Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
16 Dec 20211000 Luci Round a BarThe establishment 1000 Luci Round a Bar was fined EUR 1,000 by the Italian authority Garante. The sanction concerned a video surveillance system that did not meet the information requirements of Article 13 GDPR.ITGaranteGDPR€1,000
01 Jan 20151GLOBAL JPPI, S.L.1GLOBAL JPPI, S.L. was fined by the AEPD 1,400 EUR for sending unsolicited commercial emails without prior recipient consent. The conduct breached Article 21 of the LSSI on electronic marketing communications.ESAEPDePrivacy€1,400
23 May 202420 AÑOS DE MÚSICA A.I.E.The entity was fined for collecting copies of identity documents and personal data without proper data protection information. The authority found breaches of the data minimization and transparency principles.ESAEPDGDPR€5,000
27 Apr 202220 MINUTOS EDITORA, S.L.20 MINUTOS EDITORA, S.L. was fined by the AEPD 50,000 EUR for publishing audio of a victim’s court statement in a high-profile case. The authority found a breach of data protection rules.ESAEPDGDPR€50,000
09 Jan 202420 MINUTOS EDITORA, S.L.20 MINUTOS EDITORA, S.L. was fined 45,000 EUR by the AEPD for publicly exposing the image of a victim of an alleged crime. The authority found that this constituted a breach of data protection rules.ESAEPDGDPR€45,000
16 Apr 202520 MINUTOS EDITORA, S.L.20 MINUTOS EDITORA, S.L. was fined by the AEPD for the unauthorized dissemination of a video containing personal data. The authority found a breach of the data minimization principle under Article 5(1)(c) GDPR.ESAEPDGDPR€30,000
05 Jun 202523andMeThe UK ICO imposed a GBP 2,310,000 fine on 23andMe for personal data protection breaches. The case concerned inadequate safeguards and processing failures that increased the risk of unauthorized access to user data.GBICOGDPR€2,743,000
18 Nov 201524 Media s.r.l.24 Media s.r.l. was fined EUR 4,000 by the Garante. The authority found that the company required mandatory consent for purposes beyond the original data collection intent, including promotional communications and sharing data with third parties.ITGaranteGDPR€4,000
13 Feb 20142MTech di Renzo De Luca2MTech di Renzo De Luca was fined 2,400 EUR by the Garante. The authority found that the company sent unsolicited promotional emails and provided inadequate information notices on its websites.ITGaranteGDPR€2,400
11 May 20103Emultimedia comunicación en Internet S.L.3Emultimedia comunicación en Internet S.L. was fined €600 by the AEPD for sending unsolicited commercial emails without recipient consent. The conduct breached Article 21 of the LSSI on electronic marketing communications.ESAEPDePrivacy€600
05 Jul 20234T OCIO Y CAFÉ 2009, S.L.The company was fined EUR 500 by the AEPD for installing surveillance cameras without the express consent of the property owners. The authority found this to be a breach of Article 6 of the GDPR.ESAEPDGDPR€500
24 Feb 20254USPORT INSTALACIONES DEPORTIVAS, S.L.4USPORT INSTALACIONES DEPORTIVAS, S.L. was fined by the AEPD in the amount of 600 EUR for failing to provide access. The case concerned Article 58(1) of the GDPR and indicates a failure to cooperate with the supervisory authority.ESAEPDGDPR€600
24 Mar 2010A.A.A.A.A.A. was fined EUR 600 by the AEPD for sending unsolicited commercial emails without recipient consent. The company also failed to provide information on how to exercise the right of cancellation, breaching Article 21 of the LSSI.ESAEPDePrivacy€600
01 Mar 2017A.A.A.A.A.A. was fined €3,000 by the AEPD. The authority found that cookies were installed on its websites without prior information and consent, in breach of Article 22.2 of the LSSI.ESAEPDePrivacy€3,000
24 Mar 2023A.A.A.A.A.A. was fined EUR 300 by the AEPD for failing to provide adequate information about data processing in a video surveillance system. The authority found a breach of Article 13 GDPR because data subjects did not receive the required information.ESAEPDGDPR€300
31 Aug 2025A.A.A.A.A.A. was fined by the AEPD EUR 3,000 for using surveillance cameras in a tourist accommodation without a valid legal basis and without informing the individuals concerned. The authority found a breach of Article 6 of the GDPR.ESAEPDGDPR€3,000
01 Jul 2021A.A.A.The entity was fined by the AEPD 1,000 EUR for operating a video surveillance system without proper informational signage and customer information forms. The authority found this to be a breach of Article 13 of the GDPR.ESAEPDGDPR€1,000
01 Jan 2025A.A.A.A.A.A. failed to properly handle a data access request, which constitutes a breach of Article 15 GDPR. The AEPD imposed a fine of EUR 200, reduced to EUR 160 for early payment.ESAEPDGDPR€200
04 May 2010A.A.A.A.A.A. was fined by the AEPD EUR 600 for sending unsolicited commercial emails without the recipients’ consent. The conduct breached Article 21.1 of the LSSI, which governs electronic marketing communications.ESAEPDePrivacy€600
12 Jul 2021A.A.A.The entity was fined for processing personal data through a video surveillance system without appropriate security measures and without the required informational signage. The authority found a breach of Article 13 GDPR.ESAEPDGDPR€1,000