Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
03 Mar 2025BEKO ROMÂNIA SAIn February 2025, ANSPDCP completed an investigation at BEKO ROMÂNIA SA and found violations of GDPR provisions. As a result, the controller was fined EUR 10,000.ROANSPDCPGDPR€10,000
28 Mar 2023SOCIETE DE MARKETING (procédure simplifiée)CNIL imposed a fine of EUR 10,000 on SOCIETE DE MARKETING and issued an injunction. The case was handled under a simplified procedure.FRCNILGDPR€10,000
11 Jul 2019Thomas N****The individual secretly recorded video footage of two women in a changing room without their consent. The DSB found this to be a breach of GDPR rules on lawful processing and consent.ATDSBGDPR€10,000
29 May 2019Regione PugliaRegione Puglia was fined by the Garante 10,000 EUR for unlawfully publishing personal data of participants in a selection process on its official website. The disclosure included tax codes and income data, breaching privacy rights.ITGaranteGDPR€10,000
01 Apr 2025BitdefenderBitdefender received a GDPR fine of EUR 10,000 from the Romanian data protection authority. The sanction followed an investigation completed in April 2025 after a data breach notification, with the authority citing inadequate technical and organizational security measures.ROAutoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal€10,000
19 Feb 2015Comune di CampotostoComune di Campotosto was fined by the Garante for unlawfully publishing personal data revealing health information on its website. The case concerned a breach of privacy and personal data protection rules.ITGaranteGDPR€10,000
05 Mar 2015Istituto Professionale di Stato per i Servizi Commerciali Turistici Alberghieri "Cesare Musatti"The Istituto Professionale di Stato per i Servizi Commerciali Turistici Alberghieri “Cesare Musatti” was fined by the Italian data protection authority, Garante, in the amount of €10,000. The violation involved unlawfully publishing personal data on its website that revealed students’ health status.ITGaranteGDPR€10,000
22 May 2018Pettirossi AngeloDr Pettirossi Angelo was fined by the Garante for failing to implement minimum security measures for personal data protection. The breach allowed unauthorized access to the healthcare system.ITGaranteGDPR€10,000
16 Dec 2009Polisportiva Eschilo 1 società sportiva dilettantistica a r.l.Polisportiva Eschilo 1 was fined EUR 10,000 by the Italian Garante. The case concerned processing biometric data without prior notification to the supervisory authority, which breached data protection rules.ITGaranteGDPR€10,000
13 Jan 2023CORREDURÍA DE SEGUROS DE MADRID, S.L.CORREDURÍA DE SEGUROS DE MADRID, S.L. was fined by the AEPD 10,000 EUR for processing personal data without a legal basis. The company linked the complainant’s bank account to insurance policies they had not taken out, resulting in unauthorized charges.ESAEPDGDPR€10,000
27 Mar 2014Casa di cura Scarnati srlCasa di cura Scarnati srl was fined €10,000 by the Garante. The authority found that the company failed to properly designate, in writing, the employees authorized to process personal data.ITGaranteGDPR€10,000
13 Feb 2007Asl Basso MoliseAsl Basso Molise was fined by the Garante for failing to notify its data processing activities within the required timeframe. The breach concerned the Italian Data Protection Code.ITGaranteGDPR€10,000
05 Jan 2024B.B.B.The entity was fined for publishing personal images and phone numbers on Telegram channels without the data subjects’ consent. The authority found a breach of Article 6(1) GDPR.ESAEPDGDPR€10,000
01 Jan 2019D. B.B.B.The respondent was fined for publishing intimate photos and conversations of the complainant on WhatsApp without consent. The authority found a breach of data protection rules.ESAEPDGDPR€10,000
10 Oct 2022EKO ABEEThe fine was imposed for a violation of Article 15 GDPR because the controller failed to provide the data subject with access to their personal data. The case concerns non-compliance with the obligation to ensure the right of access within the required scope.GRHDPAGDPR€10,000
27 Nov 2024Engineering Ingegneria Informatica S.p.A.The Garante imposed a fine of EUR 10,000 on Engineering Ingegneria Informatica S.p.A. for a data breach involving the Molise regional health portal. A system vulnerability allowed unauthorized access to personal data.ITGaranteGDPR€10,000
31 Jan 2024SOCIETE AYANT POUR ACTIVITE LE SOUTIEN AUX ENTREPRISES (procédure simplifiée)The CNIL imposed an administrative fine of EUR 10,000 on SOCIETE AYANT POUR ACTIVITE LE SOUTIEN AUX ENTREPRISES. The decision concerns a breach of rules supervised by the CNIL.FRCNILGDPR€10,000
12 Sept 2013Comune di MantovaThe Municipality of Mantua was fined by the Garante for unlawfully disseminating personal data through its online services without a proper legal basis. The authority found a breach of Article 19 of the Italian Data Protection Code.ITGaranteGDPR€10,000
31 May 2022DKN.5131.51.2021StatusuchylonaTytuUODO imposed an administrative fine of PLN 10,000 for a breach involving the recording and storage of sound in a monitoring system. The case concerned improper use of CCTV monitoring with audio capture.PLUODOGDPR€2,183
04 Apr 2007Azienda sanitaria locale di PescaraAzienda sanitaria locale di Pescara was fined €10,000 by the Garante for breaching data protection rules. The case involved improper handling of sensitive personal data, including genetic and health information, without the required notification to the authority.ITGaranteGDPR€10,000