Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-22.5%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
27 Jun 2023A.I.C. ehf.A.I.C. ehf. was fined by Persónuvernd 3,500,000 ISK for registering loan defaults with Creditinfo Lánstraust hf. without meeting the required registration conditions. The case also involved defaults on loans below the minimum threshold for registration.ISPersónuverndGDPR€23,520
08 Mar 2022Harpa tónlistar- og ráðstefnuhús ohf.Harpa tónlistar- og ráðstefnuhús ohf. was fined by Persónuvernd for collecting personal identification numbers and birth dates without necessity. The authority found breaches of GDPR principles of lawfulness, fairness, transparency, and data minimization.ISPersónuverndGDPR€6,850
20 Mar 2024Stjarnan ehf.Stjarnan ehf., operating Subway in Iceland, was fined by Persónuvernd for unlawful electronic surveillance of employees. The authority found that employees were not properly notified and were not adequately informed about their rights.ISPersónuverndGDPR€10,095
19 Mar 2026KópavogsbærKópavogsbær was fined by Persónuvernd for using Google Workspace for Education in schools without full compliance with data protection rules. The authority cited, among other issues, the absence of a data protection impact assessment and unclear processing purposes.ISPersónuverndGDPR€20,910
27 Jun 2023Creditinfo Lánstraust hf.Creditinfo Lánstraust hf. was fined by Persónuvernd for recording loan default information without meeting the required registration conditions. The authority found breaches of GDPR transparency and lawfulness requirements in the processing of personal data.ISPersónuverndGDPR€254,000
03 May 2022ReykjavíkurborgReykjavíkurborg was fined ISK 5,000,000 by Persónuvernd for using the Seesaw student system in schools without adequate data protection measures. The case concerned children’s personal data and transfers of data to the United States.ISPersónuverndGDPR€36,350
15 Jun 2021Huppuís ehf.Huppuís ehf. was fined 5,000,000 ISK by Persónuvernd for unlawful electronic surveillance in an ice cream shop. The authority found breaches of transparency and proportionality requirements and noted that employees, including minors, were not informed about the surveillance.ISPersónuverndGDPR€33,950
17 Feb 2025Heilsugæsla höfuðborgarsvæðisinsHeilsugæsla höfuðborgarsvæðisins was fined ISK 5,000,000 by Persónuvernd. The authority found that the organization unlawfully merged its medical records system with those of other entities, breaching GDPR requirements on lawful data processing.ISPersónuverndGDPR€34,050
17 Oct 2023Íþrótta- og sýningahöllin hf.Íþrótta- og sýningahöllin hf. was fined by Persónuvernd 3,500,000 ISK for unlawful electronic surveillance at Laugardalshöll. The case involved processing sensitive personal data without proper authorization, including data relating to children.ISPersónuverndGDPR€23,905
27 Jun 2023embætti landlæknisThe Icelandic DPA fined embætti landlæknis 12,000,000 ISK for security weaknesses in the Heilsuvera website. The flaw allowed unauthorized access to personal data, indicating a failure to maintain adequate safeguards.ISPersónuverndGDPR€80,640
27 Jun 2023eCommerce 2020 ApSeCommerce 2020 ApS was fined by Persónuvernd in the amount of 7,500,000 ISK for registering loan defaults with Creditinfo Lánstrausti hf. without meeting the required conditions. The authority noted, among other issues, that claims below the minimum threshold were registered. The case concerns improper handling of debt-related personal data.ISPersónuverndGDPR€50,400
03 May 2022HEI – Medical TravelHEI – Medical Travel was fined ISK 1,500,000 by Persónuvernd for unlawfully collecting, recording, storing, and using email addresses without consent. The company also mishandled an access request by deleting personal data after the request had been made.ISPersónuverndGDPR€10,905
19 Mar 2026ReykjavíkurborgReykjavíkurborg was fined by Persónuvernd for using Google Workspace for Education in schools without meeting GDPR requirements. The case concerned the processing of children's personal data, which required heightened compliance and safeguards.ISPersónuverndGDPR€13,940
14 Nov 2024Comune di MaddaloniThe Garante fined Comune di Maddaloni EUR 2,000 for failing to communicate the Data Protection Officer’s contact details to the Authority. This constituted a breach of Article 37(7) GDPR.ITGaranteGDPR€2,000
13 May 2015Iperal S.p.A.Iperal S.p.A. was fined EUR 40,000 by the Garante for activating 11 phone cards in the names of 5 individuals without their knowledge. The conduct breached data protection rules.ITGaranteGDPR€40,000
27 Oct 2016Studio Medico Odontoiatrico Associato Gimmelli B. & G.Studio Medico Odontoiatrico Associato Gimmelli B. & G. was fined by the Garante for unlawfully processing personal data by disclosing it to Ina Assitalia s.p.a. without obtaining the required informed consent from the data subject. The case reflects a breach of core lawful-processing requirements.ITGaranteGDPR€6,400
25 Mar 2021Centro diagnostico italiano di MilanoThe Italian Data Protection Authority imposed a fine of EUR 50,000 on Centro diagnostico italiano di Milano. The sanction concerned violations of data protection rules.ITGaranteGDPR€50,000
06 Oct 2022Poste Italiane S.p.a.Poste Italiane S.p.a. was fined 10,000 EUR by the Garante. The authority found a breach of Article 15 GDPR due to failure to respond to a data access request.ITGaranteGDPR€10,000
12 Mar 2026Enel Energia S.p.A.Enel Energia S.p.A. was fined by the Italian data protection authority, Garante, for making unwanted telemarketing calls without a proper legal basis. The authority found that the company’s conduct breached data protection principles.ITGaranteGDPR€563,000
21 Mar 2024Azienda sanitaria locale Roma 3The Garante fined Azienda sanitaria locale Roma 3 10,000 EUR for failing to adequately protect personal data. The breach led to attempted unauthorized access to user accounts and indicated insufficient cybersecurity controls.ITGaranteGDPR€10,000