Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
30 Jan 2024Könnycsepp Nélkül a Beteg Gyermekekért AlapítványThe NAIH imposed a 1,000,000 HUF fine on the foundation for GDPR breaches related to personal data processing during phone calls. The authority found that data subjects were not adequately informed and that the processing lacked a valid legal basis.HUNAIHGDPR€2,580
11 Dec 2025Mobius Solutions LtdThe French CNIL imposed a 1 million EUR fine on Mobius Solutions Ltd for personal data processing violations. The case involved unlawful retention and reuse of data from more than 46 million users after the contract ended, as well as failure to maintain a processing activities register.FRCNILGDPR€1,000,000
18 Dec 2013Google Inc.Google Inc. was fined EUR 1 million by the Italian Data Protection Authority, Garante. The authority found that individuals were not adequately informed during data collection by Google cars for the Street View service.ITGaranteGDPR€1,000,000
07 Jul 2023Személyes adatok forrása és adatgyűjtés távhőszolgáltatás nyújtásáhozThe supervisory authority found a GDPR breach because the controller did not inform data subjects about the source of their personal data. It also failed to demonstrate accountability and compliance with data protection principles.HUNAIHGDPR€2,580
31 Jul 2024Hangrögzítés telefonos ügyfélszolgálatonThe authority imposed a fine for breaching the GDPR principles of transparency and accountability. The entity did not adequately inform callers that customer service phone calls were being recorded.HUNAIHGDPR€2,530
22 Jun 2023Autostrade per l’Italia S.p.A.Autostrade per l’Italia S.p.A. was fined by the Garante EUR 1,000,000 for violations linked to an application that processed users’ personal data. The app was used to handle refunds of highway ticket costs for delays caused by construction works.ITGaranteGDPR€1,000,000
09 Jul 2020dr. Hadházy Ákos ÁnyosThe controller processed personal data without a legal basis and did not provide adequate information about the processing linked to a petition concerning accession to the European Public Prosecutor's Office. The case indicates breaches of core transparency and lawfulness obligations.HUNAIHGDPR€2,820
22 Jun 2022Gyldendal A/SGyldendal A/S was fined 1,000,000 DKK by Datatilsynet for retaining data of 685,000 book club members longer than necessary. The authority found a breach of data retention principles.DKDatatilsynetGDPR€134,000
04 Jan 2021Innovasjon NorgeThe Norwegian DPA notified Innovasjon Norge of a planned NOK 1,000,000 fine for conducting four credit assessments of an individual and his sole proprietorship without a legal basis. The case indicates a breach of the lawfulness principle for personal data processing.NODatatilsynetGDPR€95,750
15 Oct 2019Munkavállaló munkaeszközeinek ellenőrzéseThe controller unlawfully processed the complainant's personal data by reviewing and monitoring their email account without prior notice. This breached the principle of fair processing.HUNAIHGDPR€3,010
28 Feb 2019Kecskemét Megyei Jogú Város Polgármesteri HivatalaKecskemét City Hall transferred personal data from a public interest report to a third party without a legal basis, resulting in unauthorized access. NAIH imposed a fine of 1,000,000 HUF.HUNAIHGDPR€3,160
06 Jun 2024FCA Bank S.p.A.FCA Bank S.p.A. was fined EUR 1,000,000 by the Italian supervisory authority Garante for data protection violations. The case concerned the use of blacklists in car rental services, raising compliance concerns about personal data processing.ITGaranteGDPR€1,000,000
07 Apr 2021Jogellenes adatkezelés, adattakarékosság és megfelelő tájékoztatási kötelezettség megsértéseThe authority found that the controller unlawfully processed personal data related to debt collection. It held that the principles of data minimization and transparency were breached, together with the duty to provide proper information to data subjects.HUNAIHGDPR€2,780
09 Jul 2020Ítélet a NAIH/2020/974 sz. ügyben (Alkotmánybíróság 3110/2022. (III. 23.) AB határozata)The controller processed personal data for contact purposes without a lawful basis and did not provide adequate information about the processing. The authority imposed a fine of HUF 1,000,000 for breaches of GDPR principles.HUNAIHGDPR€2,820
08 Mar 2022Harpa tónlistar- og ráðstefnuhús ohf.Harpa tónlistar- og ráðstefnuhús ohf. was fined by Persónuvernd for collecting personal identification numbers and birth dates without necessity. The authority found breaches of GDPR principles of lawfulness, fairness, transparency, and data minimization.ISPersónuverndGDPR€6,850
29 Jul 2024IBERINFORMIBERINFORM was fined by the AEPD €1,000,000 for processing personal data of self-employed individuals without a proper legal basis. The authority also found that the data were used beyond professional relationships, including for marketing and online exposure.ESAEPDGDPR€1,000,000
14 Jun 2019Facebook Ireland Ltd e Facebook Italy s.r.l.Facebook Ireland Ltd and Facebook Italy s.r.l. were fined EUR 1,000,000 by the Garante for violations involving the unauthorized sharing of user data with the application “Thisisyourdigitallife”. The case affected approximately 214,020 users.ITGaranteGDPR€1,000,000
24 Nov 2022Areti S.p.A.Areti S.p.A. was fined EUR 1,000,000 by the Garante for incorrectly labeling a customer as a “defaulting client” based on inaccurate and outdated data. The issue may have affected up to 16,743 other individuals, indicating a broader data processing failure.ITGaranteGDPR€1,000,000
04 Sept 2025Követeléskezeléssel összefüggő jogalap nélküli adatkezelés, tiltakozási joggal kapcsolatos kérelem nem teljesítése és elszámoltathatóság elvének sérelmeThe supervisory authority fined the controller for unlawfully processing the complainant’s phone number in connection with debt collection. It found breaches of lawfulness, data minimization, accountability, and failure to properly handle the data subject’s objection.HUNAIHGDPR€2,540
29 Apr 2026IBERDROLA CLIENTES, S.A.U.IBERDROLA CLIENTES, S.A.U. was fined EUR 1,000,000 by the AEPD for failing to implement adequate technical and organizational security measures. The authority found that the company did not properly verify customer identity, which constitutes a breach of Article 32 GDPR.ESAEPDGDPR€1,000,000