Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
07 Apr 2022Анонимизирано (CPDP решение-по-жалба-с-рег-№-ппн-01-101136-0)The CPDP imposed fines on two individuals for unlawful video surveillance in a co-owned property. The authority found breaches of GDPR principles of lawfulness and data minimization.BGCPDPGDPR€1,534
12 Feb 2018Анонимизирано (CPDP решение-по-жалба-с-рег-№-ж-453-05-10-201)The Commission fined an individual for unlawfully processing personal data by including it in a list supporting registration for a referendum campaign without consent. The case concerned a breach of the legal basis requirements for personal data processing.BGCPDPGDPR€5,113
16 Jun 2025Υφυπουργείο Κοινωνικής ΠρόνοιαςThe Cypriot Data Protection Commissioner imposed an administrative fine of EUR 5,000 on Υφυπουργείο Κοινωνικής Πρόνοιας on 16 June 2025. The case concerned CCTV cameras at the ministry’s headquarters, including three cameras that recorded audio without a legal basis and without the required GDPR safeguards.CYΕπίτροπος Προστασίας Δεδομένων Προσωπικού ΧαρακτήραGDPR€5,000
16 Jan 2026Πυροσβεστικό ΣώμαThe Hellenic Data Protection Authority imposed a €10,000 fine on the Fire Service for unlawfully processing an employee’s special-category health data. The authority found breaches of GDPR lawfulness and data minimization principles and noted that the data were accessible through an internal electronic application.GRΑρχή Προστασίας Δεδομένων Προσωπικού ΧαρακτήραGDPR€10,000
10 Mar 2025Οργανισμός Χρηματοδοτήσεως ΣτέγηςThe Housing Finance Corporation was fined by the CyDPC in the amount of €10,000 for retaining personal data beyond the legal retention period. The authority found this breached GDPR storage limitation and data accuracy requirements.CYCyDPCGDPR€10,000
03 Feb 2022Κοινοτικό Συμβούλιο ΒορόκληνηςThe Community Council of Voroklini was fined by the CyDPC for failing to exercise due diligence in the processing of personal data. This led to unauthorized changes to mailing addresses without proper consent.CYCyDPCGDPR€2,000
30 Mar 2026Κέντρο Εκπαίδευσης και Αποκατάστασης Τυφλών (ΚΕΑΤ)The Greek Data Protection Authority fined ΚΕΑΤ EUR 5,000 for an untimely and improper response to an employee’s request for access to CCTV footage. The case involved edited footage, missing material, and inadequate technical and organizational measures to support compliance.GRΑρχή Προστασίας Δεδομένων Προσωπικού ΧαρακτήραGDPR€5,000
22 Oct 2025εκδοτικός οίκοςThe Greek Data Protection Authority fined a publishing house EUR 9,000 for disclosing an author's personal and special-category data in an email sent to 55 recipients. It also found failures to implement data protection by design and to notify both the authority and the data subject of the breach.GRΑρχή Προστασίας Δεδομένων Προσωπικού ΧαρακτήραGDPR€9,000
16 Jan 2023Εκδόσεις Αρκτίνος ΛτδThe decision concerns the unlawful publication of names and photos of police investigators by the newspaper “Politis”. The authority found a breach of the data minimization principle under the GDPR.CYCyDPCGDPR€10,000
01 Jan 2025Εθνική Τράπεζα της Ελλάδος Α.Ε.The data protection authority imposed a EUR 220,000 fine on Εθνική Τράπεζα της Ελλάδος Α.Ε. for a GDPR violation. The case concerned deficiencies in personal data protection and compliance with GDPR requirements.GRΑρχή Προστασίας Δεδομένων Προσωπικού ΧαρακτήραGDPR€220,000
21 Sept 2022Αρχή Ηλεκτρισμού ΚύπρουThe Cyprus DPA fined the Cyprus Electricity Authority €5,000 for a personal data breach involving unauthorized disclosure to a third party. The authority found violations of GDPR Articles 5(1)(f), 24(1), and 32.CYCyDPCGDPR€5,000
18 Feb 2020ZSZZS.440.768.2018StatusuchylonaTytuUODO found a breach related to the processing of children’s biometric data in connection with use of the school canteen. A fine of PLN 20,000 was imposed.PLUODOGDPR€4,679
21 Aug 2020ZSOUODO imposed a PLN 50,000 fine on ZSO for breaching personal data protection rules. The case concerned non-compliance with requirements under data protection regulations.PLUODOGDPR€11,369
18 Nov 2015Zsa Zsa srlZsa Zsa srl was fined EUR 2,400 by the Italian Garante. The violation concerned the failure to provide the required privacy notice on the website’s data collection form, in breach of the Italian data protection code.ITGaranteGDPR€2,400
02 Feb 2024[...] Zrt.The controller did not provide adequate information about data processing through camera systems in bank branches. This constituted a breach of GDPR Articles 12 and 13.HUNAIHGDPR€156,000
01 Jan 2015ZOWROOM, S.L.ZOWROOM, S.L. was fined by the AEPD EUR 500 for sending unsolicited commercial emails. The authority also found that unsubscribe requests were not honored, which constitutes a breach of the LSSI.ESAEPDePrivacy€500
15 Jan 2015Zoccatelli MichelaZoccatelli Michela was fined EUR 2,400 by the Garante for failing to provide information to individuals applying for membership in the private Aquila Club. The authority treated this as a breach of data protection rules.ITGaranteGDPR€2,400
11 Dec 2025ZMLUK LimitedZMLUK Limited received an MPN from the ICO for sending unsolicited emails promoting energy-saving products. The case concerns a breach of electronic marketing rules and should be reviewed for compliance with applicable consent requirements.GBICOGDPR€119,000
12 May 2022Zito Auto di Gianfranco ZitoThe company was fined for operating a video surveillance system that did not meet the information requirements under GDPR Article 13 and Article 114 of the Italian Privacy Code. The authority found that the required notices for monitored individuals were not properly provided.ITGaranteGDPR€3,000
31 Mar 2016Zhu XiaozhenZhu Xiaozhen was fined by the Garante for failing to provide the simplified information required under the data protection code and the video surveillance rules. The surveillance system was operated without proper notice to the individuals concerned.ITGaranteGDPR€2,400