Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
29 Dec 2025KomendantaUODO imposed an administrative fine of PLN 40,000 on Komendanta for unlawful processing of personal data, including special category data, by publishing it on a website without a legal basis. The authority also found that appropriate technical and organizational measures were not implemented and ordered the processing operations to be brought into compliance with GDPR requirements.PLUODOGDPR€9,457
11 Apr 2013Diners Club Italia s.r.l.Diners Club Italia s.r.l. was fined €40,000 by the Garante for breaches of data protection rules. The authority found that the company failed to designate data processing officers and did not update the security program document.ITGaranteGDPR€40,000
07 Apr 2022Azienda ospedaliera di PerugiaAzienda ospedaliera di Perugia was fined by the Garante EUR 40,000 for breaches related to the protection of whistleblower identities. The authority found that adequate personal data protection measures were not in place.ITGaranteGDPR€40,000
26 Sept 2023RESTART ENERGY ONE S.A.RESTART ENERGY ONE S.A. was fined by ANSPDCP in the amount of RON 40,000 for additional GDPR violations. The authority also imposed corrective measures to improve data protection processes.ROANSPDCPGDPR€8,048
18 Sept 2014Meridi s.r.l.Meridi s.r.l. was fined by the Garante 40,000 EUR for failing to provide adequate information about video surveillance and for not appointing data processing officers. The authority found a breach of data security measures.ITGaranteGDPR€40,000
17 May 2023Volkswagen Leasing GmbHVolkswagen Leasing GmbH was fined EUR 40,000 by the Garante for failing to adequately respond to a data access request. The authority found a breach of GDPR provisions on data subject rights.ITGaranteGDPR€40,000
13 Dec 2018Anonymizováno (ÚOOÚ UOOU-08001/18-14)The entity was fined 40,000 CZK by the UOOU for insufficient security measures in the processing of personal data. The authority cited inadequate audit logs and a lack of regular access checks to electronic health records.CZUOOUGDPR€1,549
28 Apr 2022Il Sole 24 Ore S.p.a.Il Sole 24 Ore S.p.a. was fined by the Garante EUR 40,000 for publishing a court order containing the personal data of an adopted minor. The authority also found an incomplete and delayed response to a data access request.ITGaranteGDPR€40,000
18 Dec 2025Anticimex s.r.l.Anticimex s.r.l. was fined EUR 40,000 by the Garante for breaching data protection rules. The company failed to provide an employee with access to personal data, including work-related emails and CRM access logs, despite a request under Article 15 GDPR.ITGaranteGDPR€40,000
23 Sept 2010Regione PugliaRegione Puglia was fined EUR 40,000 by the Italian data protection authority, Garante. The case concerned the online publication of sensitive health data relating to disabled individuals, in breach of data protection rules.ITGaranteGDPR€40,000
07 Apr 2022ISWEB S.p.A.ISWEB S.p.A. was fined EUR 40,000 by the Italian supervisory authority, Garante. The authority found that the company failed to properly regulate its relationship with the hosting service provider in relation to data processing for Azienda ospedaliera di Perugia, in breach of Article 28 GDPR.ITGaranteGDPR€40,000
24 May 2017Call Solution s.r.l.Call Solution s.r.l. was fined EUR 40,000 by the Garante for making unsolicited promotional calls to numbers listed in the public opt-out registry. The conduct breached data protection rules and the requirements governing telephone marketing.ITGaranteGDPR€40,000
09 Feb 2023Anonymizováno (ÚOOÚ UOOU-04020/22-13)The entity was fined for repeatedly sending unsolicited commercial communications by electronic means without recipients' consent. The authority found a breach of Czech rules on information society services.CZUOOUePrivacy€1,688
18 Dec 2018ORGANIZACION NACIONAL DE CIEGOS (ONCE)ONCE was fined EUR 40,000 by the AEPD for sending more than 200 unsolicited commercial emails without prior consent. The authority found this to be a breach of Article 21 of the LSSI governing electronic marketing communications.ESAEPDePrivacy€40,000
03 Feb 2021NBQ TECHNOLOGY, S.A.U.NBQ TECHNOLOGY, S.A.U. was fined by the AEPD 40,000 EUR for processing personal data without a legal basis. The case was linked to a denied financial operation following an identity theft incident.ESAEPDGDPR€40,000
21 Oct 2019Anonymizováno (ÚOOÚ UOOU-02928/19-13)The entity was fined for publishing personal data related to criminal proceedings on its website. The authority found a breach of GDPR rules on the processing and disclosure of personal data.CZUOOUGDPR€1,561
13 Mar 2025Interflora Italia S.p.A.Interflora Italia S.p.A. was fined EUR 40,000 by the Garante for sending promotional SMS messages without providing an opt-out option. The case indicates a breach of GDPR requirements for marketing communications and data subject rights.ITGaranteGDPR€40,000
11 Apr 2013Casa di cura La Quiete srlCasa di cura La Quiete srl was fined by the Garante for failing to notify data processing activities related to patients’ laboratory tests. The data could reveal infectious diseases, which required notification under the Italian data protection code.ITGaranteGDPR€40,000
29 Sept 2011Agenzia per le erogazioni in agricoltura (AGEA)The Italian Data Protection Authority fined Agenzia per le erogazioni in agricoltura (AGEA) EUR 40,000 for violations related to the processing of personal data within the National Agricultural Information System (Sian). The case concerned compliance of the processing activities with personal data protection requirements.ITGaranteGDPR€40,000
22 Nov 2012Synergo s.r.l.Synergo s.r.l. was fined by the Italian Garante for failing to notify the processing of sensitive health data. The case involved information on HIV status and infectious diseases, which should have been notified under the Italian data protection code.ITGaranteGDPR€40,000