Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
30 Jun 2022Anonymisé (CNPD decision-13-fr-2022)The company breached GDPR by failing to respect data retention limits and by not providing employees with adequate information about the vehicle geolocation system. The CNPD imposed a fine of EUR 5,600.LUCNPDGDPR€5,600
04 Oct 2023Amazon EuropeThe CNPD imposed a fine of EUR 746,000,000 on Amazon Europe for breaches of data protection rules. The case concerned shortcomings in the processing of personal data and compliance with GDPR requirements.LUCNPDGDPR€746,000,000
16 Dec 2025Anonymisé (CNPD decision-04-fr-2025)The company did not maintain a complete and accurate record of processing activities under Article 30 GDPR. CNPD treated this as a breach of documentation obligations and imposed an administrative fine.LUCNPDGDPR€2,784
27 Oct 2021Anonymisé (CNPD decision-41-fr-2021)The CNPD imposed a fine of 18,700 EUR on Anonymisé for improper implementation of Data Protection Officer obligations. The company did not publish the DPO’s contact details, did not involve the DPO in all data protection matters, did not ensure the DPO’s autonomy, and did not assign monitoring of GDPR compliance.LUCNPDGDPR€18,700
01 Jan 2021Município de LisboaThe Portuguese data protection authority fined Município de Lisboa EUR 1,250,000 in 2021. The sanction concerned the unlawful transfer of protesters’ personal data to the Russian Embassy in breach of the GDPR.PTComissão Nacional de Proteção de DadosGDPR€1,250,000
18 Oct 2019National Revenue Agency (Bulgaria)The Commission for Personal Data Protection imposed a fine of 5,100,000 BGN on Bulgaria’s National Revenue Agency. The sanction concerned the unauthorized disclosure and dissemination of personal data following a major security breach.BGCommission for Personal Data ProtectionGDPR€2,607,000
13 Jan 2026Free Mobile and FreeFrance’s CNIL fined Free Mobile and Free a combined EUR 42 million for GDPR breaches linked to a 2024 data breach affecting more than 24 million users. The regulator found inadequate security measures and said Free Mobile unlawfully retained former subscribers’ data.FRCommission nationale de l’informatique et des libertésGDPR€42,000,000
13 Jan 2025OrangeCNIL imposed a EUR 50 million fine on Orange for displaying commercial ads in email inboxes without prior user consent. The authority also found that advertising and statistical cookies continued to be read after consent had been withdrawn, in breach of the GDPR.FRCommission Nationale de l'Informatique et des LibertésGDPR€50,000,000
06 Apr 2023К. Л. НK. L. N was fined for unlawfully processing voters' personal data. The case involved forwarding an email containing scanned voting lists to a personal email address, in breach of GDPR Article 6.BGCPDPGDPR€767
26 Feb 2019телекомуникационен операторThe telecommunications operator was fined BGN 53,000 by the CPDP for processing personal data without consent. The case involved changing a subscription plan to a prepaid service without the data subject's knowledge or agreement.BGCPDPGDPR€27,099
26 Mar 2019А.Р. ЕООДThe CPDP imposed a 10,000 BGN fine on А.Р. ЕООД for processing personal data without consent. The case also involved registering an employment contract for an imprisoned individual, which breached Article 6 GDPR.BGCPDPGDPR€5,113
24 Jul 2019НОИThe National Social Security Institute (НОИ) was fined for failing to implement adequate technical and organizational measures to prevent employees from accessing personal data without authorization. The authority found this to be a breach of GDPR Article 25.BGCPDPGDPR€2,557
26 Jan 2023Политическа партия ******The political party unlawfully processed personal data by including individuals in a list supporting its election registration without their consent. The authority found breaches of GDPR Articles 5, 6, and 24.BGCPDPGDPR€7,823
06 Jan 2020дружество за комунални услугиThe utility company processed the complainant’s personal data without a lawful basis by sharing it with a private bailiff for enforcement proceedings. CPDP imposed a fine of 10,000 BGN for breaching Article 6 GDPR.BGCPDPGDPR€5,113
12 Feb 2018Анонимизирано (CPDP решение-по-жалба-с-рег-№-ж-453-05-10-201)The Commission fined an individual for unlawfully processing personal data by including it in a list supporting registration for a referendum campaign without consent. The case concerned a breach of the legal basis requirements for personal data processing.BGCPDPGDPR€5,113
26 Oct 2021ЧСИ2The Commission fined the private bailiff ЧСИ2 for unlawfully processing personal data by accessing bank account information after the enforcement proceeding had ended. The authority found a breach of the purpose limitation principle under Article 5 GDPR.BGCPDPGDPR€383
08 Oct 2019Министър на вътрешните работиThe Ministry of Interior was fined for unlawfully processing and sharing the personal data of a Finnish citizen with Togo authorities without a legal basis. The authority found a breach of GDPR principles on lawful processing and data disclosure.BGCPDPGDPR€5,113
07 Oct 2019Анонимизирано (CPDP решение-по-жалба-с-рег-№-ппн-01-657-08-0)The Bulgarian data protection authority, CPDP, fined an individual, V.M., BGN 1,000. The sanction concerned failure to provide access to information requested by the authority in connection with a complaint about unlawful dissemination of personal data.BGCPDPGDPR€511
12 Feb 2018Политическа партия „Движение презареди България“The political party Movement Reload Bulgaria was fined 10,000 BGN by the CPDP for processing personal data without consent. The breach occurred during the registration of individuals as election commission members and violated the Bulgarian Personal Data Protection Act.BGCPDPGDPR€5,113
24 Aug 2021Топлофикация София ЕАДThe Bulgarian data protection authority fined Toplofikatsia Sofia EAD 2,000 BGN for unlawful processing of personal data caused by a name coincidence. The error led to incorrect legal actions being taken against an individual.BGCPDPGDPR€1,023