Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
13 May 2015HellastatHellastat was fined by the HDPA EUR 5,000 for the illegal collection and use of data. The case concerned a breach of data protection laws.GRHDPAGDPR€5,000
13 May 2015HellastatHellastat was fined EUR 3,000 by the HDPA for failing to inform data subjects. The authority found a breach of data protection rules requiring transparent notice to individuals.GRHDPAGDPR€3,000
03 May 2022HEI – Medical TravelHEI – Medical Travel was fined ISK 1,500,000 by Persónuvernd for unlawfully collecting, recording, storing, and using email addresses without consent. The company also mishandled an access request by deleting personal data after the request had been made.ISPersónuverndGDPR€10,905
17 Feb 2025Heilsugæsla höfuðborgarsvæðisinsHeilsugæsla höfuðborgarsvæðisins was fined ISK 5,000,000 by Persónuvernd. The authority found that the organization unlawfully merged its medical records system with those of other entities, breaching GDPR requirements on lawful data processing.ISPersónuverndGDPR€34,050
20 Aug 2024HEBERGEUR DE SITE WEB (procédure simplifiée)The CNIL imposed an administrative fine of 8,000 EUR on HEBERGEUR DE SITE WEB under a simplified procedure. The decision concerns a confirmed breach of rules supervised by the CNIL.FRCNILGDPR€8,000
23 Oct 2025Hearst Magazines Italia S.p.A.Hearst Magazines Italia S.p.A. was fined EUR 20,000 by the Garante for publishing personal data relating to an individual's health without a legal basis. The authority found a breach of the principles of lawfulness and fairness in processing.ITGaranteGDPR€20,000
09 May 2024HEADBLUE MARKETING, S.L.HEADBLUE MARKETING, S.L. was fined by the AEPD in the amount of 1,000 EUR for sending unsolicited commercial electronic communications without consent. The authority also found a failure to respond to access requests.ESAEPDePrivacy€1,000
15 Apr 2021HAZTEOIR.ORGThe association HazteOir.Org was fined EUR 5,000 by the AEPD for including images and names of individuals in a pamphlet without their consent. The authority found this to be a breach of data protection rules.ESAEPDGDPR€5,000
20 Dec 2022HAYS PERSONNEL SERVICE ESPAÑA, S.A.HAYS PERSONNEL SERVICE ESPAÑA, S.A. was fined by the AEPD 5,000 EUR for sending marketing emails without the recipient’s consent. The conduct breached Article 21 of the LSSI, which requires prior consent for such communications.ESAEPDePrivacy€5,000
12 Mar 2015Hayat KhizerHayat Khizer was fined EUR 3,000 by the Garante for improper registration of SIM cards. The cards were used by persons other than the formal registrants in connection with a criminal investigation into drug trafficking.ITGaranteGDPR€3,000
06 Sept 2023Háskóli ÍslandsThe University of Iceland was fined for inadequate signage and insufficient information about electronic surveillance on its premises. The authority found a breach of GDPR transparency and information obligations.ISPersónuverndGDPR€10,425
08 Mar 2022Harpa tónlistar- og ráðstefnuhús ohf.Harpa tónlistar- og ráðstefnuhús ohf. was fined by Persónuvernd for collecting personal identification numbers and birth dates without necessity. The authority found breaches of GDPR principles of lawfulness, fairness, transparency, and data minimization.ISPersónuverndGDPR€6,850
01 Jan 2016HAPPY SOCIAL MEDIA, LTDHAPPY SOCIAL MEDIA, LTD was fined by the AEPD EUR 3,400 for sending unsolicited marketing emails. The authority found that the messages did not include a simple opt-out mechanism, which breached the LSSI.ESAEPDePrivacy€3,400
25 Apr 2016HAPPY SOCIAL MEDIA LTDHAPPY SOCIAL MEDIA LTD was fined by the AEPD in the amount of 1,400 EUR. The case concerned unsolicited marketing emails sent without a simple opt-out mechanism, in breach of the LSSI.ESAEPDePrivacy€1,400
25 Apr 2016HAPPY SOCIAL MEDIA LTDHAPPY SOCIAL MEDIA LTD was fined EUR 1,400 by the AEPD. The case concerned sending unsolicited commercial emails without providing a simple and free opt-out mechanism, in breach of the LSSI.ESAEPDePrivacy€1,400
01 Jan 2017Happy Social Media LTD.Happy Social Media LTD. was fined by the AEPD EUR 2,000 for sending advertising emails to individuals who had opted out of receiving them. The case concerned Article 21.1 of the LSSI and the obligation to respect objections to marketing communications.ESAEPDePrivacy€2,000
02 Apr 2020HAPPY FRIDAY, S.L.HAPPY FRIDAY, S.L. was fined by the AEPD in the amount of 2,500 EUR for failing to comply with data protection rules on the use of cookies. The authority found that the company did not provide the required information or obtain user consent.ESAEPDePrivacy€2,500
11 Sept 2014Happy Fit s.r.l.Happy Fit s.r.l. was fined by the Garante in the amount of EUR 16,400 for making an unsolicited promotional phone call. The company did not provide the required information or obtain consent, breaching data protection rules.ITGaranteGDPR€16,400
17 Dec 2025HAN University of Applied SciencesThe Autoriteit Persoonsgegevens announced on 17 December 2025 that it had imposed a fine on HAN University of Applied Sciences. According to the notice, the university was hacked in September 2021, resulting in a data breach, and HAN will not object to the decision.NLAutoriteit PersoonsgegevensGDPR€100,000
04 Feb 2016Hans Christoph Josef DietrichHans Christoph Josef Dietrich was fined EUR 4,000 by the Garante. The case concerned the public display of a list of patients who had not paid for medical services, which amounted to unauthorized disclosure of personal data.ITGaranteGDPR€4,000