Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-22.8%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
12 Nov 2024Dane anonimowe (X. w Y.)UODO imposed an administrative fine of PLN 24,555 on Anonymous entity (X. in Y.) for breaches of Articles 24(1), 25(1), and 32(1)-(2) of the GDPR. The authority also ordered the processing operations to be brought into compliance with Regulation (EU) 2016/679.PLUODOGDPR€5,644
01 Feb 2025Automobilus International S.R.L.The Romanian data protection authority fined Automobilus International S.R.L. 24,885 RON after concluding its investigation in February 2025. It found breaches of GDPR Articles 32(1) and 32(2) due to inadequate technical and organizational security measures following a personal data breach.ROAutoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter PersonalGDPR€5,000
05 Jul 2021Anonymisoitu (TSV 943)The controller unlawfully processed employees' location data, breaching the GDPR principles of data minimization and lawfulness. The case concerned processing that went beyond what was necessary for the stated purpose.FITSVGDPR€25,000
25 Nov 2015Video s.r.l.Video s.r.l. was fined by the Garante 25,000 EUR for registering 500 phone cards to five unaware individuals without their consent. The case concerns a breach of data protection rules and the absence of a lawful basis for processing personal data.ITGaranteGDPR€25,000
01 Jan 2022CAIXABANK S.A.CaixaBank was fined EUR 25,000 by the AEPD for failing to update a customer's address despite repeated requests. The authority found this to be a breach of the GDPR right to rectification.ESAEPDGDPR€25,000
11 Apr 2024Innova Camera – Azienda speciale della Camera di commercio, industria, artigianato e agricoltura di RomaInnova Camera was fined by the Garante EUR 25,000 for inadequate data security measures. The breach resulted in personal data being accessed and published online following an SQL Injection attack.ITGaranteGDPR€25,000
08 Jul 2021Azienda ospedaliero-universitaria SeneseAzienda ospedaliero-universitaria Senese was fined by the Garante 25,000 EUR for violations related to data breaches involving health data and patient information. The case concerned the handling of sensitive data and required assessment of compliance with data protection obligations.ITGaranteGDPR€25,000
09 Oct 2025EON ENERGIE ROMANIA S.A.ANSPDCP completed an investigation at EON ENERGIE ROMANIA S.A. and found a breach of GDPR provisions. As a result, an administrative fine of EUR 25,000 was imposed.ROANSPDCPGDPR€25,000
18 Oct 2024X, ul.UODO imposed an administrative fine of PLN 25,000 on X, ul. for breaching Article 37(1)(a) and Article 37(7) of Regulation 2016/679. The authority also ordered the processing operations to be brought into compliance with GDPR requirements.PLUODOGDPR€5,803
05 Aug 2016LinguaphoneLinguaphone was fined 25,000 EUR by the Greek HDPA for sending unsolicited marketing emails without prior recipient consent. The conduct breached Article 11 of Law 3471/2006.GRHDPAePrivacy€25,000
01 Jan 2024BONTECU DISTRIBUCIONES, S.L.U.BONTECU DISTRIBUCIONES, S.L.U. was fined by the AEPD for processing personal data without consent and for failing to have proper data processing agreements in place. The case concerned a complainant who received an unsolicited contract from Factor Energía.ESAEPDGDPR€25,000
14 Apr 2021MASTER DISTANCIA S.A.MASTER DISTANCIA S.A. was fined EUR 25,000 by the AEPD for unlawfully processing personal data by including it in credit information systems without a valid legal basis. The authority found a breach of GDPR Article 6.ESAEPDGDPR€25,000
01 Jan 2025FEMXA FORMACIÓN, S.L.FEMXA FORMACIÓN, S.L. was fined by the AEPD 25,000 EUR for requiring a full copy of a student's ID during course enrollment. The authority found the data request unnecessary and inconsistent with data protection principles.ESAEPDGDPR€25,000
24 Nov 2025SIA "EUROPARK LATVIA"A fine of EUR 25,000 was imposed. The decision has been appealed.LVDVIGDPR€25,000
17 Jul 2025Juna S.r.l.Juna S.r.l. was fined €25,000 by the Garante for making repeated unwanted and fraudulent promotional calls to individuals. The conduct breached data protection principles, including lawful and fair processing requirements.ITGaranteGDPR€25,000
09 May 2024Provvedimento del 9 maggio 2024 [10027595]The authority imposed a fine on an anonymized healthcare entity for unauthorized access to patient health records by personnel without proper authorization. The case concerned GDPR requirements on data protection and processing security.ITGaranteGDPR€25,000
12 Feb 2015Aloisio AngeloAloisio Angelo was fined EUR 25,000 by the Italian data protection authority, Garante. The case involved activating 15 phone cards in the names of 5 individuals without their knowledge, which breached data protection rules.ITGaranteGDPR€25,000
04 Apr 2024SOCIETE AYANT POUR ACTIVITE LA PROSPECTION COMMERCIALE PAR COURRIEL POUR LE COMPTE D'ANNONCEURSThe CNIL imposed EUR 25,000 on SOCIETE AYANT POUR ACTIVITE LA PROSPECTION COMMERCIALE PAR COURRIEL POUR LE COMPTE D'ANNONCEURS as a liquidation of a penalty. The measure relates to non-compliance with a prior obligation and is enforcement in nature.FRCNILGDPR€25,000
26 Sept 2023RESTART ENERGY ONE S.A.RESTART ENERGY ONE S.A. was fined by ANSPDCP in the amount of EUR 25,000 for violations related to personal data processing. The case concerned non-compliance with GDPR requirements in data processing activities.ROANSPDCPGDPR€25,000
25 Mar 2025NTT DATA ROMÂNIA S.A.NTT DATA ROMÂNIA S.A. was fined by ANSPDCP in the amount of EUR 25,000 for GDPR violations. The case concerned non-compliance with personal data protection requirements.ROANSPDCPGDPR€25,000