Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.4%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
23 Feb 2017Sisal S.p.A.Sisal S.p.A. was fined by the Garante in the amount of EUR 20,000 for installing a geolocation system on smartphones provided to employees without proper compliance with data protection rules. The case concerned the processing of location data in an employment context and insufficient legal safeguards.ITGaranteGDPR€20,000
01 Apr 2025Anonymised (IDPC 0476_001)The IDPC imposed a EUR 20,000 fine on Anonymised (IDPC 0476_001) for breaches of several GDPR provisions. The case concerned lawfulness, fairness and transparency, purpose limitation, information duties, the right to rectification, and the appointment of a data protection officer.MTIDPCGDPR€20,000
06 Oct 2023SOCIETE DE CONSEILS EN SYSTEMES ET LOGICIELS INFORMATIQUES (procédure simplifiée)CNIL imposed a fine of EUR 20,000 on SOCIETE DE CONSEILS EN SYSTEMES ET LOGICIELS INFORMATIQUES under a simplified procedure. The decision concerns a breach of personal data protection rules.FRCNILGDPR€20,000
21 Mar 2018Azienda Sanitaria Locale Napoli 2 NordAzienda Sanitaria Locale Napoli 2 Nord was fined by the Garante for allowing personal data of registered users to be accessed and modified by anyone through its institutional website. The case concerned inadequate protection of personal data and non-compliance with data protection rules.ITGaranteGDPR€20,000
01 Jan 2020RADIOTELEVISIÓN DEL PRINCIPADO DE ASTURIASRADIOTELEVISIÓN DEL PRINCIPADO DE ASTURIAS was fined by the AEPD 20,000 EUR for retaining and processing images without a proper legal basis. The authority found a breach of data protection principles.ESAEPDGDPR€20,000
09 Mar 2016PIXMANIA S.A.S.PIXMANIA S.A.S. was fined by the AEPD in the amount of €20,000 for sending unsolicited commercial emails to a user. The company continued sending messages despite multiple unsubscribe requests, which breached the LSSI.ESAEPDePrivacy€20,000
30 Oct 2015VACACIONES EDREAMS SOCIEDAD LIMITADA UNIPERSONALVACACIONES EDREAMS SOCIEDAD LIMITADA UNIPERSONAL was fined by the AEPD 20,000 EUR for sending unsolicited commercial emails. The messages continued despite multiple requests from the recipient to unsubscribe.ESAEPDePrivacy€20,000
09 Jan 2025National Bank of GreeceNational Bank of Greece was fined €20,000 by the HDPA. The authority found that the bank failed to provide data subjects with timely access to their personal data, breaching GDPR Articles 15 and 12.GRHDPAGDPR€20,000
13 Feb 2025D.e.c. soc. coop.The Garante imposed a EUR 20,000 fine on D.e.c. soc. coop. for failing to deactivate an ex-employee's email account after the employment ended. The authority found this conduct breached GDPR principles of fair and transparent processing of personal data.ITGaranteGDPR€20,000
21 Apr 2016Estracom s.p.a.Estracom s.p.a. was fined EUR 20,000 by the Garante for retaining customers’ call data for more than thirty days. The authority found this to be a breach of data protection rules.ITGaranteGDPR€20,000
15 Mar 2018S.P. Selezione Personale s.r.l.S.P. Selezione Personale s.r.l. was fined by the Garante in the amount of EUR 20,000 for violations related to the processing of personal data in head hunting and recruitment activities. The case concerned irregularities in the handling of candidate data.ITGaranteGDPR€20,000
19 Jan 2024GEO ALTERNATIVA, S.L.GEO ALTERNATIVA, S.L. was fined by the AEPD for unlawfully processing personal data. The company included a customer's information in a credit file even though an agreement had already been reached regarding the disputed gas bill.ESAEPDGDPR€20,000
03 Nov 2015VACACIONES EDREAMS SOCIEDAD LIMITADA UNIPERSONALVACACIONES EDREAMS was fined EUR 20,000 by the AEPD for continuing to send newsletters to the complainant despite multiple unsubscribe requests. The authority found this conduct breached Article 21.1 of the LSSI.ESAEPDePrivacy€20,000
03 Sept 2025SOCIETE AYANT POUR ACTIVITE LA PROMOTION IMMOBILIERE DE LOGEMENTS (procédure simplifiée)CNIL imposed an administrative fine of 20,000 EUR on SOCIETE AYANT POUR ACTIVITE LA PROMOTION IMMOBILIERE DE LOGEMENTS. The case was handled under a simplified procedure.FRCNILGDPR€20,000
30 Aug 2024Dane anonimowe (Panią A. K., prowadzącą działalność gospodarczą pod firmą B. w M. przy ul.)The President of the Personal Data Protection Office imposed an administrative fine on an individual conducting business activity. The sanction resulted from failure to cooperate with the authority and from not providing access to personal data and information necessary for its tasks.PLUODOGDPR€4,594
23 Jun 2025Dane anonimowe (Pana A. Z., prowadzącego działalność gospodarczą pod firmą „W.” z siedzibą w T. przy ul.)The President of UODO imposed an administrative fine of PLN 18,941 on an entrepreneur operating under the name “W.”. The sanction concerned failure to provide information and failure to grant access to personal data and other information necessary for the authority to perform its duties.PLUODOGDPR€4,430
21 Dec 2023Dane anonimowe (K. sp. z o.o. sp. k. z siedzibą w W. przy ul.)The President of UODO imposed a fine of PLN 18,864 on the company for failing to cooperate in the performance of the authority’s duties. The company also did not provide access to personal data and information necessary for the regulator’s tasks.PLUODOGDPR€4,346
02 Jun 2023Dane anonimowe (T. sp. z o.o. z siedzibą w K. przy ul.)The President of UODO imposed a fine of PLN 18,864 on T. sp. z o.o. The company failed to cooperate with the authority in the performance of its duties and did not provide access to information necessary for those duties.PLUODOGDPR€4,194
27 Oct 2021Anonymisé (CNPD decision-41-fr-2021)The CNPD imposed a fine of 18,700 EUR on Anonymisé for improper implementation of Data Protection Officer obligations. The company did not publish the DPO’s contact details, did not involve the DPO in all data protection matters, did not ensure the DPO’s autonomy, and did not assign monitoring of GDPR compliance.LUCNPDGDPR€18,700
07 Feb 2013Società delle terme s.p.a.Società delle terme s.p.a. was fined by the Garante 18,400 EUR for providing inadequate information when collecting personal data and for obtaining invalid consent. The authority found violations of Articles 13 and 23 of the Italian Data Protection Code.ITGaranteGDPR€18,400