Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
04 Nov 2025SOCIETE EXERCANT UNE ACTIVITE DE CONSEIL ET AIDE A LA GESTION AUPRES DE CLUBS DE SPORTS SUBAQUATIQUES (procédure simplifiée)CNIL imposed an administrative fine of 4,000 EUR on SOCIETE EXERCANT UNE ACTIVITE DE CONSEIL ET AIDE A LA GESTION AUPRES DE CLUBS DE SPORTS SUBAQUATIQUES under a simplified procedure. The decision concerns a regulatory breach handled in administrative proceedings.FRCNILGDPR€4,000
04 Nov 2025McDonald'sThe Polish Data Protection Authority imposed a EUR 4,022,773 fine on McDonald's for insufficient security measures in personal data processing. A separate EUR 43,680 fine was also issued to the service provider involved in the same incident.PLPolish Data Protection AuthorityGDPR€4,022,000
03 Nov 2025Fiziskas personaA fine of EUR 250 was imposed by DVI. The decision has entered into force.LVDVIGDPR€250
01 Nov 2025LastPass UK LtdIn November 2025, the Information Commissioner’s Office imposed a monetary penalty of about £1.2 million on LastPass UK Ltd. The sanction concerned security and governance failures that led to a breach affecting around 1.6 million UK users, despite the use of strong encryption.GBInformation Commissioner's OfficeGDPR€1,361,000
01 Nov 2025Właścicielka lecznicy stomatologicznejThe owner of a dental clinic was fined 85,588 PLN by UODO for failing to notify affected patients in time after a personal data breach. The WSA and then the NSA upheld the penalty, finding that the required notices were sent too late.PLPresident of the Personal Data Protection Office (UODO)GDPR€20,110
28 Oct 2025Aktia PankkiThe sanction panel of the Finnish Data Protection Ombudsman’s Office imposed an EUR 865,000 fine on Aktia Pankki for deficiencies in information security in its strong electronic identification service. The incident caused some users to see other customers’ data in services requiring strong authentication.FITietosuojavaltuutetun toimistoGDPR€865,000
28 Oct 2025SIA ZZ DatsThe Latvian Data State Inspectorate found that SIA ZZ Dats failed to meet GDPR Article 32 requirements for appropriate technical and organizational measures. The case involved a major personal data leak affecting nearly all Latvian municipalities, and the authority imposed an administrative fine of EUR 300,000. The company has appealed the decision.LVDatu valsts inspekcijaGDPR€300,000
27 Oct 2025Anonymisiert (DSB 2025-0.811.087)The controller unlawfully processed personal data through video surveillance, including public sidewalk areas, contrary to data minimization principles. Images were also published online without a legal basis.ATDSBGDPR€1,500
25 Oct 2025MAR DEGUSTACIÓN, S.LMAR DEGUSTACIÓN, S.L was fined by the AEPD 1,000 EUR for installing a video surveillance system without proper consent and for failing to inform affected individuals. The authority cited breaches of GDPR Articles 5(1)(c) and 13.ESAEPDGDPR€1,000
25 Oct 2025TELECONTACT LIST S.L.TELECONTACT LIST S.L. was fined 1,000 EUR by the AEPD for failing to respond to a data subject’s request for access to and deletion of personal data. The authority found a breach of Article 15 of the GDPR.ESAEPDGDPR€1,000
23 Oct 2025Provvedimento del 23 ottobre 2025 [10195910]A fine of EUR 1,000 was imposed for the unlawful online publication of personal data by a local authority. The conduct breached core data protection principles.ITGaranteGDPR€1,000
23 Oct 2025Istituto d'Istruzione Superiore “Statista Aldo Moro” di Fara SabinaThe school published on its website a document containing personal data related to a student's disciplinary proceeding. Garante found that this breached the GDPR principles of lawfulness, fairness, and transparency.ITGaranteGDPR€4,000
23 Oct 2025Hearst Magazines Italia S.p.A.Hearst Magazines Italia S.p.A. was fined EUR 20,000 by the Garante for publishing personal data relating to an individual's health without a legal basis. The authority found a breach of the principles of lawfulness and fairness in processing.ITGaranteGDPR€20,000
23 Oct 2025Ordine degli Avvocati di LatinaOrdine degli Avvocati di Latina was fined EUR 15,000 by the Garante for unlawful, incorrect, and non-transparent processing of personal data. The authority also found a failure to ensure data minimization.ITGaranteGDPR€15,000
23 Oct 2025Azzurra Sport s.r.l.Azzurra Sport s.r.l. was fined EUR 4,000 by the Garante for unlawful processing of personal data through a video surveillance system. The breach concerned the absence of appropriate informational signage for individuals subject to the monitoring.ITGaranteGDPR€4,000
23 Oct 2025Comune di AvolaThe Garante fined Comune di Avola 2,000 EUR for failing to provide the Authority with the Data Protection Officer’s contact details. The breach concerned the obligation under Article 37(7) GDPR.ITGaranteGDPR€2,000
23 Oct 2025Comune di CurtaroloComune di Curtarolo was fined EUR 15,000 by the Garante for using surveillance footage for disciplinary purposes without proper legal justification. The authority also found that adequate privacy information was not provided to the individuals concerned.ITGaranteGDPR€15,000
23 Oct 2025Multimedia News Società CooperativaThe Garante fined Multimedia News Società Cooperativa EUR 20,000 for failing to provide a privacy notice and contact details for data requests on its website. The authority found this breached transparency obligations and data subject rights.ITGaranteGDPR€20,000
23 Oct 2025Franco SpellecchiaFranco Spellecchia was fined by the Garante for installing a video surveillance system around his residence without the required legal basis. The authority found that the setup breached GDPR rules, including the absence of a legitimate interest or authorization.ITGaranteGDPR€500
23 Oct 2025Zephiromedia S.r.l.Zephiromedia S.r.l. was fined EUR 30,000 by the Garante for sending unsolicited promotional emails. The authority also found that recipients were not given an effective way to unsubscribe or exercise their rights.ITGaranteGDPR€30,000