Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
04 Apr 2025Unnamed bankThe Polish data protection authority imposed a fine of EUR 928,498.06 on a bank. The authority found that the bank failed to inform customers about a personal data breach. The case concerns post-incident notification obligations.PLPolish Data Protection AuthorityGDPR€928,000
15 May 2025SOCIETE AYANT UNE ACTIVITE DE MARKETING ET DE CONCEPTION DE SITES WEBThe CNIL imposed an administrative fine of EUR 900,000 on SOCIETE AYANT UNE ACTIVITE DE MARKETING ET DE CONCEPTION DE SITES WEB and issued an injunction. The case concerns a regulatory breach requiring corrective action.FRCNILGDPR€900,000
04 Jul 2024Postel S.p.A.Postel S.p.A. was fined by the Garante EUR 900,000 for a data breach following a ransomware attack. The attack exploited vulnerabilities in the Microsoft Exchange platform, resulting in unauthorized access to data and publication on the dark web.ITGaranteGDPR€900,000
27 Nov 2024E.ON Energia S.p.A.E.ON Energia S.p.A. was fined EUR 892,738 by the Garante for telemarketing-related violations. The authority cited repeated contact attempts and numerous communications sent without proper consent.ITGaranteGDPR€892,000
28 Oct 2025Aktia PankkiThe sanction panel of the Finnish Data Protection Ombudsman’s Office imposed an EUR 865,000 fine on Aktia Pankki for deficiencies in information security in its strong electronic identification service. The incident caused some users to see other customers’ data in services requiring strong authentication.FITietosuojavaltuutetun toimistoGDPR€865,000
02 Feb 2017Marc 1 s.r.l.Marc 1 s.r.l. was fined €850,000 by the Garante for transferring money to China using techniques designed to avoid anti-money laundering rules. The authority also found that the actual senders had not given consent for the processing of their personal data.ITGaranteGDPR€850,000
28 Mar 2023Sky Italia S.r.l.The Italian Data Protection Authority fined Sky Italia S.r.l. EUR 842,062 for violations related to telemarketing and commercial communications. The company failed to properly verify consent, relied on outdated consents, and did not check the Public Register of Oppositions before campaigns.ITGarante per la protezione dei dati personaliGDPR€842,000
12 Sept 2024Sky Italia S.r.l.Sky Italia S.r.l. was fined EUR 842,062 by the Garante for telemarketing violations. The authority found that the company contacted individuals without proper consent and failed to consult the Public Register of Objections before promotional campaigns.ITGaranteGDPR€842,000
18 Jan 2018Telecom Italia S.p.A.Telecom Italia S.p.A. was fined EUR 840,000 by the Garante for making promotional phone calls to individuals who had not consented to the processing of their data for marketing purposes. The case indicates a breach of lawful processing rules and consent requirements.ITGaranteGDPR€840,000
06 Jul 2020Bureau Krediet Registratie (BKR)Bureau Krediet Registratie (BKR) was fined EUR 830,000 by the AP for not providing free electronic access to personal data. The authority found this practice breached the GDPR right of access.NLAPGDPR€830,000
13 Apr 2023Arnia società cooperativaThe Garante imposed a fine of 800,000 EUR on Arnia società cooperativa for unauthorized data processing and telemarketing activities. The case concerned a breach of GDPR Article 5.ITGaranteGDPR€800,000
05 Sept 2024SOCIETE SPECIALISEE DANS L’EDITION ET LA VENTE DE LOGICIELS DE GESTION AUX MEDECINSThe CNIL imposed an administrative fine of EUR 800,000 on SOCIETE SPECIALISEE DANS L’EDITION ET LA VENTE DE LOGICIELS DE GESTION AUX MEDECINS. The case concerns a breach of rules supervised by the CNIL.FRCNILGDPR€800,000
18 Apr 2018Anonymizováno (ÚOOÚ UOOU-09774/17-25)The entity was fined for processing personal data of hundreds of thousands of individuals without consent or another legal basis. The authority found this to be a breach of § 5(2) of the Czech Data Protection Act.CZUOOUGDPR€31,616
01 Jan 2021ORANGE ESPAGNE, S.A.U.ORANGE ESPAGNE, S.A.U. was fined 800,000 EUR by the AEPD for failing to adequately protect personal data. The breach enabled identity fraud and unauthorized access to banking information through SIM card duplication.ESAEPDGDPR€800,000
16 May 2018Telecom Italia S.p.A.Telecom Italia S.p.A. was fined by the Garante €800,000 for the unauthorized activation of numerous residential phone lines in a citizen's name. The case involved processing and disclosing personal data without a legal basis, as well as failing to notify data breaches.ITGaranteGDPR€800,000
09 Dec 2020Ítélet a NAIH/2019/3633/10 sz. ügyben (Fővárosi Törvényszék 106.K.700.561/2019/16) - 2020. december 9.The case concerned a HUF 800,000 fine imposed by the NAIH for unlawful camera surveillance. The authority found that the processing breached GDPR principles of lawfulness, fairness, transparency, purpose limitation, and data minimization.HUNAIHGDPR€2,240
10 Nov 2022SOCIETE DEVELOPPANT UN LOGICIEL DE VOIX SUR IP ET UNE MESSAGERIE INSTANTANEECNIL imposed a fine of 800,000 EUR on SOCIETE DEVELOPPANT UN LOGICIEL DE VOIX SUR IP ET UNE MESSAGERIE INSTANTANEE. The decision concerns a breach of rules covered by the authority’s enforcement action.FRCNILGDPR€800,000
09 Jul 2020Iliad Italia S.p.A.Iliad Italia S.p.A. was fined EUR 800,000 by the Garante for irregularities in the processing of customer data. The violations concerned SIM card activation, promotional use of data, inadequate security measures, and improper data retention.ITGaranteGDPR€800,000
22 Jul 2021Roma CapitaleRoma Capitale was fined EUR 800,000 by the Garante for failing to adequately protect the personal data of motorists using parking meters. The authority also found improper data retention practices, increasing the risk to data subjects.ITGaranteGDPR€800,000
28 Aug 2024SOCIETE SPECIALISEE DANS LA REALISATION D'ETUDES STATISTIQUES EN MATIERE DE DONNEES DE SANTECNIL imposed an administrative fine of 800,000 EUR on SOCIETE SPECIALISEE DANS LA REALISATION D'ETUDES STATISTIQUES EN MATIERE DE DONNEES DE SANTE. The decision concerns violations related to data processing and should be assessed against applicable data protection obligations.FRCNILGDPR€800,000