Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.2%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
05 Nov 2025COFIDIS S.A., SUCURSAL EN ESPAÑACOFIDIS S.A., Sucursal en España was fined €5,000 by the AEPD for mixing a complainant’s personal data with unrelated information and sending a third party’s debt statement. The case concerns a breach of the data accuracy principle.ESAEPDGDPR€5,000
01 Jan 2015MAKRO AUTOSERVICIO MAYORISTA, S.A.U.MAKRO AUTOSERVICIO MAYORISTA, S.A.U. was fined by the AEPD €5,000 for sending unsolicited commercial SMS messages. The authority found that no simple opt-out mechanism was provided, in breach of article 21.2 of the LSSI.ESAEPDePrivacy€5,000
07 Apr 2022Comune di OrteComune di Orte was fined for improper handling of personal data collected through video surveillance. The authority found a lack of transparency and insufficient data protection measures.ITGaranteGDPR€5,000
26 Feb 2026Conservatorio “XX” di XXThe Garante fined Conservatorio “XX” di XX EUR 5,000 for processing personal data relating to criminal convictions without a valid legal basis. The authority found breaches of the GDPR and the national privacy code.ITGaranteGDPR€5,000
16 Sept 2021La Prima S.r.l.La Prima S.r.l. was fined by the Garante for carrying out promotional activities without a valid legal basis. The authority found that this conduct breached GDPR requirements.ITGaranteGDPR€5,000
23 Feb 2021SFAM ESPAÑA GENERAL S.L.SFAM ESPAÑA GENERAL S.L. was fined by the AEPD in the amount of 5,000 EUR. The case concerned unauthorized charges to a customer's bank account after a purchase, raised in a complaint about data misuse.ESAEPDGDPR€5,000
12 Dec 2024Azienda Sanitaria dell’Alto AdigeThe Garante imposed a fine on Azienda Sanitaria dell’Alto Adige for breaches of data protection rules. The case involved inadequate data handling and insufficient security measures.ITGaranteGDPR€5,000
20 Oct 2022Fondazione Teatro Regio di TorinoFondazione Teatro Regio di Torino was fined EUR 5,000 by the Garante for publishing an individual's personal data on its website. The authority found a breach of the GDPR principles of lawful, fair, and transparent processing.ITGaranteGDPR€5,000
01 Jan 2016KREDITECH SPAIN, S.L.KREDITECH SPAIN, S.L. was fined by the AEPD 5,000 EUR for continuing to send commercial emails to a complainant after the complainant exercised the right to data deletion. The authority found this conduct breached the LSSI.ESAEPDePrivacy€5,000
21 Dec 2023Gestioni Aziendali s.r.l.Gestioni Aziendali s.r.l. was fined by the Garante in the amount of 5,000 EUR for operating a video surveillance system at Hotel della Vittoria without appropriate informational signage. The authority found this to be a breach of GDPR transparency requirements toward monitored individuals.ITGaranteGDPR€5,000
22 May 2012Municipal Water and Sewerage Company of RhodesThe Municipal Water and Sewerage Company of Rhodes was fined 5,000 EUR by the HDPA. The authority found that the company failed to satisfy the complainant’s data access rights and did not respond within the mandatory 15-day period.GRHDPAGDPR€5,000
12 Sept 2024Ordine delle Professioni Infermieristiche di GoriziaThe Garante imposed a fine of EUR 5,000 on the Ordine delle Professioni Infermieristiche di Gorizia for breaches of data protection rules. The case concerned non-compliance with requirements governing the processing of personal data.ITGaranteGDPR€5,000
23 May 2018BELEADER INTERNET MARKETING S.L.BELEADER INTERNET MARKETING S.L. was fined 5,000 EUR by the AEPD. The authority found that the company sent unsolicited emails and did not honor unsubscribe requests.ESAEPDePrivacy€5,000
09 Jul 2025EDICIONES CATÓLICOS Y VIDA PÚBLICA, S.L.U.The entity was fined for using non-essential cookies without obtaining prior user consent. This conduct breached the LSSI requirements on obtaining consent before activating such tracking tools.ESAEPDePrivacy€5,000
15 Sept 2015Revírní bratrská pokladna, zdravotní pojišťovnaRevírní bratrská pokladna, zdravotní pojišťovna was fined by the UOOU 5,000 CZK for processing inaccurate personal data of an insured person without their knowledge. The case concerns a breach of data protection duties and the requirement to process data accurately.CZUOOUGDPR€185
28 Jul 2020Geanonimiseerd (APD 39/2020)The case concerns a complaint about the processing of voters’ personal data during municipal elections. The controller used old electoral lists without a lawful basis, breaching the GDPR principles of purpose limitation and lawfulness.BEAPDGDPR€5,000
07 Aug 2021SPORTIUM APUESTAS DIGITAL S.A.U.SPORTIUM APUESTAS DIGITAL S.A.U. was fined by the AEPD 5,000 EUR for sending marketing emails after a data deletion request and for having non-compliant cookie policies on its website. The case indicates failures in data protection and user consent controls.ESAEPDePrivacy€5,000
08 Jun 2023Mirva s.r.l.Mirva s.r.l. was fined by the Garante 5,000 EUR for installing a video surveillance system without proper informational signage. The system also captured areas not pertaining to the company, which breached data protection rules.ITGaranteGDPR€5,000
26 Sept 2023COLEGIO ALONAI, S.L.COLEGIO ALONAI, S.L. was fined by the AEPD 5,000 EUR for installing surveillance cameras inside classrooms and outside the school without properly informing employees. The authority also found inadequate signage, constituting a breach of data protection rules.ESAEPDGDPR€5,000
29 Jan 2026dott. Paolo MontemurroDott. Paolo Montemurro was fined 5,000 EUR by the Garante for posting photographs of a patient's surgical procedure on Instagram without consent. The authority found this breached GDPR principles of lawfulness, fairness, and transparency.ITGaranteGDPR€5,000