Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
09 Jul 2025DISTRIBUTED ENERGY ASSETS, S.L.DISTRIBUTED ENERGY ASSETS, S.L. was fined by the AEPD 5,000 EUR for obstructing the exercise of data subject rights. The breach concerned in particular the right to erasure under Article 17 of the GDPR.ESAEPDGDPR€5,000
05 May 2021Disqus IncThe Norwegian DPA, Datatilsynet, intends to fine Disqus Inc NOK 25 million. The case concerns a breach of accountability, lack of a legal basis, and failure to inform users about tracking and sharing personal data.NODatatilsynetGDPR€2,503,000
28 Apr 2022DISPLAY CONNECTORS, S.L.DISPLAY CONNECTORS, S.L. was fined by the AEPD EUR 50,000 for processing excessive personal data. The company published audio of a victim’s testimony without necessity, breaching the data minimisation principle under Article 5(1)(c) GDPR.ESAEPDGDPR€50,000
19 Jan 2022DISPLAY CONNECTORS, S.L.DISPLAY CONNECTORS, S.L. was fined by the AEPD EUR 50,000 for processing excessive personal data, including the name of a minor, that was not necessary for the intended purpose. The authority found this to be a breach of data protection principles.ESAEPDGDPR€50,000
22 Apr 2022DISPLAY CONNECTORS, S.LDISPLAY CONNECTORS, S.L was fined EUR 300,000 by the AEPD for automatically publishing videos containing personal data without first ensuring the processing was lawful. The authority found this conduct breached data protection rules.ESAEPDGDPR€300,000
01 Jan 2025Diskrimineringsombudsmannen (DO)Integritetsskyddsmyndigheten (IMY) imposed a 100,000 SEK administrative sanction on Diskrimineringsombudsmannen (DO). The case concerned insufficient security measures for personal data collected via a web form, which resulted in unintended disclosure to a processor.SEIntegritetsskyddsmyndigheten (IMY)GDPR€8,727
23 Apr 2025Diskriminerings­ombudsmannen (DO)The Swedish Authority for Privacy Protection (IMY) fined the Equality Ombudsman (DO) 100,000 SEK. IMY found that DO failed to implement appropriate technical and organizational measures to ensure an adequate level of security for personal data collected via a web form.SEIMYGDPR€9,141
04 Apr 2013Discotape di Filippin Angelo & C. sncDiscotape di Filippin Angelo & C. snc was fined EUR 12,000 by the Garante. The case concerned registering numerous phone cards to an individual without their knowledge and failing to provide the required information notice.ITGaranteGDPR€12,000
28 Apr 2022Direzione Didattica Statale 1° Circolo–EboliDirezione Didattica Statale 1° Circolo–Eboli was fined by the Garante 1,500 EUR for breaching the GDPR principles of lawfulness, fairness, and transparency in data processing. The case concerned improper processing of personal data under the GDPR.ITGaranteGDPR€1,500
04 Jun 2015Direzione Casa Circondariale di BariDirezione Casa Circondariale di Bari was fined €10,000 by the Garante for unlawfully processing sensitive data. The authority found that it collected, stored, and communicated the names of participants in a union demonstration without initiating any disciplinary proceedings, in breach of data protection law.ITGaranteGDPR€10,000
01 Jan 2016DIRELEC GROUP S.L.DIRELEC GROUP S.L. was fined by the AEPD EUR 1,000 for sending unsolicited commercial emails. The conduct breached Article 21.1 of the LSSI despite prior requests to stop contacting the recipient.ESAEPDePrivacy€1,000
15 Mar 2018Directafin s.p.a.Directafin s.p.a. was fined by the Garante in the amount of EUR 20,000 for using a single consent flag for multiple processing purposes. This included marketing and sharing personal data with third parties without valid consent.ITGaranteGDPR€20,000
12 Jul 2006Diomede s.r.l.Diomede s.r.l. was fined EUR 258 by the Garante for failing to provide adequate information to data subjects in job advertisements. This constituted a breach of the Italian Privacy Code.ITGaranteGDPR€258
22 Mar 2025DINOLIN, S.A.DINOLIN, S.A. was fined EUR 450 by the AEPD for failing to comply with a data subject's request to delete personal data. The case concerns obligations under the GDPR.ESAEPDGDPR€450
11 Apr 2013Diners Club Italia s.r.l.Diners Club Italia s.r.l. was fined €40,000 by the Garante for breaches of data protection rules. The authority found that the company failed to designate data processing officers and did not update the security program document.ITGaranteGDPR€40,000
18 Jun 2025Dincă Viorel GeorgeThe operator was fined for failing to respond to prior requests from the National Supervisory Authority for Personal Data Processing. The authority also found that a previously imposed corrective measure had not been implemented.ROANSPDCPGDPR€200
24 Mar 2025DINAMO SAN JUAN, C.F.DINAMO SAN JUAN, C.F. was fined by the AEPD for processing personal data without a legal basis. The case concerned the failure to effectively remove images of minors from social media after a parent requested deletion.ESAEPDGDPR€1,000
08 May 2024DIMAGAZA, S.L.DIMAGAZA, S.L. was fined by the AEPD 1,000 EUR for posting personal data of employees affected by a collective dismissal on a notice board accessible to outsiders. The authority found a breach of the principles of integrity and confidentiality.ESAEPDGDPR€1,000
30 Dec 2011Dike Giuridica s.r.l.Dike Giuridica s.r.l. was fined by the Garante in the amount of 10,400 EUR for sending unsolicited commercial emails without prior explicit consent from recipients. The authority also found that the required privacy notice was not provided, in breach of the Italian data protection code.ITGaranteGDPR€10,400
03 Oct 2023Digivo Media LimitedBetween 24 March 2021 and 7 September 2021, 415,041 text messages were sent without valid consent, breaching Regulation 22 of PECR. The ICO identified the matter after reviewing debt management complaints submitted via the SPAM reporting tool.GBICOePrivacy€57,620