Subscribe

Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

35 entries

Filters
Clear all
ImposedCompanyCountryAuthorityTypeAmount
001Lensa.roLensa.ro, operated by Tensa Art Design, was fined EUR 20,000 by Romania’s data protection authority, ANSPDCP. The case involved cookie-based tracking and behavioral advertising without clear user consent, as well as failure to respond to the authority’s official information requests.ROAutoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter PersonalGDPR consent and cooperation violation€20,000
002Enel Energia SpAEnel Energia SpA was fined EUR 79.1 million by the Italian data protection authority, Garante. The case concerned misuse of personal data and was a major GDPR enforcement action.ITGarante per la protezione dei dati personaliMisuse of personal data€79,100,000
003DPD PolskaThe President of the Personal Data Protection Office imposed an administrative fine of more than PLN 11 million on DPD Polska for GDPR violations. The authority cited the failure to conclude data processing agreements with external carriers and inadequate organizational measures to protect data security.PLPrezes Urzędu Ochrony Danych OsobowychGDPR finezł 11,000,000
004FC BarcelonaThe AEPD imposed a fine of EUR 500,000 on FC Barcelona for a GDPR breach. The case concerned personal data processing that did not comply with legal requirements.ESAEPD€500,000
00505 Dec 2026XThe European Commission imposed a EUR 120 million fine on X for breaching transparency requirements under the Digital Services Act. The penalty covered deceptive verification design, an inadequate ad repository, and restricted access for researchers.EUEuropean CommissionDigital Services Act transparency violation€120,000,000
00624 Feb 2026Reddit, Inc.The ICO imposed a GBP 14.5 million UK GDPR fine on Reddit, Inc. for failures related to age-gating and the protection of children’s data. The matter was initially misfiled as an enforcement notice and later refiled as a monetary penalty notice.GBInformation Commissioner's OfficeChildren's data protection£14,500,000
00731 Jan 2026SC Tensa Art Design SAThe Romanian data protection authority fined SC Tensa Art Design SA, operator of the Lensa brand, EUR 20,000 under the GDPR. The sanction followed the company’s failure to respond to the authority’s investigative request concerning cookie tracking and behavioral advertising on its website.ROAutoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter PersonalGDPR investigation non-cooperation€20,000
00813 Jan 2026Free Mobile and FreeFrance’s CNIL fined Free Mobile and Free a combined EUR 42 million for GDPR breaches linked to a 2024 data breach affecting more than 24 million users. The regulator found inadequate security measures and said Free Mobile unlawfully retained former subscribers’ data.FRCommission nationale de l’informatique et des libertésData protection€42,000,000
00901 Jan 2026CloudflareAGCOM issued an ordinanza ingiunzione against Cloudflare under the Digital Services Act. The fine is 100,000 EUR and relates to a breach of DSA obligations.ITAGCOMDSA€100,000
01019 Dec 2025HelsaMiNorway’s digital accessibility regulator found 119 accessibility errors at HelsaMi, with 64 issues still unresolved after the initial remediation deadline. The operator was ordered to fix the problems by 2025-12-19 or face a daily penalty of NOK 50,000 until compliance is achieved.NOTilsynet for universell utforming av IKTAccessibility finekr 50,000
01119 Nov 2025About YouThe Hungarian Competition Authority (GVH) found that About You used misleading discount pricing and pressured consumers with countdown timers and scarcity messages. The company was ordered to pay HUF 505 million to the Hungarian central budget and to provide compensation to affected Hungarian customers.HUGazdasági VersenyhivatalMisleading pricingFt 505,000,000
01201 Nov 2025LastPass UK LtdIn November 2025, the Information Commissioner’s Office imposed a monetary penalty of about £1.2 million on LastPass UK Ltd. The sanction concerned security and governance failures that led to a breach affecting around 1.6 million UK users, despite the use of strong encryption.GBInformation Commissioner's OfficeInadequate security measures£1,200,000
01322 Oct 2025εκδοτικός οίκοςThe Greek Data Protection Authority fined a publishing house EUR 9,000 for disclosing an author's personal and special-category data in an email sent to 55 recipients. It also found failures to implement data protection by design and to notify both the authority and the data subject of the breach.GRΑρχή Προστασίας Δεδομένων Προσωπικού ΧαρακτήραGDPR data breach€9,000
01410 Oct 2025Capita plc and Capita Pension Solutions LimitedThe Information Commissioner's Office imposed a £14 million fine on Capita plc and Capita Pension Solutions Limited for UK GDPR infringements linked to a March 2023 cyber security breach. The case concerned inadequate technical and organisational measures and a delayed response to security alerts.GBInformation Commissioner's OfficeData protection breach£14,000,000
01501 Sept 2025Osnovna škola XAZOP imposed a fine of EUR 2,000 on Osnovna škola X for breaching GDPR rules on personal data processing. The case involved unlawful processing of personal data, indicating a compliance failure under data protection requirements.HRAZOPGDPR fine€2,000
01602 Jul 2025Hrvatski ured za osiguranjeAZOP imposed a 101,000 euro fine on Hrvatski ured za osiguranje (HUO) after finding that it had not implemented adequate technical and organizational measures to protect personal data. The decision followed an investigation into a major data leak affecting about 1.2 million vehicle owners in Croatia.HRAZOPPersonal data protection€101,000
01723 Jun 2025McDonald's Polska sp. z o.o.The President of the Personal Data Protection Office imposed an administrative fine of PLN 16,932,657 on McDonald's Polska sp. z o.o. and a separate fine on its processor. The decision of 2025-06-23 concerned inadequate processor verification, insufficient risk analysis, and failure to implement appropriate GDPR security measures.PLPresident of the Personal Data Protection OfficeData protection violationzł 16,932,657
01803 Jun 2025Spotify ABOn 2025-06-03, Kammarrätten ruled that Spotify AB must pay an administrative fine of 58 million SEK. The case concerned insufficient transparency and inadequate information to data subjects under the GDPR, following an investigation by Integritetsskyddsmyndigheten.SEIntegritetsskyddsmyndigheten (IMY)GDPR transparency violationkr 58,000,000
01903 Jun 2025Regione LombardiaThe Italian Data Protection Authority, Garante per la protezione dei dati personali, imposed a EUR 50,000 fine on Regione Lombardia. The case concerned unlawful retention of employees' email metadata, excessive retention of web browsing logs, and prolonged storage of helpdesk ticket data.ITGarante per la protezione dei dati personaliGDPR data retention violation€50,000
02001 Jun 2025CarrefourThe Agencia Española de Protección de Datos imposed a EUR 3.2 million fine on Carrefour. The penalty followed five security breaches between January and April 2023 that affected the personal data of thousands of customers.ESAgencia Española de Protección de DatosData security breach€3,200,000