Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
21 Nov 2022ING Bank NV Amsterdam Sucursala BucureștiANSPDCP completed an investigation into ING Bank NV Amsterdam Bucharest Branch and found a breach of GDPR provisions. The case was opened following a data breach notification submitted by the controller.ROANSPDCPGDPR€20,000
27 Aug 2025INGPoland’s data protection authority, UODO, fined ING more than PLN 18 million. The authority found that the bank scanned identity documents in situations not required by AML rules, including for non-customers and in cases unrelated to service provision.PLUrząd Ochrony Danych OsobowychGDPR€4,215,000
18 Feb 2021INFORMÁTICA MÉDICA, S.L.INFORMÁTICA MÉDICA, S.L. was fined by the AEPD 60,000 EUR for failing to have a proper data processing agreement with its processor, OUTENUVE. The authority treated this as a breach of Article 28 GDPR.ESAEPDGDPR€60,000
29 Jul 2011INFORMA D&B, SAINFORMA D&B, SA was fined by the AEPD 50,000 EUR for continuing to send commercial emails after the recipient requested unsubscribing and objected to data processing. The authority found a breach of Article 21 of the LSSI.ESAEPDePrivacy€50,000
08 Mar 2018INFOMOBILITY S.P.A.INFOMOBILITY S.P.A. was fined EUR 26,000 by the Garante for providing inadequate information to customers about geolocation activities in its car sharing service. The authority found that the disclosures did not meet transparency requirements for users.ITGaranteGDPR€26,000
27 Nov 2025Infobel NVInfobel NV was fined by the APD in the amount of 5,000 EUR for unlawfully processing personal data for direct marketing purposes without a valid legal basis. The authority found breaches of GDPR Articles 5(1)(a), 6(1), and 24.BEAPDGDPR€5,000
27 Nov 2025InfobelThe Belgian Data Protection Authority (APD) imposed a EUR 40,000 fine on Infobel on 2025-11-27. The authority found that the company resold telecom-derived personal data for marketing purposes without valid consent and ordered it to inform its business customers of the decision.BEAutorité de protection des données (APD)GDPR€40,000
08 Aug 2014INFOASSIST A.E.INFOASSIST A.E. was fined by the HDPA 7,500 EUR for processing personal data without consent. The authority found breaches of legality and data minimization principles.GRHDPAGDPR€7,500
06 Oct 2016Infantino Auto S.r.l.ITGaranteGDPR€2,400
23 Jul 2010INEXTRAMA SOL INF. SECTOR GRAFICO S.L.INEXTRAMA SOL INF. SECTOR GRAFICO S.L. was fined by the AEPD EUR 30,001 for sending unsolicited commercial emails. The conduct breached Article 21.1 of the LSSI, which prohibits unsolicited marketing communications.ESAEPDePrivacy€30,001
18 Jan 2021INDUSTRIAS METÁLICAS ANRO, S.L.INDUSTRIAS METÁLICAS ANRO, S.L. was fined by the AEPD for failing to comply with cookie policy requirements on its website. The breach concerned Article 22.2 of the LSSI.ESAEPDePrivacy€2,000
13 May 2024INDEPENDENTS DE VALLROMANESThe political party Independents de Vallromanes was fined by the AEPD €2,000. The case concerned posting images of a court judgment on social media that included the complainant’s first and last name.ESAEPDGDPR€2,000
29 May 2026IndaNext Hungary Korlátolt Felelősségű TársaságNAIH imposed a fine of 25,000,000 HUF on IndaNext Hungary Kft. for unlawfully publishing personal data and special category data of an individual on www.blikk.hu. The authority found no legal basis and identified breaches of GDPR Articles 6, 9, and 12.HUNAIHGDPR€70,750
28 Nov 2021INCOPROSOL, S.L.INCOPROSOL, S.L. was fined EUR 5,000 by the AEPD for recording a customer's phone conversation without informing them. The authority treated this as a breach of data protection principles.ESAEPDGDPR€5,000
01 Jan 2024INCIBEINCIBE was fined EUR 2,000 by the AEPD for failing to implement data protection by design and by default, in breach of Article 25 GDPR. The procedure concerning the alleged breach of Article 5(1)(f) was dismissed because no serious threat to rights and freedoms was found.ESAEPDGDPR€2,000
24 Feb 2010INBORNTECH S.L.INBORNTECH S.L. was fined by the AEPD 1,200 EUR for sending an unsolicited commercial email. The authority found that the requirements of Article 21 of the LSSI were not met.ESAEPDePrivacy€1,200
18 May 2012INATED S.L.INATED S.L. was fined by the AEPD EUR 600 for sending unsolicited commercial communications by email. This conduct breached Article 21.1 of the LSSI, which prohibits such messages without prior recipient consent.ESAEPDePrivacy€600
01 Jan 2015IMPROCONSULTEX FORMACION INFORMATICA S.L.IMPROCONSULTEX FORMACION INFORMATICA S.L. was fined by the AEPD EUR 1,000 for sending commercial communications by electronic means without prior consent. The case concerns a breach of Article 21.1 of the LSSI and indicates insufficient legal basis for electronic marketing.ESAEPDePrivacy€1,000
04 Jun 2025impresa individuale Pasquale GuadagnoThe company was fined for installing a surveillance camera without proper signage. The camera also captured areas beyond its commercial premises, which breached data protection rules.ITGaranteGDPR€2,000
30 Jan 2014impresa individuale Otelma di Belelli Marco AmletoThe sole proprietorship Otelma di Belelli Marco Amleto was fined EUR 6,400 by the Garante for failing to implement minimum security measures when processing sensitive data via its website. The breaches included not appointing a data processor and not preparing a security program document.ITGaranteGDPR€6,400