Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-22.8%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
06 Jul 2006Filippi Giovanni & C. s.n.c.Filippi Giovanni & C. s.n.c. was fined 1,549 EUR by the Garante. The authority found that personal data were processed to send commercial messages without proper disclosure required under data protection law.ITGaranteGDPR€1,549
19 Aug 2022Fidesz-Magyar Polgári SzövetségFidesz-Magyar Polgári Szövetség was fined by NAIH 300,000 HUF for unlawfully processing personal data, including phone numbers, without a legal basis. The authority also found violations of the rights to erasure and access, as well as inadequate information provided during phone campaigns.HUNAIHGDPR€735
18 Feb 2010Fibrille s.r.l.Fibrille s.r.l. was fined EUR 6,000 by the Garante for processing personal data from job applicants' CVs without providing the required information. The authority found a breach of the notice obligation under Article 13 of the Italian Data Protection Code.ITGaranteGDPR€6,000
24 Oct 2023FIBRA ÓPTICA MÁLAGA, S.L.FIBRA ÓPTICA MÁLAGA, S.L. changed a customer's contact email and bank account details without consent. The AEPD found a breach of GDPR Article 6(1) and imposed a 70,000 EUR fine.ESAEPDGDPR€70,000
29 Aug 2025FIATC MUTUA DE SEGUROS Y REASEGUROSFIATC Mutua de Seguros y Reaseguros was fined €40,000 by the AEPD after unauthorized access to its systems. The incident may have exposed personal data, including DNI/CIF, and the authority found inadequate security measures and a breach of Article 5(1)(f) GDPR.ESAEPDGDPR€40,000
01 Jan 2015FEVER LABS INCFEVER LABS INC was fined EUR 10,000 by the AEPD for sending unsolicited commercial emails. The authority found that the messages did not include a simple and free way for recipients to opt out of further communications, in breach of the LSSI.ESAEPDePrivacy€10,000
28 Jun 2023FESTINA LOTUS S.A.FESTINA LOTUS S.A. did not respond to requests to delete a user's account and personal data. The authority found a breach of Article 17 GDPR and imposed a fine of EUR 1,000.ESAEPDGDPR€1,000
11 Dec 2014Ferreri Costruzioni s.r.l.Ferreri Costruzioni s.r.l. was fined EUR 2,400 by the Garante for failing to provide data subjects with the required information about data processing through web forms on its website. The conduct breached Article 13 of the Italian Privacy Code.ITGaranteGDPR€2,400
22 Oct 2015Ferrara AdrianoFerrara Adriano was fined EUR 2,400 by the Garante. The authority found that the company used a video surveillance system without adequate notices for the individuals being recorded, in breach of data protection rules.ITGaranteGDPR€2,400
01 Jan 2016FERIA MUESTRARIO INTERNACIONAL DE VALENCIAThe entity collected personal data from children under 14 without providing the required information or obtaining parental consent. The AEPD found this to be a breach of data protection rules.ESAEPDePrivacy€8,000
21 May 2019Ferencvárosi Szociális és Gyermekjóléti Intézmények IgazgatóságaThe Ferencvárosi Social and Child Welfare Institutions Directorate was fined for failing to report a personal data breach within the required deadline. The incident involved documents sent to the wrong address, triggering the notification duty under GDPR Article 33.HUNAIHGDPR€306
06 May 2021Ferde ASThe Norwegian DPA notified Ferde AS of a NOK 5 million fine for unlawfully transferring personal data of Norwegian motorists to China without a valid legal basis. The case concerns non-compliant processing and cross-border transfer of personal data outside the EEA.NODatatilsynetGDPR€497,000
06 Nov 2014Fengfeng WuFengfeng Wu was fined by the Garante in the amount of EUR 2,400 for failing to provide data subjects with the required information about the processing of personal data through a video surveillance system at Bar Wu Fengfeng in Milan. The case concerns a breach of transparency and information obligations linked to CCTV processing.ITGaranteGDPR€2,400
01 Jan 2025FEMXA FORMACIÓN, S.L.FEMXA FORMACIÓN, S.L. was fined by the AEPD 25,000 EUR for requiring a full copy of a student's ID during course enrollment. The authority found the data request unnecessary and inconsistent with data protection principles.ESAEPDGDPR€25,000
14 May 2026FeGi M&A Services s.r.l.FeGi M&A Services s.r.l. was fined EUR 1,000 by the Garante for making promotional phone calls without the required consent. The authority found this conduct breached GDPR principles of fairness and transparency.ITGaranteGDPR€1,000
13 Nov 2024FederprivacyFederprivacy was fined EUR 6,000 by the Garante after a data breach caused by a cyberattack. The attack compromised the website, email accounts, and social media, indicating inadequate technical and organizational measures.ITGaranteGDPR€6,000
29 Apr 2021FederpolFederpol was fined 5,000 EUR by the Garante for improperly sharing members’ personal information with other associates. The authority found that this breached data protection rules and required a valid legal basis and appropriate safeguards.ITGaranteGDPR€5,000
21 Jan 2016Federico FabiFederico Fabi was fined by the Garante for failing to provide the required information to data subjects when collecting personal data through forms on the company’s website. The case concerns a breach of transparency and notice obligations under data protection rules.ITGaranteGDPR€2,400
24 Feb 2011Federconsorzi Dolomiti SuperskiFederconsorzi Dolomiti Superski was fined EUR 12,000 by the Italian Garante. The authority found that the company failed to provide the required data protection information to individuals, in breach of Articles 13 and 161 of the Italian Data Protection Code.ITGaranteGDPR€12,000
17 Jul 2025Federazione Italiana Sport EquestriThe Italian Data Protection Authority imposed a EUR 10,000 fine on Federazione Italiana Sport Equestri for publishing a disciplinary decision involving a minor on its website without anonymizing personal data. The breach concerned data protection rules and the disclosure of information that could identify the minor.ITGaranteGDPR€10,000