Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-22.5%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
10 Mar 2022Agenzia Regionale per la Tutela dell'Ambiente dell'AbruzzoThe Regional Agency for Environmental Protection of Abruzzo was fined by the Garante €8,000 for breaches of data protection principles. The violations concerned lawfulness, fairness, transparency, and data minimization.ITGaranteGDPR€8,000
07 Dec 2023Azienda OspedalieraAzienda Ospedaliera was fined EUR 8,000 by the Garante for breaches of data protection rules. The case concerned data processing principles and insufficient security measures.ITGaranteGDPR€8,000
28 Mar 2019Comune di GenovaComune di Genova was fined for unlawfully communicating personal data to third-party companies without a proper legal basis. The authority found a breach of data protection rules.ITGaranteGDPR€8,000
14 Jun 2018Osimo Servizi s.p.a.Osimo Servizi s.p.a. was fined EUR 8,000 by the Garante. The breach concerned the failure to notify the processing of biometric data used in an employee attendance system.ITGaranteGDPR€8,000
20 Aug 2024HEBERGEUR DE SITE WEB (procédure simplifiée)The CNIL imposed an administrative fine of 8,000 EUR on HEBERGEUR DE SITE WEB under a simplified procedure. The decision concerns a confirmed breach of rules supervised by the CNIL.FRCNILGDPR€8,000
14 Nov 2019ASL n. 2 SavoneseASL n. 2 Savonese was fined EUR 8,000 by the Garante for breaches of data protection principles. The authority found improper processing of personal data, including failures to comply with lawfulness, fairness, transparency, and data minimization.ITGaranteGDPR€8,000
19 Dec 2024SOCIETE ASSURANT DES ACTIVITES DE SECURITE PRIVE, PROTECTION RAPPROCHEE, HOTESSARIAT ET GESTION LOGISTIQUE (procédure simplifiée)CNIL imposed an administrative fine of EUR 8,000 on SOCIETE ASSURANT DES ACTIVITES DE SECURITE PRIVE, PROTECTION RAPPROCHEE, HOTESSARIAT ET GESTION LOGISTIQUE under a simplified procedure. The record indicates a regulatory breach, but no further details were provided.FRCNILGDPR€8,000
18 Feb 2016Europa Investigazioni s.r.lEuropa Investigazioni s.r.l was fined EUR 8,000 by the Garante. The authority found that the company failed to notify the processing of data indicating the geographical position of individuals or objects via an electronic communications network.ITGaranteGDPR€8,000
31 Aug 2023Ordine degli Avvocati di XXThe Garante fined the Ordine degli Avvocati di XX EUR 8,000 for unlawfully disclosing personal data without a legal basis. The authority found breaches of the principles of lawfulness, fairness, and transparency.ITGaranteGDPR€8,000
30 Apr 2026Dane anonimowe (Burmistrza Miasta i Gminy D.)UODO imposed an administrative fine of 7,700 PLN on Anonymous data (Mayor of D. Municipality). The sanction resulted from failing to notify the President of the Personal Data Protection Office of a personal data breach without undue delay, and no later than 72 hours after becoming aware of it.PLUODOGDPR€1,807
23 Oct 2025Dane anonimowe (Komornika Sądowego przy Sądzie Rejonowym w S. B. F. Kancelaria)The President of UODO imposed an administrative fine on the bailiff’s office for failing to report a personal data breach within the required 72 hours. The authority also found that the affected individual was not notified without undue delay after the data was disclosed to an unauthorized recipient.PLUODOGDPR€1,819
11 Jun 2021Anonymisé (CNPD decision-21-fr-2021)The company did not comply with the data minimization principle and failed to adequately inform employees and third parties about data processing activities. CNPD found these practices to breach GDPR Articles 5(1)(c) and 13.LUCNPDGDPR€7,600
25 Nov 2025Dane anonimowe (D. C., prowadzącego działalność gospodarczą pod firmą W.)UODO imposed a fine of PLN 7,577 on an anonymous entrepreneur for failing to implement adequate technical and organizational measures to secure data processing. The authority also found that processing was not properly limited to the controller’s instructions and that no record of processing activities was maintained.PLUODOGDPR€1,794
13 Jan 2022Azienda Sanitaria Locale FrosinoneAzienda Sanitaria Locale Frosinone was fined by the Italian supervisory authority, Garante, in the amount of EUR 7,500. The case concerned breaches of transparency and information duties in personal data processing under GDPR Articles 12 and 13.ITGaranteGDPR€7,500
31 May 2024CUMACA MOTOR, S.L.CUMACA MOTOR, S.L. was fined EUR 7,500 by the AEPD for requiring customers to provide a copy of their identity document without a valid justification. The authority found that this breached the GDPR data minimization principle.ESAEPDGDPR€7,500
08 Aug 2014INFOASSIST A.E.INFOASSIST A.E. was fined by the HDPA 7,500 EUR for processing personal data without consent. The authority found breaches of legality and data minimization principles.GRHDPAGDPR€7,500
08 Aug 2014Hummingbird EPEHummingbird EPE was fined by the HDPA for processing publicly available personal data without the consent of the data subjects. The authority found a breach of the principles of data relevance and proportionality.GRHDPAGDPR€7,500
06 Mar 2024The Central Young Men’s Christian AssociationThe Central YMCA sent an email to participants in a programme for people living with HIV using “CC” instead of “BCC”, which exposed recipients’ email addresses to all recipients. From those addresses, 166 individuals could be identified or potentially identified, allowing an inference that they were likely living with HIV. The ICO imposed a £7,500 fine and issued a reprimand.GBICOGDPR€8,772
11 May 2021Stichting Ondersteuning Provinciale Fractie Overijssel Partij voor de Vrijheid (PVV Overijssel)PVV Overijssel was fined by the AP EUR 7,500 for failing to report a personal data breach within the required 72-hour period. The case concerns a delayed notification to the supervisory authority about a security incident.NLAPGDPR€7,500
17 Jul 2025Perla Odontoiatria Veneta S.r.l.The Garante fined Perla Odontoiatria Veneta S.r.l. EUR 7,500 for failing to meet information and transparency obligations in the processing of health data. The authority cited breaches of GDPR Articles 5, 9, and 15.ITGaranteGDPR€7,500