Urban Transport Organization (OASA) was fined for failing to timely conduct a Data Protection Impact Assessment (DPIA) for its Automatic Fare Collection System. The authority found this to be a breach of data protection principles in connection with the system's processing activities.GRHDPAGDPR€20,000
27 Jun 2025YDAIL CONSTRUCT SRLANSPDCP completed an investigation at YDAIL CONSTRUCT SRL in June 2025 and found a violation of applicable legal provisions. As a result, the company was fined 20,000 RON.ROANSPDCPGDPR€3,936
01 Dec 2022Amazon Italia Logistica s.r.l.Amazon Italia Logistica s.r.l. was fined by the Garante for delaying its response to a data subject’s request to access professional certificates. The authority found a breach of Article 15 GDPR.ITGaranteGDPR€20,000
18 Apr 2024MOURO PRODUCCIONES, S.R.L.MOURO PRODUCCIONES, S.R.L. was fined by the AEPD 20,000 EUR for collecting copies of identity documents and personal data of minors and their guardians without proper data protection information. The authority found breaches of the data minimization and transparency principles.ESAEPDGDPR€20,000
05 Dec 2024SOCIETE SPECIALISEE DANS L'ELABORATION ET ORGANISATION DE CAMPAGNES PUBLICITAIRES (procédure simplifiée)The CNIL imposed an administrative fine of EUR 20,000 on SOCIETE SPECIALISEE DANS L'ELABORATION ET ORGANISATION DE CAMPAGNES PUBLICITAIRES under a simplified procedure. The case concerns a data protection breach identified by the authority.FRCNILGDPR€20,000
27 Jan 2022Azienda socio sanitaria territoriale Nord di MilanoAzienda socio sanitaria territoriale Nord di Milano was fined by the Garante 20,000 EUR for failing to implement adequate security measures to protect personal data. The authority found a breach of GDPR provisions on data protection and security.ITGaranteGDPR€20,000