Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
12 Jan 2024Grocery Delivery E-Services UK Ltd t/a HelloFreshThe ICO fined Grocery Delivery E-Services UK Ltd t/a HelloFresh 140,000 GBP for sending 79 million spam emails and 1 million spam texts over seven months. The marketing consent was inadequate because it did not mention text messages and was bundled with an age confirmation statement that may have unfairly encouraged agreement. Customers were also not clearly told that their data would continue to be used for marketing for up to 24 months after cancelling subscriptions.GBICOGDPR€162,000
01 Nov 2025LastPass UK LtdIn November 2025, the Information Commissioner’s Office imposed a monetary penalty of about £1.2 million on LastPass UK Ltd. The sanction concerned security and governance failures that led to a breach affecting around 1.6 million UK users, despite the use of strong encryption.GBInformation Commissioner's OfficeGDPR€1,361,000
24 Feb 2026Reddit, Inc.The ICO imposed a GBP 14.5 million UK GDPR fine on Reddit, Inc. for failures related to age-gating and the protection of children’s data. The matter was initially misfiled as an enforcement notice and later refiled as a monetary penalty notice.GBInformation Commissioner's OfficeGDPR€16,606,000
25 Aug 2023This Is The Big Deal LimitedThis Is The Big Deal Limited sent or instigated 41,417,889 unsolicited direct marketing messages to individuals without consent, breaching regulation 22 of PECR. In addition, 102,132 text messages were sent without the required opt-out information under regulation 23 of PECR. The ICO imposed a fine of 30,000 GBP.GBICOePrivacy€35,028
20 Nov 2025LastPass UK LtdThe ICO imposed a GBP 1,228,283 penalty on LastPass UK Ltd for breaches of Article 5(1)(f) and Article 32(1)(f) UK GDPR. Failure to implement appropriate technical and organisational measures allowed a threat actor to exfiltrate personal data relating to about 1.6 million UK customers from a backup database. The most sensitive data in customer password vaults remained encrypted because of LastPass' zero-knowledge system.GBICOGDPR€1,393,000
05 Dec 2024ESL Consultancy Services Ltd Between 15 September 2022 and 5 December 2023, 37,977 complaints were received about direct marketing messages sent at the instigation of ESL Consultancy Services Ltd. The ICO fined the company GBP 200,000 and issued an enforcement notice.GBICOGDPR€241,000
21 Sept 2023SGS Home Protect LtdSGS Home Protect Ltd made 24,214 marketing calls to individuals in breach of regulation 21 of PECR. The ICO imposed a fine of 70,000 GBP and issued an enforcement notice.GBICOePrivacy€80,724
16 Sept 2025Bharat Singh ChandBharat Singh Chand, a self-employed lead generator, sent or instigated the sending of 966,449 direct marketing SMS messages between 3 December 2023 and 3 July 2024. The activity breached regulations 22 and 23 of PECR and generated 19,138 complaints to the 7726 spam reporting service. He was fined £200,000 and issued with an enforcement notice.GBICOePrivacy€231,000
05 Jun 202523andMeThe UK ICO imposed a GBP 2,310,000 fine on 23andMe for personal data protection breaches. The case concerned inadequate safeguards and processing failures that increased the risk of unauthorized access to user data.GBICOGDPR€2,743,000
26 Feb 2024Ministry of DefenceThe UK Ministry of Defence sent emails using the “To” field instead of “BCC”, which disclosed 265 unique email addresses. The ICO found this breached GDPR Article 5(1)(f) and imposed a fine of 350,000 GBP.GBICOGDPR€409,000
16 May 2023Ice Telecommunications LtdIce Telecommunications Ltd made 72,682 unsolicited marketing calls to businesses registered with the CTPS or TPS between 13 September 2021 and 31 January 2022. The ICO imposed a fine of £80,000 for breaching direct marketing rules.GBICOGDPR€92,016
19 Jan 2024L.A.D.H LimitedL.A.D.H Limited sent 31,329 direct marketing text messages to individuals in breach of regulations 22 and 23 of PECR. The ICO imposed a fine of GBP 50,000 and issued an enforcement notice.GBICOePrivacy€58,260
23 Feb 2026Reddit, Inc.The ICO imposed a penalty of 14,472,500 GBP on Reddit, Inc. for breaches of Articles 5(1)(a), 6, 8, and 35 of the UK GDPR. The case concerned unlawful personal data processing and failures to implement appropriate safeguards and a data protection impact assessment.GBICOGDPR€16,571,000
16 Jan 2024Poxell LtdThe ICO found that Poxell Ltd made 2,647,805 unsolicited direct marketing calls between 31 March 2022 and 20 July 2022, breaching regulations 21 and 24 of PECR. This led to 413 complaints to the ICO and TPS, with recipients reporting persistent calls about energy-related products and home improvements.GBICOePrivacy€174,000
08 Jun 2023Maxen Power Supply LimitedMaxen Power Supply Limited used overseas call centres to make unsolicited marketing calls to businesses. The conduct breached regulations 21 and 24 of PECR, and the ICO imposed a fine of 120,000 GBP and issued an enforcement notice.GBICOePrivacy€139,000
12 Dec 2024Breathe Services LtdBreathe Services Ltd, a debt advice company based in Bolton, was investigated by the ICO following complaints about unsolicited calls to potentially vulnerable individuals. The ICO found that the company spoofed outbound numbers and made 4,376,037 unsolicited direct marketing calls to numbers registered with the Telephone Preference Service, generating multiple complaints.GBICOGDPR€206,000
14 Apr 2025DPP Law LtdThe UK Information Commissioner fined law firm DPP Law Ltd 60,000 GBP for breaches of Articles 5(1)(f), 32(1), 32(2) and 33(1) of the UK GDPR. The infringements occurred between 25 May 2018 and 17 July 2022. The case concerned inadequate security measures and incident reporting obligations.GBICOGDPR€69,456
06 Nov 2025Lead Pronto LtdLead Pronto Ltd received an MPN and an EN from the ICO for sending unsolicited SMS messages promoting Government funded boiler grants. The case indicates a breach of direct marketing rules and consent requirements.GBICOGDPR€34,065
06 Mar 2024The Central Young Men’s Christian AssociationThe Central YMCA sent an email to participants in a programme for people living with HIV using “CC” instead of “BCC”, which exposed recipients’ email addresses to all recipients. From those addresses, 166 individuals could be identified or potentially identified, allowing an inference that they were likely living with HIV. The ICO imposed a £7,500 fine and issued a reprimand.GBICOGDPR€8,772
09 Nov 2023Complete Marketing Services LtdBetween 8 June 2021 and 4 February 2022, Complete Marketing Services Ltd instigated 242,497 unsolicited direct marketing calls in breach of PECR. The ICO became aware of the matter after complaints about live marketing calls relating to road traffic accidents and personal injury claims were reported via the TPS.GBICOePrivacy€172,000