Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-22.8%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
23 Jan 2023FRESHLY COSMETICS, S.L.FRESHLY COSMETICS, S.L. was fined EUR 5,000 by the AEPD for failing to provide a cookie notice on its website. The authority also found that non-essential cookies were used without prior user consent, in breach of Article 22.2 of the LSSI.ESAEPDePrivacy€5,000
24 Apr 2013Free Time s.r.l.Free Time s.r.l. was fined EUR 54,000 by the Italian Garante. The case concerned the registration of numerous phone cards to unaware third parties without providing the required information on data processing.ITGaranteGDPR€54,000
24 Jul 2024FREE TECHNOLOGIES EXCOM, S.L.FREE TECHNOLOGIES EXCOM, S.L. was fined by the AEPD 10,000 EUR for sending unencrypted emails containing user credentials without prior notice. The authority also noted the absence of two-factor authentication, which constituted a breach of Article 32 GDPR.ESAEPDGDPR€10,000
13 Jan 2026Free Mobile and FreeFrance’s CNIL fined Free Mobile and Free a combined EUR 42 million for GDPR breaches linked to a 2024 data breach affecting more than 24 million users. The regulator found inadequate security measures and said Free Mobile unlawfully retained former subscribers’ data.FRCommission nationale de l’informatique et des libertésGDPR€42,000,000
16 Dec 2021Frederiksberg KommuneFrederiksberg Kommune was fined by Datatilsynet for failing to implement adequate security measures in a self-service solution. This led to unauthorized access to protected personal data.DKDatatilsynetGDPR€6,724
20 Mar 2008Frareg s.r.l.Frareg s.r.l. was fined by the Garante for sending advertising material by fax without providing prior and adequate information to recipients. The authority found this to be a breach of data protection rules.ITGaranteGDPR€3,000
23 Oct 2025Franco SpellecchiaFranco Spellecchia was fined by the Garante for installing a video surveillance system around his residence without the required legal basis. The authority found that the setup breached GDPR rules, including the absence of a legitimate interest or authorization.ITGaranteGDPR€500
20 Mar 2014Franco Oro più srlFranco Oro più srl was fined EUR 4,800 by the Italian Garante. The case concerned the failure to provide the required data protection information on both a paper form and the company website, in breach of the Italian Data Protection Code.ITGaranteGDPR€4,800
16 Oct 2013FRANCE TELECOM ESPAÑA, S.A.FRANCE TELECOM ESPAÑA, S.A. was fined by the AEPD for sending commercial emails to a complainant despite a request not to use personal data for advertising purposes. The authority found a breach of Article 21.1 of the LSSI.ESAEPDePrivacy€33,001
22 Jan 2015Francesco Saverio ManesFrancesco Saverio Manes was fined by the Garante EUR 2,400 for failing to provide data subjects with the required information about the processing of personal data through a video surveillance system at the cultural club “K2”. The case concerned the absence of mandatory notices for individuals captured by the CCTV system.ITGaranteGDPR€2,400
17 Apr 2026Framos Italia s.r.l. in liquidazioneFramos Italia s.r.l. in liquidation was fined EUR 5,000 by the Garante. The authority found that former employees’ email accounts were not deactivated and that information on data processing was not clear and comprehensive.ITGaranteGDPR€5,000
04 Mar 2020Fotó készítése és közzététele Facebookon hozzájárulás nélkülThe authority found unlawful processing and publication of personal data without a valid legal basis. A fine was imposed and the image had to be deleted from Facebook.HUNAIHGDPR€299
23 Nov 2017Foschini Mauro e Banca Nazionale del Lavoro S.p.A.Foschini Mauro and Banca Nazionale del Lavoro S.p.A. were fined by the Garante 4,000 EUR for breaches of data protection rules. The case concerned non-compliance with provisions of the Italian Privacy Code.ITGaranteGDPR€4,000
03 Oct 2013Forum Sport Center società sportiva dilettantistica S.r.l.Forum Sport Center società sportiva dilettantistica S.r.l. was fined by the Italian Garante in the amount of €8,400. The sanction concerned inadequate data protection notices for personal data collection and video surveillance systems.ITGaranteGDPR€8,400
21 Feb 2013Forum Media Edizioni s.r.l.Forum Media Edizioni s.r.l. was fined by the Italian Garante in the amount of €6,400. The case concerned the sending of unsolicited promotional faxes without the required information and without obtaining consent, in breach of Articles 13 and 130 of the Italian Data Protection Code.ITGaranteGDPR€6,400
28 Jun 2023Fortis Insolvency LimitedFortis Insolvency Limited sent 558,354 direct marketing SMS messages without valid consent, of which 527,481 were received by subscribers between 26 July 2020 and 26 July 2021. This breached regulation 22 of PECR. The company was fined £30,000 and issued with an enforcement notice.GBICOePrivacy€34,713
28 Oct 2022FORMAESTUDIO, C.B.FORMAESTUDIO, C.B. was fined €6,000 by the AEPD for requiring students to disclose their COVID vaccination status and present a passport as a condition for participating in teaching practice. The authority found that this processing breached data protection rules.ESAEPDGDPR€6,000
07 Aug 2023FORMACIÓN Y EMPLEO DE EXTREMADURA, S.L.The company sent emails to multiple recipients without using BCC, allowing each recipient to see the other recipients’ email addresses. AEPD treated this as a breach of data protection rules and imposed an 8,000 EUR fine.ESAEPDGDPR€8,000
29 Jun 2023FORKMERGE S.L.FORKMERGE S.L. was fined by the AEPD EUR 2,000 for failing to comply with a data subject’s request to remove personal data from search engine results. The authority found this to be a breach of Article 17 GDPR.ESAEPDGDPR€2,000
10 Jun 2021Foodinho s.r.l.Foodinho s.r.l. was fined by the Garante EUR 2,600,000 for violations in the processing of riders’ personal data. The authority cited insufficient data minimization, inadequate privacy by design measures, and automated decision-making without proper human intervention.ITGaranteGDPR€2,600,000