Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-22.8%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
29 Apr 2022Fire Brigade HeadquartersA fine was imposed for unlawful processing of personal data, which breached data protection principles and security obligations. The case concerned failures to ensure compliance with data protection requirements.GRHDPAGDPR€25,000
17 Oct 2024AziendaThe company was fined for failing to implement adequate security measures, which led to a data breach affecting a large number of individuals. The case indicates insufficient protection of personal data and elevated risk to data subjects.ITGaranteGDPR€25,000
27 Feb 2025Istarski vodovod d.o.o.Istarski vodovod d.o.o. was fined by AZOP EUR 25,000 for failing to implement adequate technical security measures. The deficiencies included the absence of two-factor authentication and monitoring systems, which led to unauthorized access and a data breach.HRAZOPGDPR€25,000
23 Aug 2022Anonymisiert (DSB 2022-0.585.764)The responsible party unlawfully processed personal data by installing a hidden WiFi camera in a public restroom. This breached the GDPR principles of lawfulness, purpose limitation, and data minimization, and the data subjects were not informed.ATDSBGDPR€25,000
01 Jan 2024GASEXPRESS PATRAIX, S.L.GASEXPRESS PATRAIX, S.L. was fined by the AEPD 25,000 EUR for allowing unauthorized access to previous users' data in its automated gas station system. The exposed information included DNI numbers and partial credit card numbers.ESAEPDGDPR€25,000
07 Jul 2025AURThe Romanian data protection authority imposed two fines on AUR totaling EUR 25,000. The sanctions concerned unauthorized access to supporters' personal data in the AUR app and unlawful collection of personal data on campaign platforms.ROAutoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter PersonalGDPR€25,000
19 Dec 2025ORANGE ESPAGNE, S.A.U.ORANGE ESPAGNE, S.A.U. was fined by the AEPD 25,000 EUR for sending invoices to a person who was not a customer and for failing to properly delete their data after a request. The authority found breaches of data accuracy and the right to erasure under GDPR Articles 5(1)(d) and 17.ESAEPDGDPR€25,000
29 Jun 2018BANCO BILBAO VIZCAYA ARGENTARIA, S.A.Banco Bilbao Vizcaya Argentaria, S.A. was fined by the AEPD EUR 25,000 for sending unsolicited commercial messages. The authority found that recipients were not provided with a free opt-out mechanism.ESAEPDePrivacy€25,000
05 Feb 2026Gemeente DelftGemeente Delft processed personal data without a sufficient legal basis. It also processed special categories of personal data without a valid exception, breaching GDPR principles.NLAPGDPR€25,000
14 Apr 2011Trentino Trasporti Esercizio S.p.A.Trentino Trasporti Esercizio S.p.A. was fined by the Garante 25,000 EUR for collecting personal data through web forms without providing the required privacy notice. This constituted a breach of Article 13 of the Italian Data Protection Code.ITGaranteGDPR€25,000
31 Aug 2023Robin S.r.l.The Garante fined Robin S.r.l. 25,000 EUR for publishing a photograph of minors with insufficient anonymization. The case concerns a breach of personal data protection rules applicable to children.ITGaranteGDPR€25,000
05 Jan 2021DKN.5131.6.2020StatusprawomocnaTytuUODO imposed a fine of PLN 25,000 on the University for failing to report a personal data breach to the President of UODO. The institution also did not notify the affected individuals about the breach.PLUODOGDPR€5,498
15 Nov 2012Gruppo Ro.Ri s.r.l.Gruppo Ro.Ri s.r.l. was fined by the Garante for failing to notify the cessation of data processing after the merger of Casa di cura S. Teresa del Bambin Gesù s.r.l. The authority found a breach of Article 38 of the Italian Data Protection Code.ITGaranteGDPR€25,000
18 Dec 2025TELCOM BUSINESS SOLUTIONS S.L.TELCOM BUSINESS SOLUTIONS S.L. was fined by the AEPD for attempting to process live and biometric data without prior consent. After a purchase, users were redirected to a US-based company for identity verification.ESAEPDGDPR€25,000
05 Feb 2026Gemeente HilversumThe Autoriteit Persoonsgegevens found that Gemeente Hilversum processed personal data without a valid legal basis during an investigation into Muslim residents and organizations. The municipality accepted an administrative fine of 25,000 EUR and acknowledged responsibility.NLAutoriteit PersoonsgegevensGDPR€25,000
01 Jan 2019GLOVOAPP23, S.L.GLOVOAPP23, S.L. was fined by the Spanish data protection authority, AEPD, in the amount of €25,000. The authority found a breach for failing to appoint a Data Protection Officer as required by Article 37 of the GDPR.ESAEPDGDPR€25,000
14 Apr 2025niegoAn administrative fine of 25,255 PLN was imposed for failure to comply with an order contained in an administrative decision of the President of UODO. The case concerns non-fulfilment of an obligation imposed by the supervisory authority.PLUODOGDPR€5,893
22 Nov 2012Mediabusiness Int. s.r.l.Mediabusiness Int. s.r.l. was fined EUR 26,000 by the Garante for sending unsolicited promotional faxes. The authority found that the company did not obtain valid consent from recipients, which breached data protection rules.ITGaranteGDPR€26,000
08 Mar 2018INFOMOBILITY S.P.A.INFOMOBILITY S.P.A. was fined EUR 26,000 by the Garante for providing inadequate information to customers about geolocation activities in its car sharing service. The authority found that the disclosures did not meet transparency requirements for users.ITGaranteGDPR€26,000
06 Dec 2011Composad s.r.l.Composad s.r.l. was fined by the Garante €26,000 for processing personal data collected through its website without properly appointing a data processor. The case concerned a breach of data protection rules and related organizational obligations.ITGaranteGDPR€26,000