Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
26 Nov 2024NetflixThe Autoriteit Persoonsgegevens fined Netflix 4.75 million euros for privacy and GDPR transparency failures. The 26 November 2024 decision concerned inadequate explanations in Netflix’s privacy notice and insufficiently clear responses to data access requests.NLAutoriteit PersoonsgegevensGDPR€4,750,000
25 Mar 2021Fastweb S.p.A.Fastweb S.p.A. was sanctioned by the Garante for making unauthorized promotional calls and sending messages without proper consent. The authority also found insufficient measures to ensure data processing security and GDPR compliance.ITGaranteGDPR€4,501,000
05 Feb 2025FacharztThis case concerns a confirmed fine by the Austrian Federal Administrative Court (BVwG) against Facharzt for disclosing health data in an online review. The conduct indicates a breach of personal data protection rules involving medical information.ATBundesverwaltungsgericht (BVwG)GDPR€4,500,000
27 Oct 2023Telemach HrvatskaAZOP imposed a EUR 4.5 million fine on Telemach Hrvatska for GDPR violations. The authority found that the company transferred personal data to Serbia without valid transfer safeguards, failed to properly inform data subjects, and overprocessed copies of employee ID documents.HRAZOPGDPR€4,500,000
23 Jul 2025ING Bank Śląski SAThe Polish supervisory authority imposed an administrative fine on ING Bank Śląski SA for scanning the identity documents of customers and prospective customers without properly assessing whether this was necessary under AML rules. The decision became final on 23 July 2025 and concerns breaches of Articles 5(1)(a), (b) and (c) and 6(1) of the GDPR.PLPresident of the Personal Data Protection OfficeGDPR€4,375,000
20 Aug 2024Dane anonimowe (X. S.A.)The UODO imposed an administrative fine of PLN 4,053,173 on X. S.A. for breaching Article 34(1) and (2) of the GDPR. The case concerned failure to meet the obligations to notify affected individuals about a personal data breach.PLUODOGDPR€950,000
04 Nov 2025McDonald'sThe Polish Data Protection Authority imposed a EUR 4,022,773 fine on McDonald's for insufficient security measures in personal data processing. A separate EUR 43,680 fine was also issued to the service provider involved in the same incident.PLPolish Data Protection AuthorityGDPR€4,022,000
23 Aug 2021VODAFONE ESPAÑA, S.A.U.Vodafone España was fined by the AEPD for breaching data protection principles. The case involved issuing SIM card duplicates to unauthorized individuals, which compromised data integrity and confidentiality.ESAEPDGDPR€4,000,000
02 May 2023KópavogsbærKópavogsbær was fined 4,000,000 ISK by Persónuvernd for using the Seesaw student system in schools without meeting GDPR requirements. The case concerned the processing of children's personal data, which requires a lawful basis and appropriate safeguards.ISPersónuverndGDPR€26,720
02 Dec 2020Karolinska UniversitetssjukhusetKarolinska Universitetssjukhuset was fined by IMY for failing to conduct a needs and risk analysis before granting access rights in its TakeCare journal system. The authority found this breached GDPR requirements on data security and accountability.SEIMYGDPR€389,000
01 Jan 2024XFERA MÓVILES, S.A.U.XFERA MÓVILES, S.A.U. was fined by the AEPD for failing to ensure the security and confidentiality of personal data. The incident resulted in a data breach and created a risk of identity theft.ESAEPDGDPR€4,000,000
01 Oct 2023TrustpilotThe Italian Competition Authority (AGCM) fined Trustpilot EUR 4,000,000. The authority found that the company misled consumers about the authenticity of reviews and how they were moderated.ITItalian Competition Authority (AGCM)Omnibus€4,000,000
23 Nov 2020Utbildningsnämnden i Stockholms stad, SkolplattformenThe Education Committee of Stockholm City was fined by IMY 4,000,000 SEK for processing personal data in breach of GDPR Articles 5 and 32. The authority cited inadequate security measures and failure to conduct impact assessments for systems handling sensitive student data.SEIMYGDPR€391,000
17 Jan 2024Dane anonimowe (V. sp. z o. o. z siedzibą w S. za naruszenie art. 5 ust. 1 lit. f), art. 5 ust. 2, art. 25 ust. 1 oraz art. 32 ust. 1 lit. b) i lit. d) i ust. 2 rozporządzenia 2016/679)UODO imposed a fine of PLN 3,819,960 on V. sp. z o.o. for breaches of GDPR rules on data security and confidentiality. The case concerned, among other things, data processing principles, data protection by design, and the implementation of appropriate technical and organizational measures.PLUODOGDPR€868,000
12 Apr 2022Minister van FinanciënThe Dutch Data Protection Authority imposed a fine on the Minister of Finance for improper processing of personal data in the Fraud Signaling Facility (FSV) application by the Tax and Customs Administration. The authority found breaches of lawfulness, purpose limitation, accuracy, and storage limitation principles.NLAPGDPR€3,700,000
02 Dec 2020Sahlgrenska Universitets­sjukhusetSahlgrenska University Hospital was fined SEK 3.5 million for failing to perform the required needs and risk analysis before granting access rights in its medical record systems. The authority found this breached GDPR requirements on data security and accountability.SEIMYGDPR€340,000
30 Dec 2025SOCIETE DU SECTEUR TERTIAIREThe CNIL imposed an administrative fine of EUR 3,500,000 on SOCIETE DU SECTEUR TERTIAIRE. The case concerns a breach of personal data protection rules.FRCNILGDPR€3,500,000
27 Jun 2023A.I.C. ehf.A.I.C. ehf. was fined by Persónuvernd 3,500,000 ISK for registering loan defaults with Creditinfo Lánstraust hf. without meeting the required registration conditions. The case also involved defaults on loans below the minimum threshold for registration.ISPersónuverndGDPR€23,520
17 Oct 2023Íþrótta- og sýningahöllin hf.Íþrótta- og sýningahöllin hf. was fined by Persónuvernd 3,500,000 ISK for unlawful electronic surveillance at Laugardalshöll. The case involved processing sensitive personal data without proper authorization, including data relating to children.ISPersónuverndGDPR€23,905
24 Feb 2025UNICAJA BANCO, S.A.U.UNICAJA BANCO, S.A.U. was fined by the AEPD EUR 3,500,000 for inadequate security measures in its video surveillance system. The authority found a breach of data protection requirements.ESAEPDGDPR€3,500,000