Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
31 Jul 2024Hangrögzítés telefonos ügyfélszolgálatonThe authority imposed a fine for breaching the GDPR principles of transparency and accountability. The entity did not adequately inform callers that customer service phone calls were being recorded.HUNAIHGDPR€2,530
08 Aug 2022Hangfelvétel készítése szerelési munkák soránThe authority found that the entity breached the GDPR by recording audio during installation work without a proper legal basis. It also failed to meet transparency and data protection principle requirements.HUNAIHGDPR€762
12 Mar 2026Hanako s.r.l.Hanako s.r.l. was fined by the Garante EUR 2,000 for operating a video surveillance system without ensuring GDPR compliance. The authority cited inadequate security measures and failure to provide sufficient information to employees.ITGaranteGDPR€2,000
01 Jul 2025HAMMERHOJ DESIGN, S.L.HAMMERHOJ DESIGN, S.L. was fined EUR 4,000 by the AEPD for publishing images of minors on Facebook without consent. The authority found this conduct to be in breach of Article 6(1) GDPR.ESAEPDGDPR€4,000
07 Jun 2021Hälso- och sjukvårdsnämnden Region StockholmHälso- och sjukvårdsnämnden Region Stockholm was fined by IMY for failing to inform callers to the 1177 service about the collection of phone numbers and communication IDs. The authority found a breach of GDPR transparency obligations.SEIMYGDPR€49,725
11 May 2020Hälso- och sjukvårdsnämnden i Region Örebro länHälso- och sjukvårdsnämnden i Region Örebro län was fined by IMY 120,000 SEK for publishing sensitive personal data on its website without a legal basis. The authority found breaches of GDPR Articles 5, 6, 9, and 32.SEIMYGDPR€11,321
17 Jan 2023Hälso- och sjukvårdsnämnden i Region DalarnaHälso- och sjukvårdsnämnden i Region Dalarna was fined by IMY for failing to implement appropriate technical and organizational measures to ensure an adequate level of security when sending physical appointment letters. The authority found this did not meet the requirements of Article 32 GDPR.SEIMYGDPRkr 200,000
19 Mar 2026HafnarfjarðarbærHafnarfjarðarbær was fined for using Google Workspace for Education in schools without full compliance with data protection rules. The authority cited unclear processing purposes and delayed data protection impact assessments.ISPersónuverndGDPR€19,516
26 Oct 2011H3G S.p.A.H3G S.p.A. was fined EUR 120,000 by the Garante for sending unsolicited promotional communications to a fixed telephone line. The conduct breached data protection provisions.ITGaranteGDPR€120,000
12 Jun 2014H3g s.p.a.H3g s.p.a. was fined EUR 75,000 by the Garante for violations related to customer profiling without the required consent. The case concerned personal data processing that did not comply with data protection requirements.ITGaranteGDPR€75,000
20 Aug 2019Gymnasienämnden i Skellefteå kommunGymnasienämnden i Skellefteå kommun was fined by IMY for using facial recognition to record student attendance. The authority found that the processing was more intrusive than necessary and lacked a valid exception for biometric data.SEIMYGDPR€18,578
22 Jun 2022Gyldendal A/SGyldendal A/S was fined 1,000,000 DKK by Datatilsynet for retaining data of 685,000 book club members longer than necessary. The authority found a breach of data retention principles.DKDatatilsynetGDPR€134,000
29 Nov 2012G & W Invest s.r.l.G & W Invest s.r.l. was fined €30,000 by the Italian data protection authority, Garante. The case concerned processing biometric data without timely notification, in breach of the Italian Data Protection Code.ITGaranteGDPR€30,000
11 Sept 2025G.Villa S.r.l.G.Villa S.r.l. was fined by the Garante EUR 22,500 for sending unsolicited promotional emails to an address not disclosed for marketing purposes. The company also failed to respond to the data subject's request for access to and deletion of personal data.ITGaranteGDPR€22,500
21 Sept 2022GUUDJOB WORLDWIDE S.L.GUUDJOB WORLDWIDE S.L. failed to delete personal data after a data subject request, breaching GDPR Articles 12 and 17. The AEPD imposed a fine of EUR 1,000, reduced to EUR 800 for early payment.ESAEPDGDPR€1,000
04 Apr 2013Gustavo CapizziGustavo Capizzi was fined €6,000 by the Garante for failing to provide the required data protection notice. The breach concerned a video surveillance system at the association “La Petit Nuit”.ITGaranteGDPR€6,000
30 Jan 2025Guru Nanak s.r.l.s.Guru Nanak s.r.l.s. was fined by the Garante EUR 1,000 for the non-compliant installation of a video surveillance system. The cameras captured areas beyond the company’s premises, creating a privacy and data protection breach.ITGaranteGDPR€1,000
09 Dec 2020Guldborgsund KommuneGuldborgsund Kommune was fined 50,000 DKK by Datatilsynet for a data breach. Sensitive information was mistakenly sent to an unauthorized recipient, causing significant consequences for the affected individuals.DKDatatilsynetGDPR€6,718
02 Jul 2020GTL s.r.l.GTL s.r.l. was fined EUR 3,000 by the Garante for failing to respond to an individual's data access request. The authority treated this as a breach of GDPR obligations.ITGaranteGDPR€3,000
29 May 2008G. & T. Design Comunication s.r.l.G. & T. Design Comunication s.r.l. was fined €4,000 by the Garante for failing to provide the requested information on the acquisition and processing of an email address. The authority treated this as a breach of data protection requirements.ITGaranteGDPR€4,000