Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
09 Aug 2012Iatriko AthinonThe fine was imposed for failing to respond to a data subject's request for access to their medical records. The authority treated this as a violation of the right to information.GRHDPAGDPR€7,500
09 Aug 2012Iatriko AthinonThe fine was imposed for failing to implement appropriate organizational and technical measures to secure sensitive medical data. The case concerned insufficient protection of special-category personal data.GRHDPAGDPR€7,500
24 Jun 2025I ASPIDA TOU DAVIDThe entity did not inform data subjects about the processing of their personal data. The authority treated this as a GDPR breach and imposed a monetary fine.GRHDPAGDPR€3,000
24 Jun 2025I ASPIDA TOU DAVIDThe entity failed to provide the required information and to implement adequate data protection measures. HDPA imposed a fine of EUR 3,000 for breach of GDPR principles.GRHDPAGDPR€3,000
24 Jun 2025I ASPIDA TOU DAVIDThe entity did not satisfy a minor's request to access personal data, which constitutes a breach of GDPR principles. HDPA imposed a fine of EUR 3,000.GRHDPAGDPR€3,000
24 Jun 2025I ASPIDA TOU DAVIDThe HDPA imposed a EUR 1,000 fine on I ASPIDA TOU DAVID. The authority found that the entity failed to cooperate, which breaches GDPR requirements.GRHDPAGDPR€1,000
20 Mar 2015IANO OIKONOMIKE EKDOSEIS AEIANO OIKONOMIKE EKDOSEIS AE was fined EUR 30,000 by the HDPA for sending unsolicited electronic communications. The company collected a large number of email addresses without consent, breaching data protection rules.GRHDPAePrivacy€30,000
22 Jan 2015Iama Consulting s.r.l.Iama Consulting s.r.l. was fined by the Garante for collecting email addresses through a website form without providing the required privacy notice. The authority found a breach of Article 13 of the Italian Data Protection Code.ITGaranteGDPR€2,400
14 Sept 2018IAHORRO BUSINESS SOLUTIONS SLIAHORRO BUSINESS SOLUTIONS SL was fined by the AEPD €1,000 for sending unsolicited commercial electronic communications. The company also failed to provide a procedure for exercising rights of access, rectification, cancellation, or objection.ESAEPDePrivacy€1,000
25 Oct 2024IA BILET SRLThe operator was fined EUR 1,000 by ANSPDCP for violating GDPR provisions. The case concerns non-compliant processing of personal data.ROANSPDCPGDPR€1,000
25 Oct 2024IA BILET SRLThe operator was fined EUR 1,000 by ANSPDCP for violating GDPR provisions. The case concerns non-compliance with personal data protection requirements.ROANSPDCPGDPR€1,000
14 May 2025IAB EuropeThe Gegevensbeschermingsautoriteit’s decision concerned IAB Europe and the Transparency and Consent Framework. A fine of EUR 250,000 was imposed for GDPR breaches related to the processing of personal data, and the Brussels Market Court confirmed the violations and sanctions while noting procedural grounds for annulling the original decision.BEGegevensbeschermingsautoriteit (GBA)GDPR€250,000
02 Feb 2022IAB EuropeIAB Europe was fined EUR 250,000 by the Belgian APD for violations related to its Transparency & Consent Framework. The authority identified issues with transparency, the legal basis for processing, and the security of personal data.BEAPDGDPR€250,000
02 Feb 2022IAB EuropeIAB Europe was fined EUR 250,000 by the Belgian APD for violations related to its Transparency & Consent Framework. The authority cited lack of transparency, improper processing of personal data, and failure to meet GDPR obligations.BEAPDGDPR€250,000
13 Mar 2015HYUNDAY MOTOR ESPAÑA, S.L.U.HYUNDAY MOTOR ESPAÑA, S.L.U. was fined 10,000 EUR by the AEPD. The sanction concerned sending unsolicited commercial emails without recipient consent, in breach of the LSSI.ESAEPDePrivacy€10,000
23 Dec 2024HYUNDAI MOTOR ESPAÑA S.L.U.HYUNDAI MOTOR ESPAÑA S.L.U. was fined EUR 2,000,000 by the AEPD for a data security incident. Unauthorized access to customer data occurred, breaching data protection principles.ESAEPDGDPR€2,000,000
10 Sept 2024HWM PSI, S.L.HWM PSI, S.L. was fined by the AEPD 100 EUR for sending an email to multiple recipients without using BCC. This exposed recipients’ personal email addresses and breached data protection rules.ESAEPDGDPR€100
22 Jan 2024Hvidovre KommuneHvidovre Kommune was fined by Datatilsynet for failing to maintain an appropriate level of security. The issue allowed unauthorized access to protected addresses of children through the municipal dental service's self-service solution, which incorrectly extended access to both custodial parents.DKDatatilsynetGDPR€26,816
21 Mar 2013HU YunteHU Yunte was fined by the Garante for failing to provide the required data protection notice in connection with a video surveillance system. The breach concerned Article 13 of the Italian Data Protection Code.ITGaranteGDPR€2,400
18 Jul 2013Hu YonglianHu Yonglian was fined by the Garante in the amount of EUR 2,400 for inadequate data protection notice in a retail store video surveillance system. The authority found a breach of the Italian Privacy Code.ITGaranteGDPR€2,400