Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
03 Oct 2023Utbildningsnämnden i Stockholms stad – Aspuddens skolaThe Stockholm City Education Committee was fined by IMY 800,000 SEK for unlawful camera surveillance at Aspuddens school. The authority found breaches of legality and data minimization principles, as well as a failure to provide the required information under GDPR.SEIMYGDPR€68,744
04 Oct 2023Amazon EuropeThe CNPD imposed a fine of EUR 746,000,000 on Amazon Europe for breaches of data protection rules. The case concerned shortcomings in the processing of personal data and compliance with GDPR requirements.LUCNPDGDPR€746,000,000
05 Oct 2023DPP Law LtdThe Information Commissioner's Office issued a monetary penalty notice against DPP Law Ltd. The firm was fined GBP 60,000 for failing to implement appropriate technical and organisational measures to secure personal data.GBInformation Commissioner's OfficeGDPR€69,282
06 Oct 2023Ítélet a NAIH-19-18-2024 sz. ügyben (Kúria Kfv.IV.37.804/2025/2)The entity was fined for improper processing of personal data in a nationwide energy efficiency program. The authority found inadequate transparency and consent procedures, as well as insufficient data security measures.HUNAIHGDPR€194,000
06 Oct 2023Texas Andreas Petersen A/SThe Danish Data Protection Authority reported Texas Andreas Petersen A/S to the police and recommended a fine of at least DKK 200,000. The case concerned the collection and sharing of website visitors' personal data without a legal basis.DKDatatilsynetGDPR€26,818
06 Oct 2023SOCIETE DE CONSEILS EN SYSTEMES ET LOGICIELS INFORMATIQUES (procédure simplifiée)CNIL imposed a fine of EUR 20,000 on SOCIETE DE CONSEILS EN SYSTEMES ET LOGICIELS INFORMATIQUES under a simplified procedure. The decision concerns a breach of personal data protection rules.FRCNILGDPR€20,000
10 Oct 2023UAB RamidonasThe supervisory authority imposed a €6,000 fine on UAB Ramidonas for personal data security violations. The case concerned deficiencies in data protection controls that could have exposed individuals’ information to risk.LTValstybinė duomenų apsaugos inspekcijaGDPR€6,000
10 Oct 2023American ExpressCNIL imposed a EUR 1,500,000 fine on American Express for placing cookies without prior user consent. The case concerns breaches of GDPR and privacy law requirements.FRCNILGDPR€1,500,000
10 Oct 2023ComuneThe Italian data protection authority fined a municipality EUR 12,000 for unlawfully publishing personal data online in access request registers. Documents in the transparency section of the municipal website exposed names, protocol numbers, and other sensitive details of hundreds of citizens.ITGarante per la protezione dei dati personaliGDPR€12,000
10 Oct 2023TemuThe European Commission imposed a EUR 200 million fine on Temu under the Digital Services Act. The authority said Temu failed to identify, analyse, and assess systemic risks linked to illegal products offered on its platform.EUEuropean CommissionDSA€200,000,000
10 Oct 2023Hogeschool van Arnhem en Nijmegen (HAN)The Autoriteit Persoonsgegevens imposed a fine of EUR 175,000 on Hogeschool van Arnhem en Nijmegen (HAN). The authority found that the institution did not provide sufficient protection for students’ personal data.NLAutoriteit PersoonsgegevensGDPR€175,000
10 Oct 2023GALENICUM HEALTH, S.L.U.GALENICUM HEALTH, S.L.U. was fined EUR 500 by the AEPD for failing to display informational signage about its video surveillance system. The authority found a breach of Article 5(1)(c) GDPR in relation to transparency and proper notice.ESAEPDGDPR€500
11 Oct 2023CONSULTORÍA PERITACIONES ALMERIENSES, S.L.The company was fined by the AEPD 1,000 EUR for not having a privacy policy on its website. The issue arose because it collected personal data through a contact form, triggering the information duties under GDPR Article 13.ESAEPDGDPR€1,000
11 Oct 2023COM. PROP. ***COMUNIDAD.1The entity installed surveillance cameras oriented toward public roads without prior administrative authorization. This breached data protection rules and resulted in a fine by the AEPD.ESAEPDGDPR€1,000
11 Oct 2023B.B.B.The entity installed surveillance cameras without consent in a rented equestrian club. The recordings captured minors and disabled individuals, which constituted a privacy violation.ESAEPDGDPR€2,000
12 Oct 2023Onda Più S.r.l.Onda Più S.r.l. was fined EUR 200,000 by the Garante for activating energy supply contracts without customer consent. The authority also found the use of inaccurate and outdated personal data.ITGaranteGDPR€200,000
12 Oct 2023SOCIETE EDITANT DES CHAINES ET DISTRIBUANT DES OFFRES DE TELEVISION PAYANTESCNIL imposed a fine of EUR 600,000 on SOCIETE EDITANT DES CHAINES ET DISTRIBUANT DES OFFRES DE TELEVISION PAYANTES. The case concerns a confirmed regulatory breach, with no further details provided in the record.FRCNILGDPR€600,000
12 Oct 2023S.T.A. Società Trattamento Acque s.r.l.S.T.A. Società Trattamento Acque s.r.l. was fined €75,000 by the Garante. The authority found a breach of Article 15 GDPR after the company failed to respond to an employee's request for access to professional training records.ITGaranteGDPR€75,000
12 Oct 2023Scionti Selezioni Superiori S.r.l.Scionti Selezioni Superiori S.r.l. was fined EUR 70,000 by the Garante for failing to implement adequate measures to prevent unauthorized access to customer data. The data was then used for promotional purposes without the individuals' consent.ITGaranteGDPR€70,000
13 Oct 2023COMUNIDAD DE PROPIETARIOS ***COMUNIDAD.1The entity installed a video surveillance system with cameras directed toward public areas without prior administrative authorization. In addition, unauthorized personnel had access to the system, creating a data protection compliance breach.ESAEPDGDPR€1,000