Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
01 Aug 2025Dr. Max SRLANSPDCP fined Dr. Max SRL EUR 1,000 after an investigation concluded in August 2025. The authority found breaches of GDPR Articles 12 and 17, including failure to respond to a deletion request and unlawful retention of an identity card copy without consent.ROAutoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter PersonalGDPR€1,000
05 Nov 2020DR MARÍN CIRUGIA PLÁSTICA, S.L.P.DR MARÍN CIRUGIA PLÁSTICA, S.L.P. was fined EUR 4,000 by the AEPD. The authority found that the company failed to provide a privacy policy on its website and used personal data for marketing purposes without consent.ESAEPDePrivacy€4,000
06 Jun 2024Drivalia Leasys Rent S.p.A.Drivalia Leasys Rent S.p.A. was fined by Garante 250,000 EUR for denying a car rental voucher to a customer listed on a blacklist. The authority found insufficient transparency in data processing and a lack of proper legal basis and consent under GDPR.ITGaranteGDPR€250,000
09 Jul 2020dr. Hadházy Ákos ÁnyosThe controller processed personal data without a legal basis and did not provide adequate information about the processing linked to a petition concerning accession to the European Public Prosecutor's Office. The case indicates breaches of core transparency and lawfulness obligations.HUNAIHGDPR€2,820
01 Jan 2014DREAM RING, S.L.DREAM RING, S.L. was fined by the AEPD EUR 6,000 for sending unsolicited commercial SMS messages. The conduct breached Article 21 of the LSSI, which restricts marketing communications without prior recipient consent.ESAEPDePrivacy€6,000
20 Sept 2023DREAM HOUSE SISTEMAS DE DESCANSO, S.L.DREAM HOUSE SISTEMAS DE DESCANSO, S.L. was fined EUR 2,500 by the AEPD for sending unsolicited advertising SMS messages to a customer who had previously objected. The authority found this conduct breached Article 21 of the LSSI.ESAEPDePrivacy€2,500
21 Mar 2013dr. Attilio Vincenzo PignatelliDr. Attilio Vincenzo Pignatelli was fined by the Garante EUR 2,400 for operating a video surveillance system without the required simplified notice and for failing to comply with data retention rules. The case concerned non-compliance with information duties and retention periods for recorded footage.ITGaranteGDPR€2,400
06 Nov 2014Dragica LjubojevicDragica Ljubojevic was fined by the Garante in the amount of 2,400 EUR for failing to provide data subjects with the required information about the processing of personal data. The case concerned a video surveillance system at a private club.ITGaranteGDPR€2,400
25 Mar 2021Dragefossen ASDragefossen AS was fined 150,000 NOK by Datatilsynet for unlawfully live streaming surveillance footage from a camera in Rognan sentrum on the internet. The authority found no legal basis for the processing, which breached GDPR Articles 6 and 5.NODatatilsynetGDPR€14,756
06 May 2024DQG NORTE A.I.E.DQG NORTE A.I.E. was fined by the AEPD for collecting copies of identity documents and personal data of minors and their guardians without proper data protection information. The authority found breaches of GDPR data minimization and transparency principles.ESAEPDGDPR€5,000
14 Apr 2025DPP Law LtdThe UK Information Commissioner fined law firm DPP Law Ltd 60,000 GBP for breaches of Articles 5(1)(f), 32(1), 32(2) and 33(1) of the UK GDPR. The infringements occurred between 25 May 2018 and 17 July 2022. The case concerned inadequate security measures and incident reporting obligations.GBICOGDPR€69,456
05 Oct 2023DPP Law LtdThe Information Commissioner's Office issued a monetary penalty notice against DPP Law Ltd. The firm was fined GBP 60,000 for failing to implement appropriate technical and organisational measures to secure personal data.GBInformation Commissioner's OfficeGDPR€69,282
09 Nov 2023DPG Professional Services LtdBetween 3 August 2021 and 3 August 2022, DPG made 74,119 unsolicited calls for direct marketing purposes, breaching Reg 21 of PECR. The activity resulted in 13 complaints and came to the Commissioner’s attention through an operation focused on life insurance and later life planning marketing.GBICOePrivacy€103,000
24 Feb 2022DPG Media Magazines B.V.DPG Media Magazines B.V. was fined for obstructing data subjects’ access to and erasure of their personal data by imposing unnecessary barriers. The authority found this conduct breached Article 12(2) GDPR.NLAPGDPR€525,000
DPD PolskaThe President of the Personal Data Protection Office imposed an administrative fine of more than PLN 11 million on DPD Polska for GDPR violations. The authority cited the failure to conclude data processing agreements with external carriers and inadequate organizational measures to protect data security.PLPrezes Urzędu Ochrony Danych Osobowych€2,568,000
01 Jan 2020DOUGLAS SPAIN, S.A.U.DOUGLAS SPAIN, S.A.U. was fined by the AEPD 2,700 EUR for continuing to send advertising emails to a complainant after confirming deletion of the complainant’s personal data. The authority found this breached Article 21 of the LSSI.ESAEPDePrivacy€2,700
20 Oct 2022Douglas Italia S.p.A.Douglas Italia S.p.A. was fined by the Italian Garante in the amount of €1,400,000. The authority found inadequate responses to data subject requests and a lack of clear separation between the privacy policy and cookie policy in the app. The conduct breached multiple GDPR provisions.ITGaranteGDPR€1,400,000
29 Sept 2021dott.ssa Manuela MazzoliThe Garante imposed a fine of 2,000 EUR on dott.ssa Manuela Mazzoli for breaches of data protection rules. The case concerned the processing of personal data in the healthcare sector, including the principles of lawfulness, fairness, and transparency.ITGaranteGDPR€2,000
28 Oct 2021dott.ssa GiglioA doctor was fined for improperly handling personal data, including medical prescriptions. The authority found breaches of GDPR Articles 5, 9, and 32 on processing principles, special-category data, and security measures.ITGaranteGDPR€10,000
24 Nov 2022dott.ssa Emilia ColosimoThe Garante imposed a EUR 1,000 fine on dott.ssa Emilia Colosimo for breaches of the principles of lawful, fair and transparent processing of personal data, data minimization, and data security. The authority also cited insufficient safeguards against unauthorized or unlawful processing.ITGaranteGDPR€1,000