Subscribe

Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

35 entries

Filters
Clear all
ImposedCompanyCountryAuthorityTypeAmount
02121 May 2025NN ΕλληνικήThe Greek Data Protection Authority imposed a €22,000 fine on NN Ελληνική for refusing to provide recorded telephone calls in response to a data subject access request. The case concerns failure to comply with access rights obligations under data protection law.GRΑρχή Προστασίας Δεδομένων Προσωπικού ΧαρακτήραData subject access request violation€22,000
02229 Apr 2025Ordine professionale degli psicologi della LombardiaOn 2025-04-29, the Italian Data Protection Authority fined the Ordine professionale degli psicologi della Lombardia EUR 30,000. The sanction concerned breaches of Articles 5(1)(f) and 32 GDPR following a data breach and the failure to implement adequate security measures.ITGarante per la protezione dei dati personaliFailure to implement adequate security measures€30,000
02323 Apr 2025MetaThe European Commission fined Meta EUR 200 million for breaching the Digital Markets Act. The sanction concerns Meta’s “consent or pay” model used for Facebook and Instagram users in Europe.IEEuropean CommissionDigital Markets Act violation€200,000,000
02401 Apr 2025BitdefenderBitdefender received a GDPR fine of EUR 10,000 from the Romanian data protection authority. The sanction followed an investigation completed in April 2025 after a data breach notification, with the authority citing inadequate technical and organizational security measures.ROAutoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter PersonalGDPR data security breach€10,000
02501 Jan 2025Sambla GroupThe Finnish Data Protection Authority fined Sambla Group EUR 950,000 after unauthorized parties accessed credit application data by manipulating web addresses. The authority found that the company had not implemented adequate safeguards to prevent the breach.FITietosuojavaltuutetun toimistoInsufficient security measures€950,000
02627 Sept 2024Meta Platforms Ireland LimitedThe Irish Data Protection Commission fined Meta Platforms Ireland Limited EUR 91,000,000 for inadequate protection of Facebook and Instagram user passwords. According to the decision, the company stored passwords in plain text without proper encryption, and the final decision was announced on 2024-09-27.IEIrish Data Protection CommissionData security€91,000,000
02705 Oct 2023DPP Law LtdThe Information Commissioner's Office issued a monetary penalty notice against DPP Law Ltd. The firm was fined GBP 60,000 for failing to implement appropriate technical and organisational measures to secure personal data.GBInformation Commissioner's OfficeData security£60,000
02804 Oct 2023Amazon EuropeThe CNPD imposed a fine of EUR 746,000,000 on Amazon Europe for breaches of data protection rules. The case concerned shortcomings in the processing of personal data and compliance with GDPR requirements.LUCNPDGDPR€746,000,000
02922 May 2023Meta PlatformsIreland's Data Protection Commission imposed a EUR 1.2 billion GDPR fine on Meta Platforms in May 2023. The case concerned unlawful transfer of EU user data to the US.IEIreland Data Protection CommissionUnlawful data transfer€1,200,000,000
03028 Mar 2023Sky Italia S.r.l.The Italian Data Protection Authority fined Sky Italia S.r.l. EUR 842,062 for violations related to telemarketing and commercial communications. The company failed to properly verify consent, relied on outdated consents, and did not check the Public Register of Oppositions before campaigns.ITGarante per la protezione dei dati personaliGDPR telemarketing€842,062
03104 Jan 2023MetaMeta, the parent company of Facebook and Instagram, was fined 390 million euros by the Irish Data Protection Commission in 2023. The authority cited GDPR violations related to consent for personalized advertising.IEIrish Data Protection CommissionGDPR consent violation€390,000,000
03202 Sept 2022Meta Platforms, Inc.Ireland's Data Protection Commission fined Meta Platforms, Inc. 405 million euros for the handling of minors' data on Instagram. The case involved public exposure of contact details and default public business accounts.IEData Protection CommissionPersonal data processing€405,000,000
03302 Sept 2021WhatsAppWhatsApp was fined 225 million EUR by the Irish Data Protection Commission in 2021. The authority cited violations related to privacy policies and insufficient transparency about how user data was used.IEIrish Data Protection CommissionTransparency violation€225,000,000
03401 Jan 2021Município de LisboaThe Portuguese data protection authority fined Município de Lisboa EUR 1,250,000 in 2021. The sanction concerned the unlawful transfer of protesters’ personal data to the Russian Embassy in breach of the GDPR.PTComissão Nacional de Proteção de DadosGDPR data transfer violation€1,250,000
03525 Feb 2020Addiko Bank d.d.The High Administrative Court of the Republic of Croatia upheld AZOP’s decision of 25 February 2020 against Addiko Bank d.d. The confirmed administrative fine was 145,995.09 EUR for obstructing customers’ access to their personal data and credit documentation.HRAZOPGDPR access rights violation€145,995