Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
10 Jul 2025Istituto Comprensivo 2 C.D.The Garante fined Istituto Comprensivo 2 C.D. EUR 4,000 for breaches of data protection rules. The authority cited non-compliance with the principles of lawfulness, fairness, and transparency in the processing of personal data.ITGaranteGDPR€4,000
05 Jul 2017Istituto Auxologico ItalianoIstituto Auxologico Italiano was fined EUR 10,000 by the Garante for failing to implement adequate technical and organizational measures to protect sensitive personal data. The breach concerned the control and security of personal data contained in medical records, in violation of the Italian Data Protection Code.ITGaranteGDPR€10,000
10 Jun 2020Istituto autonomo per le case popolari della provincia di IserniaIstituto autonomo per le case popolari della provincia di Isernia was fined EUR 2,000 by the Garante. The authority found that personal data, including health information, had been published on the institutional website without a proper legal basis.ITGaranteGDPR€2,000
17 Apr 2026Istituto “Ancelle della Compagnia della Regina dei Gigli”The Garante fined the school EUR 4,000 for processing students’ personal data without a proper legal basis. The authority found breaches of lawfulness, fairness, and transparency.ITGaranteGDPR€4,000
13 Mar 2025Istituto Alberghiero Mediterraneo di Pulsano (TA)Istituto Alberghiero Mediterraneo di Pulsano was fined EUR 2,000 by the Garante. The authority found breaches of the principles of lawfulness, fairness, and transparency in personal data processing.ITGaranteGDPR€2,000
17 Jul 2024IstitutoThe Garante fined Istituto EUR 10,000 for violations related to the processing of personal data in the context of medical and scientific research. The authority found that retention periods were not defined and transparency toward data subjects was insufficient.ITGaranteGDPR€10,000
11 Feb 2021Istituti ospedalieri bergamaschiThe Garante fined Istituti ospedalieri bergamaschi EUR 45,000 for a data protection breach. Online medical reports were accessible to other patients, exposing sensitive personal data.ITGaranteGDPR€45,000
27 Feb 2025Istarski vodovod d.o.o.Istarski vodovod d.o.o. was fined by AZOP EUR 25,000 for failing to implement adequate technical security measures. The deficiencies included the absence of two-factor authentication and monitoring systems, which led to unauthorized access and a data breach.HRAZOPGDPR€25,000
07 Sept 2023ISRA Center Marketing Research SRLIn August 2023, the Romanian supervisory authority ANSPDCP completed an investigation into ISRA Center Marketing Research SRL. It found a GDPR violation and imposed a fine of EUR 2,000.ROANSPDCPGDPR€2,000
20 Oct 2022I.S.P.R.O.The Italian Data Protection Authority fined I.S.P.R.O. EUR 7,000 for violations related to the processing of health data. The case concerned improper handling of sensitive data, creating a material compliance risk.ITGaranteGDPR€7,000
11 Apr 2013I.S.P. Italia srlI.S.P. Italia srl was fined by the Garante for sending unsolicited promotional faxes without the required information notice and without obtaining recipients’ consent. The authority found that the conduct breached rules on prior consent and information duties.ITGaranteGDPR€32,000
06 Feb 2023I&S Limited Kft.I&S Limited Kft. was fined by NAIH for continuous recording of work activities and monitoring guests, as well as for misleading information about data processing. The authority also found unauthorized processing of health data for marketing purposes.HUNAIHGDPR€76,800
21 Apr 2021Isinc S.r.l.s.Isinc S.r.l.s. was fined 20,000 EUR by the Garante for sending promotional emails using personal data taken from public databases without proper consent. The authority found this conduct to be in breach of GDPR Article 5.ITGaranteGDPR€20,000
01 Jan 2023ISA MADRID SERVICIOS, S.L.ISA MADRID SERVICIOS, S.L. was fined EUR 900 by the AEPD for improperly positioning a surveillance camera that captured public areas. The authority also found that adequate signage informing individuals about the surveillance was not provided, in breach of data protection rules.ESAEPDGDPR€900
21 Jan 2010I.S.A. - Istituto Scolastico Ambrosiano s.n.c.I.S.A. - Istituto Scolastico Ambrosiano s.n.c. was fined EUR 6,000 by the Garante. The case concerned the collection of personal data through its website without providing users with adequate information required under Article 13 of the Italian Data Protection Code.ITGaranteGDPR€6,000
23 Mar 2021Irish Credit Bureau DACThe Irish Data Protection Commission (DPC) fined Irish Credit Bureau DAC EUR 90,000 in inquiry IN-19-7-2. The fine has been collected.IEDPCGDPR€90,000
09 May 2024IRIDEX GROUP SALUBRIZARE SRLIRIDEX GROUP SALUBRIZARE SRL was fined by ANSPDCP 2,000 EUR for sending a collective email to clients with recipients' email addresses visible. The incident resulted in unauthorized disclosure of personal data.ROANSPDCPGDPR€2,000
13 May 2021Iren Mercato S.p.A.Iren Mercato S.p.A. was fined by the Garante for processing personal data for marketing purposes without proper consent. The company also contacted individuals listed in the public opposition register.ITGaranteGDPR€2,856,000
01 Feb 2018Iqbal QuasimIqbal Quasim was fined EUR 30,000 by the Garante. The case concerned registering phone SIM cards to third parties without their consent, which breached data protection rules.ITGaranteGDPR€30,000
31 May 2018Iqbal QasimIqbal Qasim was fined by the Garante in the amount of EUR 70,000 for registering phone SIM cards to third parties without their consent. The conduct breached privacy and personal data protection rules.ITGaranteGDPR€70,000