Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.4%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
25 Nov 2025Dane anonimowe (D. C., prowadzącego działalność gospodarczą pod firmą W.)UODO imposed a fine of PLN 7,577 on an anonymous entrepreneur for failing to implement adequate technical and organizational measures to secure data processing. The authority also found that processing was not properly limited to the controller’s instructions and that no record of processing activities was maintained.PLUODOGDPR€1,794
11 Jun 2021Anonymisé (CNPD decision-21-fr-2021)The company did not comply with the data minimization principle and failed to adequately inform employees and third parties about data processing activities. CNPD found these practices to breach GDPR Articles 5(1)(c) and 13.LUCNPDGDPR€7,600
30 Apr 2026Dane anonimowe (Burmistrza Miasta i Gminy D.)UODO imposed an administrative fine of 7,700 PLN on Anonymous data (Mayor of D. Municipality). The sanction resulted from failing to notify the President of the Personal Data Protection Office of a personal data breach without undue delay, and no later than 72 hours after becoming aware of it.PLUODOGDPR€1,807
23 Oct 2025Dane anonimowe (Komornika Sądowego przy Sądzie Rejonowym w S. B. F. Kancelaria)The President of UODO imposed an administrative fine on the bailiff’s office for failing to report a personal data breach within the required 72 hours. The authority also found that the affected individual was not notified without undue delay after the data was disclosed to an unauthorized recipient.PLUODOGDPR€1,819
14 Jan 2021Agenzia regionale protezione ambientale Campania (ARPAC)ARPAC was fined by the Garante EUR 8,000 for violations concerning data security measures and data breach notification obligations. The case involved non-compliance with GDPR Articles 5 and 32.ITGaranteGDPR€8,000
29 Jan 2015Abruzzo Vigilanza s.r.l.Abruzzo Vigilanza s.r.l. was fined €8,000 by the Garante for using a vehicle tracking system without the required notification. The case concerns non-compliance with data protection notification obligations.ITGaranteGDPR€8,000
09 Oct 2025Arienti & C. s.r.l. a socio unicoThe Garante fined Arienti & C. s.r.l. a socio unico EUR 8,000 for denying a former employee access to their email account after the employment contract ended. The authority found this breached GDPR Article 15 on the right of access to personal data.ITGaranteGDPR€8,000
04 May 2015CitibankThe HDPA imposed a fine of EUR 8,000 on Citibank. The case concerned the bank’s failure to satisfy the complainant’s right of access to personal data.GRHDPAGDPR€8,000
02 Oct 2014Comune di Piana degli AlbanesiThe Municipality of Piana degli Albanesi was fined EUR 8,000 by the Garante for failing to appoint data processing officers. The authority also found that the required security program document had not been drafted, in breach of data protection rules.ITGaranteGDPR€8,000
27 Aug 2024YThe case concerns a football club that obtained a member list during a takeover and used the personal data for commercial mailings without a valid legal basis. The authority found breaches of several GDPR provisions and imposed a monetary fine.BEAPDGDPR€8,000
04 Dec 2020BORJAMOTOR, S.A.BORJAMOTOR, S.A. was fined by the AEPD €8,000 for sending commercial SMS messages without explicit consent from recipients. The authority also identified improper consent practices for personal data processing on the company’s website.ESAEPDePrivacy€8,000
13 Nov 2024Azienda Sanitaria provinciale di EnnaAzienda Sanitaria provinciale di Enna was fined by the Garante 8,000 EUR for breaches of GDPR Articles 5 and 6 and Article 2-ter of the Italian Privacy Code. The case concerned improper handling of personal data. The decision indicates non-compliance with core rules on lawful and proper processing.ITGaranteGDPR€8,000
15 Dec 2011dott. Mancini Endriodott. Mancini Endrio was fined EUR 8,000 by the Garante for violating data protection rules. The case concerned inadequate compliance with data security requirements under Article 162, paragraph 2-bis, of the Italian Privacy Code.ITGaranteGDPR€8,000
20 Aug 2024Ana Hotels SRLAna Hotels SRL was fined by ANSPDCP €8,000 after a data security incident caused by a ransomware attack. The incident led to unauthorized disclosure of personal data belonging to a significant number of employees.ROANSPDCPGDPR€8,000
17 Jul 2025Smart R.E. S.r.l.Smart R.E. S.r.l. was fined EUR 8,000 by the Italian authority Garante for failing to comply with a former employee’s deletion request. After the employment ended, the assigned email account remained active and redirected messages to another company account.ITGaranteGDPR€8,000
07 Sept 2011Aga s.r.l.Aga s.r.l. was fined EUR 8,000 by the Garante for processing online customers' personal data without ensuring freely given and specific consent. The authority found this to be a breach of data protection rules.ITGaranteGDPR€8,000
14 Nov 2024Comune di Borgo Val di TaroComune di Borgo Val di Taro was fined EUR 8,000 by the Garante for improper handling of personal data. The authority found breaches of lawfulness, fairness, transparency, and data minimization principles.ITGaranteGDPR€8,000
14 Oct 2021Azienda per la Tutela della Salute (ATS) della SardegnaAzienda per la Tutela della Salute (ATS) della Sardegna was fined EUR 8,000 by the Garante for improper processing of personal data, including health data. The authority found breaches of GDPR Articles 5 and 9.ITGaranteGDPR€8,000
29 Oct 2020Città Metropolitana di NapoliCittà Metropolitana di Napoli was fined EUR 8,000 by the Garante for improper handling of personal data. The authority found that a disciplinary document was not marked as confidential, which allowed unauthorized access within the administration.ITGaranteGDPR€8,000
17 Jan 2013Bagno sport 70 s.a.s.Bagno sport 70 s.a.s. was fined 8,000 EUR by the Garante for processing customers' biometric data for payments. The company failed to notify the supervisory authority, which breached the Italian Data Protection Code.ITGaranteGDPR€8,000