Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.2%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
05 Apr 2024PALANCAMAR, S.L.PALANCAMAR, S.L. was fined EUR 5,000 by the AEPD for failing to inform a customer about the processing of their personal data during a vehicle purchase. The authority treated this as a breach of Article 13 GDPR.ESAEPDGDPR€5,000
04 Dec 2019VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined 5,000 EUR by the AEPD for failing to provide requested information. The case concerned a breach of obligations under data protection rules.ESAEPDGDPR€5,000
04 Feb 2020XFERA MÓVILES, S.A.XFERA MÓVILES, S.A. was fined by the Spanish data protection authority, AEPD, in the amount of 5,000 EUR. The sanction concerned obstruction of the authority’s inspection function, which breaches Article 58(1) GDPR.ESAEPDGDPR€5,000
04 Jun 2025Comune di ReccoThe Garante fined Comune di Recco EUR 5,000 for inadequate data protection measures linked to video surveillance used to monitor waste disposal. The authority found breaches of the principles of lawfulness, fairness, and transparency.ITGaranteGDPR€5,000
01 Jan 2015ENDESA ENERGÍA S.A.ENDESA ENERGÍA S.A. was fined by the AEPD EUR 5,000 for sending unsolicited commercial SMS messages to a complainant who had previously opted out of such communications. The authority found a breach of Article 21.1 of the LSSI.ESAEPDePrivacy€5,000
13 Jun 2022AMADEUS IT GROUP, S.A.AMADEUS IT GROUP, S.A. was fined by the AEPD EUR 5,000 for failing to properly handle a data subject's requests to access and delete personal data. The authority found a breach of Article 12 GDPR because the company did not provide an adequate response.ESAEPDGDPR€5,000
30 Oct 2024Untold SRLUntold SRL was fined EUR 5,000 by ANSPDCP for violations of GDPR provisions. The case concerned non-compliance with personal data protection requirements.ROANSPDCPGDPR€5,000
26 Mar 2015Lo.Ma. S.r.l.Lo.Ma. S.r.l. was fined EUR 5,000 by the Italian data protection authority, Garante. The sanction concerned the activation of SIM cards without the knowledge of the individuals concerned, which breached data protection rules.ITGaranteGDPR€5,000
29 Apr 2021Alfa Shipyard s.r.l.Alfa Shipyard s.r.l. was fined by the Garante in the amount of €5,000 for failing to respond to a data subject's request for information. The authority found this to be a breach of GDPR obligations.ITGaranteGDPR€5,000
27 Mar 2025Azienda sanitaria territoriale di MacerataAzienda sanitaria territoriale di Macerata was fined 5,000 EUR by the Garante for failing to comply with data access requests and for breaches of data protection rules. The case concerned the processing of health data and inadequate security measures.ITGaranteGDPR€5,000
24 Jul 2019НОИThe National Social Security Institute (НОИ) was fined for failing to implement adequate technical and organizational measures to prevent employees from accessing personal data without authorization. The authority found this to be a breach of GDPR Article 25.BGCPDPGDPR€2,557
06 Oct 2014MANGO-ON LINE, S.A.MANGO-ON LINE, S.A. was fined by the AEPD €5,000 for continuing to send newsletters to a complainant despite multiple unsubscribe requests. The authority found this breached Article 21 of the LSSI on unsolicited commercial communications.ESAEPDePrivacy€5,000
05 Feb 2025FARMEC SAThe National Supervisory Authority for Personal Data Processing completed an investigation in December 2024 at FARMEC SA and found a GDPR violation. As a result, the company was fined EUR 5,000.ROANSPDCPGDPR€5,000
07 Oct 2020UST GLOBAL ESPAÑA, S.A.UST Global España, S.A. was fined by the AEPD EUR 5,000 for improperly sharing employees’ personal data in a group email. The disclosed data included names, email addresses, and DNI numbers, which breached data protection principles.ESAEPDGDPR€5,000
24 Jul 2024MONUMENTAL FORMA SPORT, S.L.MONUMENTAL FORMA SPORT, S.L. was fined EUR 5,000 by the AEPD for sending unsolicited commercial SMS messages without recipient consent. The case concerned Article 21 of the LSSI, which requires prior consent for electronic marketing communications.ESAEPDePrivacy€5,000
06 Dec 2021Telekom România Communications SAANSPDCP completed an investigation into Telekom România Communications SA in November 2021. As a result, a fine of EUR 5,000 was imposed for GDPR violations.ROANSPDCPGDPR€5,000
28 Sept 2023Giuseppe AnzaloneThe Garante imposed a EUR 5,000 fine on Giuseppe Anzalone for breaches of personal data processing rules. The case concerned patient data and involved failures to comply with lawfulness, fairness, transparency, data minimization, integrity, and confidentiality principles.ITGaranteGDPR€5,000
13 May 2015HellastatHellastat was fined by the HDPA EUR 5,000 for the illegal collection and use of data. The case concerned a breach of data protection laws.GRHDPAGDPR€5,000
10 Jun 2021MARIA & DESPOINA KOUSATHANA O.E.The company was fined by the HDPA 5,000 EUR for operating a video surveillance system without proper notification and for unlawful camera use in kitchen areas. The authority also found that data subjects were not informed about the processing of their personal data.GRHDPAGDPR€5,000
25 Nov 2024XFERA CONSUMER FINANCE ESTABLECIMIENTO FINANCIERO DE CRÉDITO, S.A.The AEPD fined XFERA Consumer Finance 5,000 EUR for sending a customer unsolicited advertising SMS messages. The messages were sent after the customer had asked to stop receiving such communications, indicating a breach of marketing communication rules.ESAEPDePrivacy€5,000