Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
05 Jul 2018Vodafone Italia S.p.A.Vodafone Italia S.p.A. was fined EUR 800,000 by the Garante for making unsolicited promotional phone calls and sending SMS messages without proper consent. The authority found that these practices breached data protection rules.ITGaranteGDPR€800,000
03 Oct 2023Utbildningsnämnden i Stockholms stad – Aspuddens skolaThe Stockholm City Education Committee was fined by IMY 800,000 SEK for unlawful camera surveillance at Aspuddens school. The authority found breaches of legality and data minimization principles, as well as a failure to provide the required information under GDPR.SEIMYGDPR€68,744
20 Nov 2025SOCIETE AYANT POUR ACTIVITE L'EDITION DE REVUES ET PERIODIQUES ET LA REGIE PUBLICITAIRECNIL imposed an administrative fine of EUR 750,000 on SOCIETE AYANT POUR ACTIVITE L'EDITION DE REVUES ET PERIODIQUES ET LA REGIE PUBLICITAIRE. The case concerns a confirmed breach of rules supervised by the CNIL.FRCNILGDPR€750,000
27 Feb 2023Bank of Ireland 365 (‘BOI’)The Irish DPC fined Bank of Ireland 365 (‘BOI’) €750,000 in inquiry IN-20-7-2. The fine has been collected.IEDPCGDPR€750,000
27 Nov 2025Conde NastThe French data protection authority CNIL fined Conde Nast EUR 750,000 over cookie practices on the Vanity Fair website. The authority found that the company placed cookies without valid consent, did not provide sufficient information about necessary cookies, and made refusal and withdrawal mechanisms ineffective.FRCNILGDPR€750,000
03 Oct 2024Police Service of Northern IrelandThe Police Service of Northern Ireland was fined £750,000 by the ICO for breaches of Articles 5(1)(f), 32(1) and (2) of the UK GDPR between 25 May 2018 and 14 June 2024. The case concerned insufficient protection of personal data and inadequate security of processing. The decision indicates a failure to implement appropriate technical and organisational safeguards.GBICOGDPR€890,000
10 Oct 2024SOCIETE COMMERCIALISANT DES PORTEFEUILLES DE CRYPTOMONNAIEThe CNIL imposed an administrative fine of EUR 750,000 on SOCIETE COMMERCIALISANT DES PORTEFEUILLES DE CRYPTOMONNAIE. The record indicates a regulatory breach, but no further details are provided.FRCNILGDPR€750,000
22 Jul 2021TikTok Inc.TikTok Inc. was fined 750,000 EUR by the Dutch authority AP for providing its privacy policy to users in the Netherlands, including children, only in English. The authority found this breached Article 12 GDPR, which requires information to be provided in a clear and easily accessible form.NLAPGDPR€750,000
30 Apr 2020vingerafdrukken personeelThe Autoriteit Persoonsgegevens imposed a fine for the unlawful processing of employees' biometric data, specifically fingerprints, for time registration purposes. The authority found this to be a breach of Article 9 of the GDPR.NLAPGDPR€725,000
31 May 2019Kamerafelvételek kiadásának elmulasztásaThe controller did not inform the data subject about the actions taken on their requests within the required timeframe. It also failed to provide access to certain data, which constituted a GDPR breach.HUNAIHGDPR€2,156
14 Oct 2020Munkahelyi kamerás megfigyelés célhoz kötöttséggel, adattakarékossággal és az érintettek tájékoztatásával kapcsolatos hiányosságaiThe entity was fined by NAIH in the amount of HUF 700,000 for improperly implementing camera surveillance of employees. The authority also found that employees were not adequately informed about the scope and rules of the video monitoring.HUNAIHGDPR€1,925
17 Jan 2025Dane anonimowe (X. z siedzibą w K.)The UODO imposed administrative fines on X. based in K. for breaches of Article 6(1), Article 9(1), Article 13(1) and (2), Article 25(1), and Article 32(1) and (2) of the GDPR. These breaches also resulted in violations of the principles in Article 5(1)(a) and (f) and Article 5(2) of the GDPR.PLUODOGDPR€161,000
13 Nov 2024Illumia S.p.A.Illumia S.p.A. was fined by the Italian data protection authority, Garante, for violations related to the processing of personal data for telemarketing purposes. The authority cited inadequate contractual arrangements with sub-processors and insufficient oversight of commercial partners.ITGaranteGDPR€678,000
14 Apr 2023Sorgenia S.p.a.Sorgenia S.p.a. was fined EUR 676,956 by the Italian data protection authority, Garante. The case concerned failure to respect data deletion and objection rights in connection with unlawful telemarketing practices in the energy sector.ITGaranteGDPR€676,000
07 Jun 2021Voice Integrate Nordic ABVoice Integrate Nordic AB exposed audio files of recorded calls to 1177 Vårdguiden on the internet, including personal data. IMY found that the company failed to implement adequate safeguards under Article 32 GDPR and imposed a fine of SEK 650,000.SEIMYGDPR€64,643
11 May 2018Česká republika – Ministerstvo vnitraThe Ministry of the Interior was fined by UOOU for processing sensitive personal data, including DNA profiles, without explicit consent. The authority found this to be a breach of data protection law.CZUOOUGDPR€25,487
12 Oct 2023SOCIETE EDITANT DES CHAINES ET DISTRIBUANT DES OFFRES DE TELEVISION PAYANTESCNIL imposed a fine of EUR 600,000 on SOCIETE EDITANT DES CHAINES ET DISTRIBUANT DES OFFRES DE TELEVISION PAYANTES. The case concerns a confirmed regulatory breach, with no further details provided in the record.FRCNILGDPR€600,000
10 Jun 2020UniCredit S.p.A.UniCredit S.p.A. was fined by Garante EUR 600,000 for a data breach. The incident involved unauthorized access to personal data of about 762,000 individuals after an intrusion using credentials of employees from an external partner.ITGaranteGDPR€600,000
03 Aug 2022SOCIETE SPECIALISEE DANS LE SECTEUR DE L'HOTELLERIECNIL imposed a fine of 600,000 EUR on SOCIETE SPECIALISEE DANS LE SECTEUR DE L'HOTELLERIE. The case concerns a breach of rules supervised by the French data protection authority.FRCNILGDPR€600,000
24 Nov 2022SOCIETE FOURNISSANT DE l'ELECTRICITE, DU GAZ ET DES SERVICESCNIL imposed a fine of 600,000 EUR on SOCIETE FOURNISSANT DE l'ELECTRICITE, DU GAZ ET DES SERVICES. The available record indicates an administrative penalty issued by the French data protection authority.FRCNILGDPR€600,000