Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.2%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
08 Feb 2023Medijobs Platform SRLMedijobs Platform SRL was fined EUR 5,000 by ANSPDCP after unauthorized access to its IT infrastructure. The incident led to the downloading and deletion of certain personal data.ROANSPDCPGDPR€5,000
11 Feb 2021Istituto Superiore Statale "Pitagora"Istituto Superiore Statale "Pitagora" was fined by the Garante 5,000 EUR for unlawful processing of personal data. The authority found failures to ensure data minimization and transparency toward data subjects.ITGaranteGDPR€5,000
05 Mar 2024ROCA & ASOCIADOS ABOGADOS Y ECONOMISTAS, S.L.P.ROCA & ASOCIADOS ABOGADOS Y ECONOMISTAS, S.L.P. was fined 5,000 EUR by the AEPD. The authority found that the company published employees’ personal data on its website without consent, breaching Article 6(1) of the GDPR.ESAEPDGDPR€5,000
03 Mar 2022AUTOMOVILES FERSAN, S.A.AUTOMOVILES FERSAN, S.A. used personal data without consent to include it in a vehicle purchase contract. The AEPD imposed a fine of EUR 5,000 for breaching data protection rules.ESAEPDGDPR€5,000
14 Jun 2024GESCONSULT, S.A. S.G.I.I.C.GESCONSULT, S.A. S.G.I.I.C. was fined by the AEPD 5,000 EUR for processing personal data without a legal basis. The case involved recording a meeting and sharing the recording without proper consent.ESAEPDGDPR€5,000
29 Dec 2025SOCIETE EXERCANT UNE ACTIVITE D'EDITION DE JOURNAUX (procédure simplifiée)The CNIL imposed an administrative fine of 5,000 EUR on SOCIETE EXERCANT UNE ACTIVITE D'EDITION DE JOURNAUX. The case was handled under a simplified procedure.FRCNILGDPR€5,000
23 Jul 2025Agricola International SAAgricola International SA was fined EUR 5,000 by ANSPDCP for a data security breach. The incident was reported by the company itself, indicating an internally detected event that required compliance review.ROANSPDCPGDPR€5,000
21 Jul 2022Comune di GinosaComune di Ginosa was fined EUR 5,000 by the Garante for violations related to the processing of personal data in the whistleblowing context. The authority found that an adequately high level of confidentiality and protection for the data subjects was not ensured.ITGaranteGDPR€5,000
16 Mar 2017ABELHAS.PT LIMITEDABELHAS.PT LIMITED was fined EUR 5,000 by the AEPD for failing to provide the required information and procedures to reject data processing on its website. The authority found a breach of Article 22.2 of the LSSI.ESAEPDePrivacy€5,000
14 Apr 2023ESTUDIO VILLALBA ANTIQUE, S.L.ESTUDIO VILLALBA ANTIQUE, S.L. was fined by the AEPD for processing personal data without consent. The authority found a breach of the lawfulness principle under Article 6(1) GDPR.ESAEPDGDPR€5,000
26 Mar 2026Esselunga S.p.A.Esselunga S.p.A. was fined EUR 5,000 by the Italian supervisory authority, Garante. The case concerned a failure to respond to a data access request under Article 15 GDPR, including access to employee attendance records.ITGaranteGDPR€5,000
12 Jun 2026Compania Națională Poșta RomânăCompania Națională Poșta Română was fined by ANSPDCP in the amount of EUR 5,000 for GDPR violations. The case concerned non-compliance with personal data protection requirements.ROANSPDCPGDPR€5,000
22 Apr 2022CÍTRICOS TANTA, S.L.CÍTRICOS TANTA, S.L. was fined by the AEPD for processing personal data without consent. The case involved registering an individual in the Social Security system without their knowledge or agreement.ESAEPDGDPR€5,000
11 Jan 2024Comune di SiracusaThe Garante fined Comune di Siracusa €5,000 for breaches of data protection obligations under Article 37 GDPR. The case concerned failures related to the appointment and management of the data protection officer requirement.ITGaranteGDPR€5,000
09 Jul 2020YThe Litigation Chamber imposed a fine of 5,000 EUR for unlawful processing of personal data through surveillance cameras in a residential building. The responsible party failed to establish a legal basis for the processing and did not share access with co-owners.BEAPDGDPR€5,000
08 Feb 2023COMMUNE (procédure simplifiée)CNIL imposed a EUR 5,000 fine on COMMUNE under a simplified procedure and issued an injunction. The case concerned a confirmed breach requiring corrective action.FRCNILGDPR€5,000
07 Sept 2021B.B.B.The entity was fined by the AEPD 5,000 EUR for publicly disseminating surveillance footage without justification. The authority found that this conduct breached data protection principles.ESAEPDGDPR€5,000
01 Jan 2020Caja Rural San José de Nules S. Cooperativa de Crédito de la Comunidad ValencianaCaja Rural San José de Nules was fined by the AEPD 5,000 EUR for publicly displaying individuals’ personal data on a notice board. The conduct breached data protection principles by exposing their economic status.ESAEPDGDPR€5,000
06 Mar 2023B.B.B.The entity was fined by the AEPD €5,000 for publishing radio amateurs’ personal data on a Telegram channel. The breach involved linking call signs to personal information, which violated data protection rules.ESAEPDGDPR€5,000
21 Sept 2022Αρχή Ηλεκτρισμού ΚύπρουThe Cyprus DPA fined the Cyprus Electricity Authority €5,000 for a personal data breach involving unauthorized disclosure to a third party. The authority found violations of GDPR Articles 5(1)(f), 24(1), and 32.CYCyDPCGDPR€5,000