Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
20 Dec 2025JOMAFRAN 2013, S. LJOMAFRAN 2013, S. L was fined by the AEPD EUR 1,400 for sending unsolicited commercial emails without prior consent. The authority found this conduct breached Article 21.1 of the LSSI.ESAEPDePrivacy€1,400
20 Dec 2025KVIKU SPAIN, S.L.KVIKU SPAIN, S.L. was fined by the AEPD 5,000 EUR for processing personal data without a legal basis. The case concerned debt collection related to a loan that the complainant had neither consented to nor requested.ESAEPDGDPR€5,000
19 Dec 2025HelsaMiNorway’s digital accessibility regulator found 119 accessibility errors at HelsaMi, with 64 issues still unresolved after the initial remediation deadline. The operator was ordered to fix the problems by 2025-12-19 or face a daily penalty of NOK 50,000 until compliance is achieved.NOTilsynet for universell utforming av IKTEAA€4,197
19 Dec 2025MÁV Személyszállítási Zártkörűen Működő RészvénytársaságThe NAIH imposed a 50,000,000 HUF fine on MÁV Személyszállítási Zrt. for breaching GDPR principles. The authority found deficiencies in transparency and data minimization in the company's camera surveillance and audio recording practices at HÉV stations.HUNAIHGDPR€129,000
19 Dec 2025ORANGE ESPAGNE, S.A.U.ORANGE ESPAGNE, S.A.U. was fined by the AEPD 25,000 EUR for sending invoices to a person who was not a customer and for failing to properly delete their data after a request. The authority found breaches of data accuracy and the right to erasure under GDPR Articles 5(1)(d) and 17.ESAEPDGDPR€25,000
18 Dec 2025Comune di NaveComune di Nave was fined by the Garante for failing to ensure transparency in the processing of vehicle license plate data captured by surveillance cameras. The authority also found a breach of GDPR principles and the absence of a data protection impact assessment.ITGaranteGDPR€6,000
18 Dec 2025Elba Catering Distribuzioni s.r.l.s.Elba Catering Distribuzioni s.r.l.s. was fined EUR 2,000 by the Garante for installing a video surveillance system that primarily captured public streets. The authority found that this processing breached data protection rules.ITGaranteGDPR€2,000
18 Dec 2025Anticimex s.r.l.Anticimex s.r.l. was fined EUR 40,000 by the Garante for breaching data protection rules. The company failed to provide an employee with access to personal data, including work-related emails and CRM access logs, despite a request under Article 15 GDPR.ITGaranteGDPR€40,000
18 Dec 2025SOCIETE EXERCANT UNE ACTIVITE D'AGENCE DE VOYAGE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 2,000 on SOCIETE EXERCANT UNE ACTIVITE D'AGENCE DE VOYAGE and issued an injunction. The case concerns a breach of rules supervised by the CNIL.FRCNILGDPR€2,000
18 Dec 2025SOCIETE AYANT POUR ACTIVITE L'AMENAGEMENT PAYSAGER, L'INSTALLATION DE JARDINS ET DE TERRAINS DE SPORT (procédure simplifiée)The CNIL imposed an administrative fine of EUR 7,000 on the company engaged in landscaping, garden installation, and sports field installation. The case was handled under a simplified procedure.FRCNILGDPR€7,000
18 Dec 2025Provvedimento del 18 dicembre 2025 [10210431]A professional sent a communication containing personal data to an institutional email address, which breached data protection rules. The Garante imposed a fine of EUR 1,000.ITGaranteGDPR€1,000
18 Dec 2025SOCIETE EXERCANT UNE ACTIVITE DE REALISATION D'OPERATIONS DE PROSPECTION COMMERCIALE PAR VOIE ELECTRONIQUE POUR LE COMPTE D'AGENCES DE PUBLICITE (procédure simplifiée)CNIL imposed an administrative fine of EUR 6,000 on SOCIETE EXERCANT UNE ACTIVITE DE REALISATION D'OPERATIONS DE PROSPECTION COMMERCIALE PAR VOIE ELECTRONIQUE POUR LE COMPTE D'AGENCES DE PUBLICITE. The case was handled under a simplified procedure.FRCNILGDPR€6,000
18 Dec 2025LTL S.p.A.LTL S.p.A. was fined 40,000 EUR by the Garante for unlawfully maintaining access to an ex-employee’s email account after termination. The authority found this to be a breach of data protection rules.ITGaranteGDPR€40,000
18 Dec 2025SOCIETE EXERCANT UNE ACTIVITE DE PROGRAMMATION INFORMATIQUE (GESTIONS LOCATIVE ET DE COPROPRIETE) (procédure simplifiée)The CNIL imposed an administrative fine of EUR 15,000 on SOCIETE EXERCANT UNE ACTIVITE DE PROGRAMMATION INFORMATIQUE and issued an injunction. The case concerned a breach of personal data protection obligations.FRCNILGDPR€15,000
18 Dec 2025SOCIETE EXERCANT UNE ACTIVITE DE COLLECTE DE DONNEES PROVENANT DE JEUX CONCOURS, DE PROSPECTION COMMERCIALE ET DE TRANSMISSION DE DONNEES A SES CLIENTS (procédure simplifiée)CNIL imposed an administrative fine of 20,000 EUR on a company engaged in collecting data from prize contests, commercial prospecting, and data transmission to clients. The case was handled under a simplified procedure.FRCNILGDPR€20,000
18 Dec 2025Pioneer Hi-Bred Italia Sementi s.r.l.Pioneer Hi-Bred Italia Sementi s.r.l. was fined by the Garante 120,000 EUR for installing telematic devices in company vehicles to monitor employees' driving behavior. The authority found that the processing lacked proper data protection safeguards and privacy information.ITGaranteGDPR€120,000
18 Dec 2025TELCOM BUSINESS SOLUTIONS S.L.TELCOM BUSINESS SOLUTIONS S.L. was fined by the AEPD for attempting to process live and biometric data without prior consent. After a purchase, users were redirected to a US-based company for identity verification.ESAEPDGDPR€25,000
17 Dec 2025Stichting Hogeschool van Arnhem en NijmegenThe Autoriteit Persoonsgegevens imposed a fine of €175,000 on Stichting Hogeschool van Arnhem en Nijmegen for failing to implement adequate technical and organizational measures appropriate to the risk. These deficiencies resulted in a data breach.NLAPGDPR€175,000
17 Dec 2025HAN University of Applied SciencesThe Autoriteit Persoonsgegevens announced on 17 December 2025 that it had imposed a fine on HAN University of Applied Sciences. According to the notice, the university was hacked in September 2021, resulting in a data breach, and HAN will not object to the decision.NLAutoriteit PersoonsgegevensGDPR€100,000
16 Dec 2025Anonymisé (CNPD decision-06-fr-2025)The company failed to maintain a proper record of processing activities under Article 30 GDPR. The register contained inaccuracies and omissions, indicating a breach of documentation obligations.LUCNPDGDPR€1,277