Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
15 Oct 2025Dane anonimowe (B. Sp. z o.o. z siedzibą w M. za naruszenie przepisu art. 33 ust. 1 rozporządzenia 2016/679)UODO imposed an administrative fine on B. Sp. z o.o. for failing to notify the President of the Personal Data Protection Office of a personal data breach without undue delay and, at the latest, within 72 hours of becoming aware of it. The case concerns the reporting obligation under Article 33(1) GDPR.PLUODOGDPR€9,519
14 Oct 2025CORAL TRAVEL & TOURISM SERVICES S.R.L.The operator was fined for violating GDPR provisions. The case concerned non-compliance with personal data protection requirements.ROANSPDCPGDPR€982
13 Oct 2025BANKINTER, S.A.BANKINTER, S.A. was fined by the AEPD 400,000 EUR for failing to implement adequate technical and organizational measures to ensure data integrity and confidentiality. The deficiency resulted in unauthorized access to personal data.ESAEPDGDPR€400,000
13 Oct 2025GLOBAL COAST INVESTMENTS, S.L.GLOBAL COAST INVESTMENTS, S.L. did not respond to a data access request. The AEPD found a breach of Article 15 GDPR and imposed a fine of 1,000 EUR.ESAEPDGDPR€1,000
13 Oct 2025Vellea Home SRLIn September 2025, the National Supervisory Authority for Personal Data Processing completed an investigation at Vellea Home SRL and found violations of GDPR provisions. The operator was fined EUR 5,000.ROANSPDCPGDPR€5,000
10 Oct 2025Capita plc and Capita Pension Solutions LimitedThe Information Commissioner's Office imposed a £14 million fine on Capita plc and Capita Pension Solutions Limited for UK GDPR infringements linked to a March 2023 cyber security breach. The case concerned inadequate technical and organisational measures and a delayed response to security alerts.GBInformation Commissioner's OfficeGDPR€16,074,000
09 Oct 2025SOCIETE EXERCANT UNE ACTIVITE DE VENTE A DISTANCE SUR CATALOGUE GENERAL (procédure simplifiée)The CNIL imposed an administrative fine of EUR 4,000 on SOCIETE EXERCANT UNE ACTIVITE DE VENTE A DISTANCE SUR CATALOGUE GENERAL. The case was handled under a simplified procedure.FRCNILGDPR€4,000
09 Oct 2025Arienti & C. s.r.l. a socio unicoThe Garante fined Arienti & C. s.r.l. a socio unico EUR 8,000 for denying a former employee access to their email account after the employment contract ended. The authority found this breached GDPR Article 15 on the right of access to personal data.ITGaranteGDPR€8,000
09 Oct 2025EON ENERGIE ROMANIA S.A.ANSPDCP completed an investigation at EON ENERGIE ROMANIA S.A. and found a breach of GDPR provisions. As a result, an administrative fine of EUR 25,000 was imposed.ROANSPDCPGDPR€25,000
09 Oct 2025Ordine delle Professioni Infermieristiche di PisaOrdine delle Professioni Infermieristiche di Pisa was fined by the Garante 16,000 EUR for breaches of data protection principles. The authority cited non-compliance with lawfulness, fairness, transparency, and data minimization requirements.ITGaranteGDPR€16,000
09 Oct 2025AD Media S.r.l.AD Media S.r.l. was fined EUR 5,000 by the Garante for sending promotional emails without proper consent. The authority found a breach of the principles of lawfulness, fairness, and transparency in data processing.ITGaranteGDPR€5,000
09 Oct 2025Provvedimento del 9 ottobre 2025 [10184697]The Garante imposed a EUR 70,000 fine on a company managing a hospital for violations related to the processing of health data. The case also involved a change in the complainant's treatment path and a failure to notify the authority of a data breach.ITGaranteGDPR€70,000
09 Oct 2025Ordine Interprovinciale dei Tecnici Sanitari di Radiologia Medica e delle Professioni Sanitarie Tecniche della Riabilitazione e della Prevenzione di AQ - CH - PE - TEThe Garante fined Ordine Interprovinciale dei Tecnici Sanitari 6,000 EUR for keeping an online disciplinary suspension record available despite the suspension being contested. The authority found breaches of lawfulness, fairness, transparency, data minimization, and accuracy.ITGaranteGDPR€6,000
09 Oct 2025FT Solutions S.r.l.FT Solutions S.r.l. was fined by the Garante 5,000 EUR for processing personal data for marketing purposes without proper consent. The case involved more than 2 million records and resulted in unauthorized telemarketing activities.ITGaranteGDPR€5,000
09 Oct 2025Sicuritalia S.p.A.Sicuritalia S.p.A. was fined EUR 500,000 by the Italian supervisory authority Garante. The case concerned unauthorized access to a former employee's email account after employment ended, in breach of GDPR requirements.ITGaranteGDPR€500,000
07 Oct 2025Anonymisiert (DSB 2025-0.778.661)An individual unlawfully accessed and processed personal data from a secured hard drive without a legitimate purpose. The authority found this to be a breach of core GDPR principles, including lawfulness and purpose limitation.ATDSBGDPR€2,500
04 Oct 2025OVH HISPANO, S.L.U.OVH HISPANO, S.L.U. was fined by the AEPD 120,000 EUR for a data protection breach. Confidential emails and documents of third parties were improperly shared due to inadequate data protection measures.ESAEPDGDPR€120,000
03 Oct 2025INTEGRAL DE VIGILANCIA Y CONTROL, S.L.INTEGRAL DE VIGILANCIA Y CONTROL, S.L. was fined by the AEPD 5,000 EUR for sending emails to a personal email address without a proper legal basis. The authority treated this as a breach of data protection rules.ESAEPDGDPR€5,000
02 Oct 2025TIGER MEDIA INC.TIGER MEDIA INC. was fined by the AEPD EUR 120,000 for processing personal data without a lawful basis. The authority also found that the company failed to appoint an EU representative, in breach of GDPR Articles 6 and 27.ESAEPDGDPR€120,000
02 Oct 2025EMAGISTER SERVICIOS DE FORMACIÓN, S.L.EMAGISTER SERVICIOS DE FORMACIÓN, S.L. was fined EUR 80,000 by the AEPD for a data security incident involving unauthorized processes on its web servers. The authority found a breach of data protection principles.ESAEPDGDPR€80,000