Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-22.5%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
11 Sept 2025COMMUNE (procédure simplifiée)CNIL imposed an administrative fine of EUR 10,000 on COMMUNE under a simplified procedure and issued a warning. The case concerns a breach of rules requiring supervisory intervention.FRCNILGDPR€10,000
29 May 2026Unicredit Bank SAUnicredit Bank SA was fined EUR 10,000 by ANSPDCP for violating GDPR provisions. The case concerns non-compliance with personal data protection requirements and should be considered in compliance risk assessments.ROANSPDCPGDPR€10,000
14 Mar 2019Comune di Porto Sant’ElpidioThe Garante fined Comune di Porto Sant’Elpidio EUR 10,000 for publishing documents on its website that contained personal data revealing the health status of individuals with disabilities. The authority found a breach of data protection rules.ITGaranteGDPR€10,000
11 May 2023Libra Internet Bank SALibra Internet Bank SA was fined EUR 10,000 by ANSPDCP for another breach of GDPR provisions. The case concerns non-compliance with personal data protection requirements.ROANSPDCPGDPR€10,000
31 May 2017Unit Contact s.r.l.Unit Contact s.r.l. was fined by the Garante EUR 10,000 for making unsolicited promotional calls to a number listed in the public opt-out register. The conduct breached data protection rules and telephone marketing requirements.ITGaranteGDPR€10,000
11 Sept 2025SOCIETE EXERCANT UNE ACTIVITE DE BANQUE ET ASSURANCE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 10,000 on SOCIETE EXERCANT UNE ACTIVITE DE BANQUE ET ASSURANCE. The case was handled under a simplified procedure.FRCNILGDPR€10,000
27 Dec 2023COMITE SOCIAL ECONOMIQUE D'ENTREPRISES (procédure simplifiée)The CNIL imposed an administrative fine of 10,000 EUR on COMITE SOCIAL ECONOMIQUE D'ENTREPRISES under a simplified procedure. The case concerns a confirmed regulatory breach, with no further details provided in the record.FRCNILGDPR€10,000
26 Oct 2023A.C. Group S.r.l.s.A.C. Group S.r.l.s. was fined by the Garante 10,000 EUR for making an unsolicited marketing call to a number listed in the Public Register of Objections without prior informed consent. The authority also found that the company failed to adequately respond to a data subject rights request.ITGaranteGDPR€10,000
13 Feb 2024LA VANGUARDIA EDICIONES, S.L.LA VANGUARDIA EDICIONES, S.L. was fined by the AEPD €10,000 for installing non-essential cookies on its website without obtaining valid user consent. The authority found this to be a breach of the LSSI.ESAEPDePrivacy€10,000
05 Oct 2017Qiu JunjieQiu Junjie was fined EUR 10,000 by the Garante for failing to protect video surveillance recordings with a password. The authority found this breached the minimum security measures required under the Italian Data Protection Code.ITGaranteGDPR€10,000
04 Apr 2024GAFAS EN RED DE ÓPTICAS, S.L.GAFAS EN RED DE ÓPTICAS, S.L. was fined €10,000 by the AEPD for sending unsolicited advertising SMS messages without providing an opt-out link. The conduct breached the LSSI rules governing electronic marketing communications.ESAEPDePrivacy€10,000
24 Oct 2019Anonymizováno (ÚOOÚ UOOU-01096/19-19)The entity was fined by the UOOU for sending commercial communications without a valid legal basis. The messages were not properly identified as commercial and the sender was not correctly identified.CZUOOUePrivacy€391
30 Apr 2025BITDEFENDER SRLIn April 2025, the Romanian authority ANSPDCP completed an investigation into BITDEFENDER SRL and found a GDPR violation. The company was fined EUR 10,000.ROANSPDCPGDPR€10,000
08 Mar 2012Comune di Marano PrincipatoThe Municipality of Marano Principato was fined by the Garante for processing personal data without appointing data processors and for failing to adopt minimum security measures. The authority found a breach of Article 33 of the Italian Privacy Code.ITGaranteGDPR€10,000
22 May 2018Ordinanza ingiunzione - 22 maggio 2018 [9027240]A general practitioner was fined for failing to adopt minimum security measures in a health information system. The deficiencies allowed unauthorized access to the data.ITGaranteGDPR€10,000
29 Jan 2020CASA GRACIO OPERATION, SLUCASA GRACIO OPERATION, SLU was fined by the AEPD 10,000 EUR for installing a video surveillance system that could capture public areas and access points. The authority found that this processing breached data protection rules.ESAEPDGDPR€10,000
28 Apr 2022Ministero della DifesaMinistero della Difesa was fined EUR 10,000 by the Garante for improperly disclosing personal data, including health-related information, to unauthorized personnel. The authority found a breach of the principles of lawfulness, fairness, and transparency.ITGaranteGDPR€10,000
15 Jan 2020Comune di Francavilla FontanaThe Municipality of Francavilla Fontana was fined 10,000 EUR by the Garante for publishing personal data on its institutional website. The conduct breached data protection rules and triggered supervisory action.ITGaranteGDPR€10,000
18 Jan 2024Dane anonimowe (przez Pana B.W. prowadzącego działalność gospodarczą pod firmą: B.)UODO imposed an administrative fine on B. for failing to notify the supervisory authority of a personal data breach without undue delay. The authority also found that the affected individuals were not informed of the breach without undue delay.PLUODOGDPR€2,251
04 Sept 2025Owner of the studentenkotenThe Belgian Data Protection Authority (GBA) imposed a total fine of EUR 9,700 on the owner of a student house. The case concerned the unlawful use of surveillance cameras inside and around the property to monitor students.BEGegevensbeschermingsautoriteit (GBA)GDPR€9,700