Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
06 Aug 2020Hozzáférési jog, adatpontosság és átláthatóság elvének megsértéseThe decision concerned unlawful processing of personal data during debt collection and breaches of access rights and information obligations under the GDPR. Both entities involved in the case were fined for their actions.HUNAIHGDPR€5,780
21 Sept 2023House Hold Appliances 247 LtdHouse Hold Appliances 247 Ltd made 19,069 marketing calls to individuals in breach of regulation 21 of PECR. The ICO fined the company 55,000 GBP and issued an enforcement notice.GBICOePrivacy€63,426
15 Sept 2022HOTEL VILLA SORO, S.L.The company was fined by the AEPD EUR 1,000 for installing surveillance cameras that could capture public areas without proper signage. The authority considered this a breach of data protection rules.ESAEPDGDPR€1,000
13 Jun 2013Hotel Villa Las Tronas s.r.l.Hotel Villa Las Tronas s.r.l. was fined EUR 2,400 by the Garante for failing to provide simplified information about video surveillance. The authority found this to be a breach of data protection rules.ITGaranteGDPR€2,400
04 Dec 2014Hotel Stamira s.r.l.Hotel Stamira s.r.l. was fined by the Garante for processing personal data related to job applications without providing the required information notice. The authority found a breach of Article 13 of the Italian Data Protection Code.ITGaranteGDPR€2,400
20 Apr 2017Hotel Savoia Genova s.r.l.Hotel Savoia Genova s.r.l. was fined €16,800 by the Garante. The authority found that the company failed to provide the required information to individuals about its video surveillance system and kept surveillance footage longer than permitted.ITGaranteGDPR€16,800
07 Jun 2012HOTEL REY DON SANCHO S.A.HOTEL REY DON SANCHO S.A. was fined EUR 30,001 by the AEPD for continuing to send unsolicited commercial emails despite a request for data cancellation. The authority found a breach of Article 21.1 of the LSSI.ESAEPDePrivacy€30,001
07 Mar 2024Hotel Milano di Foschi Eros e Righini Rina & C. SncThe Garante fined Hotel Milano EUR 3,000 for improper installation of surveillance cameras. The cameras captured public streets and third-party properties, and the informational signage was inadequate.ITGaranteGDPR€3,000
01 Jan 2014HOSPITAL VETERINARIO LA MORALEJA, S.L.HOSPITAL VETERINARIO LA MORALEJA, S.L. was fined by the AEPD 5,000 EUR for sending unsolicited commercial communications by electronic means. The authority found that recipients were not given an option to object to receiving such messages.ESAEPDePrivacy€5,000
01 Jan 2022HOSPITAL POVISA, S.A.HOSPITAL POVISA, S.A. was fined by the AEPD 30,000 EUR for breaching data protection rules. The case concerned the improper inclusion of private health test results in a public health system, which violated the complainant’s privacy.ESAEPDGDPR€30,000
10 Mar 2020Hørsholm KommuneThe Danish DPA reported Gladsaxe and Hørsholm Municipalities to the police for inadequate data security measures. The court fined Hørsholm Municipality DKK 50,000 for failing to encrypt computers containing sensitive personal data, which led to a data breach.DKDatatilsynetGDPR€6,692
07 Dec 2023Hora Credit IFN SAThe authority fined Hora Credit IFN SA for sending documents containing another client's personal data to the complainant's email address. The incident indicates a breach of confidentiality and proper personal data processing requirements.ROANSPDCPGDPR€2,000
07 Dec 2023Hora Credit IFN SAThe authority fined Hora Credit IFN SA for sending documents containing another client's personal data to the complainant's email address. The incident indicates a breach of confidentiality and proper personal data processing requirements.ROANSPDCPGDPR€20,000
07 Dec 2023Hora Credit IFN SAThe authority fined Hora Credit IFN SA for sending documents containing another client's personal data to the complainant's email address. The incident indicates a breach of confidentiality and proper personal data processing requirements.ROANSPDCPGDPR€2,000
28 Aug 2025Home Improvement Marketing LtdHome Improvement Marketing Ltd was investigated by the ICO as part of a wider review of complaint trends in the energy and home improvements sector. After a search warrant and extensive investigation, the ICO found that between 31 May 2023 and 31 August 2023 the company initiated 2,449,380 automated marketing calls to subscribers without prior consent, contrary to PECR. The conduct generated 274 complaints to the TPS and ICO reporting tools.GBICOePrivacy€347,000
20 Apr 2023HOLALUZ-CLIDOM, S.A.HOLALUZ-CLIDOM, S.A. was fined EUR 70,000 by the AEPD for processing personal data without consent. The company registered energy supplies for properties without the owner's consent, which breached Article 6(1) GDPR.ESAEPDGDPR€70,000
10 Oct 2023Hogeschool van Arnhem en Nijmegen (HAN)The Autoriteit Persoonsgegevens imposed a fine of EUR 175,000 on Hogeschool van Arnhem en Nijmegen (HAN). The authority found that the institution did not provide sufficient protection for students’ personal data.NLAutoriteit PersoonsgegevensGDPR€175,000
01 Feb 2024HOGAR LUZ Y GAS S.L.HOGAR LUZ Y GAS S.L. was fined EUR 4,000 by the Spanish Data Protection Agency (AEPD). The case concerned the failure to provide requested information, which breaches Article 58.1 of the GDPR.ESAEPDGDPR€4,000
27 Jul 2011HN LOGISTICA FERIAL EVENTOS Y CONGRESOS S.L.HN LOGISTICA FERIAL EVENTOS Y CONGRESOS S.L. was fined by the AEPD 600 EUR for sending unsolicited commercial emails without recipient consent. The conduct breached Article 21 of the LSSI.ESAEPDePrivacy€600
03 Apr 2023HM HOSPITALES 1989, S.A.HM HOSPITALES 1989, S.A. was fined EUR 200,000 by the AEPD for insufficient security measures in its hospital information system. The authority found a breach of Article 32 GDPR, which requires appropriate technical and organizational safeguards.ESAEPDGDPR€200,000