Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-22.5%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
21 Dec 2023Azienda socio-sanitaria localeThe Garante imposed a fine on a local health authority for violations related to the handling of sensitive personal data. The case concerned improper processing of special-category data, which breached data protection rules.ITGaranteGDPR€18,000
24 Jun 2025BirthlinkThe UK Information Commissioner’s Office (ICO) fined Scottish charity Birthlink GBP 18,000. The case involved the destruction of about 4,800 personal records, up to 10% of which may have been irreplaceable.GBICOGDPR€21,109
18 May 2023AUTOMOBILE BAVARIA SRLThe fine was imposed for the unauthorized disclosure of personal data of 290 clients and potential clients, which were publicly accessible on the operator's website. The case concerns a breach of data protection rules through disclosure without an appropriate legal basis or safeguards.ROANSPDCPGDPR€18,000
16 Sept 2021Azienda sanitaria provinciale di CosenzaAzienda sanitaria provinciale di Cosenza was fined by the Garante for unlawfully publishing health data on its institutional website. The case involved breaches of data protection principles and required security measures for sensitive data.ITGaranteGDPR€18,000
10 Apr 2025Provvedimento del 10 aprile 2025 [10144184]A healthcare organization was fined after an employee accessed a patient's health dossier without authorization. The case highlights a breach of data protection rules in the healthcare sector.ITGaranteGDPR€18,000
14 Jan 2021Azienda Usl di BolognaAzienda Usl di Bologna was fined by the Garante 18,000 EUR for violations related to personal data protection in the healthcare sector. The case concerned irregularities in the processing of patient data, which breached data protection requirements.ITGaranteGDPR€18,000
11 Sept 2025Comune di NichelinoComune di Nichelino was fined EUR 18,000 by the Garante for failing to provide an adequate response to a data subject's request to exercise their rights. The authority found breaches of lawfulness, fairness, transparency, and data minimization.ITGaranteGDPR€18,000
16 Nov 2023Provvedimento del 16 novembre 2023 [9960948]The Garante imposed an EUR 18,000 fine on a training company for the unauthorized online publication of personal data relating to health. The case concerned breaches of GDPR Articles 5 and 32 on data processing principles and security.ITGaranteGDPR€18,000
12 Dec 2024SOCIETE DE VENTE AU DETAIL (procédure simplifiée)The CNIL imposed an administrative fine of EUR 18,000 on SOCIETE DE VENTE AU DETAIL under a simplified procedure. The decision concerns a breach of rules within the CNIL's remit.FRCNILGDPR€18,000
31 Dec 2021Dane anonimowe (S. Spółka z o.o. z siedzibą w W. przy ul.)The President of UODO imposed an administrative fine of PLN 18,192 on the company. The sanction resulted from failing to provide access to personal data and other information necessary for the authority to perform its duties.PLUODOGDPR€3,957
01 Dec 2021Dane anonimowe (P. Sp. z o.o. z siedzibą we W. przy ul.)The UODO imposed an administrative fine of PLN 18,192 on P. Sp. z o.o. The case concerned a breach of applicable rules that resulted in an administrative sanction.PLUODOGDPR€3,931
25 Jan 2023Dane anonimowe (S. Sp. z o.o. z siedzibą w R. przy ul.)The President of UODO imposed an administrative fine of PLN 18,279 on the company. The sanction was issued for failing to cooperate with the authority and for not providing information necessary for the performance of its duties.PLUODOGDPR€3,876
07 Feb 2013Società delle terme s.p.a.Società delle terme s.p.a. was fined by the Garante 18,400 EUR for providing inadequate information when collecting personal data and for obtaining invalid consent. The authority found violations of Articles 13 and 23 of the Italian Data Protection Code.ITGaranteGDPR€18,400
03 Jun 2010ICTS Italia s.r.l.ICTS Italia s.r.l. was fined by the Garante for using a biometric system for employee access control and attendance without adequate notice, consent, or minimum security measures. The company also failed to notify the Garante.ITGaranteGDPR€18,400
27 Oct 2021Anonymisé (CNPD decision-41-fr-2021)The CNPD imposed a fine of 18,700 EUR on Anonymisé for improper implementation of Data Protection Officer obligations. The company did not publish the DPO’s contact details, did not involve the DPO in all data protection matters, did not ensure the DPO’s autonomy, and did not assign monitoring of GDPR compliance.LUCNPDGDPR€18,700
21 Dec 2023Dane anonimowe (K. sp. z o.o. sp. k. z siedzibą w W. przy ul.)The President of UODO imposed a fine of PLN 18,864 on the company for failing to cooperate in the performance of the authority’s duties. The company also did not provide access to personal data and information necessary for the regulator’s tasks.PLUODOGDPR€4,346
02 Jun 2023Dane anonimowe (T. sp. z o.o. z siedzibą w K. przy ul.)The President of UODO imposed a fine of PLN 18,864 on T. sp. z o.o. The company failed to cooperate with the authority in the performance of its duties and did not provide access to information necessary for those duties.PLUODOGDPR€4,194
23 Jun 2025Dane anonimowe (Pana A. Z., prowadzącego działalność gospodarczą pod firmą „W.” z siedzibą w T. przy ul.)The President of UODO imposed an administrative fine of PLN 18,941 on an entrepreneur operating under the name “W.”. The sanction concerned failure to provide information and failure to grant access to personal data and other information necessary for the authority to perform its duties.PLUODOGDPR€4,430
30 Aug 2024Dane anonimowe (Panią A. K., prowadzącą działalność gospodarczą pod firmą B. w M. przy ul.)The President of the Personal Data Protection Office imposed an administrative fine on an individual conducting business activity. The sanction resulted from failure to cooperate with the authority and from not providing access to personal data and information necessary for its tasks.PLUODOGDPR€4,594
14 Sept 2006Banca Sella S.p.a.Banca Sella S.p.a. was fined EUR 20,000 by the Garante for processing biometric data without the notification required under the privacy code. The authority found this to be a breach of Italian privacy rules.ITGaranteGDPR€20,000