Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
07 Jul 2025Partidul Alianța pentru Unirea Românilor (AUR)Partidul Alianța pentru Unirea Românilor (AUR) was fined EUR 15,000 by ANSPDCP for violations related to data security breaches. The case concerned reported data security incidents within the political party.ROANSPDCPGDPR€15,000
02 Oct 2025UNIVERSITE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 15,000 on UNIVERSITE (procédure simplifiée). The case concerns a breach of rules supervised by the CNIL.FRCNILGDPR€15,000
20 Oct 2022Policlinico Casilino di RomaPoliclinico Casilino di Roma was fined by the Garante for violations related to the handling of personal data in the healthcare sector. The case concerned improper processing of patient data and privacy compliance requirements.ITGaranteGDPR€15,000
10 Jul 2025Outly di Veneziani & Co s.r.l.The Garante fined Outly di Veneziani & Co s.r.l. EUR 15,000 for insufficient transparency when obtaining consent and for inadequate information on data retention periods. The issues affected all interested parties and potential customers.ITGaranteGDPR€15,000
08 Dec 2025Dane anonimowe (S.)The UODO imposed an administrative fine of PLN 14,816 on Anonymous data (S.). The penalty was issued for failing to provide access to all personal data and information necessary for the President of the UODO to perform his duties.PLUODOGDPR€3,502
13 Sept 2017Jump 3000 s.r.l.Jump 3000 s.r.l. was fined by the Garante 14,800 EUR for providing clients with inadequate data protection information. The authority found that the privacy notices did not properly identify the data controller.ITGaranteGDPR€14,800
25 Feb 2016Associazione sportivo dilettantistica Feriolo Sporting ClubFeriolo Sporting Club was fined by the Garante 14,400 EUR for failing to provide adequate simplified information about its video surveillance system. The authority also found that recorded images were retained longer than permitted.ITGaranteGDPR€14,400
12 Oct 2017Hu GuangyuHu Guangyu was fined EUR 14,400 by the Garante. The authority found inadequate simplified information on video surveillance and retention of recorded images beyond the permitted period.ITGaranteGDPR€14,400
20 Mar 2014SIGE S.p.a.SIGE S.p.a. was fined by the Italian data protection authority, Garante, in the amount of €14,400. The case concerned a video surveillance system that retained images longer than permitted under the Garante's guidelines.ITGaranteGDPR€14,400
09 Mar 2017Moto One s.r.l.Moto One s.r.l. was fined by the Garante in the amount of 14,400 EUR for violations related to its video surveillance system. The authority found that recorded images were retained longer than permitted and that required informational signage was missing.ITGaranteGDPR€14,400
11 Jul 2013Cowboys' Guest Ranch S.r.l.Cowboys' Guest Ranch S.r.l. was fined EUR 14,400 by the Garante for failing to provide the required privacy notice when collecting personal data through online forms, paper questionnaires, and dance competition registration forms. The breach concerned the obligation to inform data subjects about the processing of their personal data.ITGaranteGDPR€14,400
20 Nov 2024Anonymisé (CNPD decision-03-fr-2024)The company was fined for installing surveillance cameras without a legal basis. The authority found breaches of GDPR principles of lawfulness, transparency, and security.LUCNPDGDPR€14,288
31 May 2023Dane anonimowe (G. Sp. z o.o. z siedzibą w K. przy ul.)The President of UODO imposed an administrative fine of PLN 14,148 on G. Sp. z o.o. The sanction was issued for failing to cooperate with the authority in the performance of its duties and for not providing access to information necessary for those duties.PLUODOGDPR€3,119
16 Nov 2023Dane anonimowe (W. sp. j. z siedzibą we W. przy ul.)The President of the Personal Data Protection Office imposed an administrative fine of PLN 14,148 on the company. The sanction was issued because the company failed to provide access to personal data and information necessary for the authority’s tasks.PLUODOGDPR€3,235
20 Dec 2012Regione Emilia RomagnaRegione Emilia Romagna was fined EUR 14,000 by the Garante for unlawfully disseminating personal data through the Regional Student Registry without a legal basis. The authority also found unauthorized retention of sensitive student data.ITGaranteGDPR€14,000
09 Oct 2014Comune di UdineThe Municipality of Udine was fined 14,000 EUR by the Garante. The authority found that the Security Policy Document (DPS) had not been updated from 2005 to 2011, which breached data protection rules.ITGaranteGDPR€14,000
10 Apr 2023COLEGIO OFICIAL DE ARQUITECTOS DE GRANADACOLEGIO OFICIAL DE ARQUITECTOS DE GRANADA was fined €14,000 by the AEPD for data protection breaches. The authority found a conflict of interest in the appointment of the Data Protection Officer, missing required information on data processing in complaint forms, and the use of third-party cookies without user consent.ESAEPDePrivacy€14,000
13 Jan 2022Azienda sanitaria unica regionale MarcheAzienda sanitaria unica regionale Marche was fined EUR 14,000 by the Garante for inadequate data protection measures. The breach involved health data and was linked to QR code generation; improved security measures were later implemented.ITGaranteGDPR€14,000
06 Sept 2019Anonymised (CyDPC ΑΝΟΝΥΜΟΠΟΙΗΜΕΝΗ ΑΠΟΦΑΣΗ δημοσί)A medical practice was fined EUR 14,000 for posting a patient's pre- and post-surgery images on Instagram without consent. The authority found a breach of GDPR rules on personal data processing and the protection of special-category data.CYCyDPCGDPR€14,000
30 Jun 2021Dane anonimowe (Fundację)UODO imposed a PLN 13,644 administrative fine on the Foundation for failing to report a personal data breach without undue delay. The Foundation also did not notify the affected individuals about the incident, breaching controller obligations.PLUODOGDPR€3,018