Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
17 Dec 2021Kormánytisztviselő jogviszonyának megszűnésével összefüggésben egészségügyi adat kezelése, és erre irányuló hozzáférés megtagadásaThe authority found that the controller unlawfully denied access to personal data and failed to provide complete information about data processed in connection with the termination of employment. This breached GDPR Articles 12, 14, and 15.HUNAIHGDPR€1,632
29 Nov 2018Wind Tre S.p.A.Wind Tre S.p.A. was fined EUR 600,000 by the Garante for unsolicited promotional calls and SMS. The authority found breaches of several provisions of the Italian Data Protection Code.ITGaranteGDPR€600,000
05 Oct 2020Pontosság elvének megsértéseThe controller was fined for processing inaccurate personal data, in breach of the accuracy principle under GDPR Art. 5(1)(d). The authority also ordered correction of the complainant’s address data.HUNAIHGDPR€1,674
16 Jul 2024A.S. Watson Health & Beauty Continental Europe B.V.A.S. Watson Health & Beauty Continental Europe B.V. was fined 600,000 EUR by the Dutch AP. The authority found that the company processed personal data without a lawful basis because it failed to obtain consent for tracking cookies on kruidvat.nl, breaching GDPR Articles 5 and 6.NLAPGDPR€600,000
08 Aug 2019Zala Megyei Kormányhivatal Keszthelyi Járási FöldhivatalThe Zala Megyei Kormányhivatal Keszthelyi Járási Földhivatal was fined 600,000 HUF by NAIH for breaching the principles of data minimization and transparency. The authority found that personal data was made accessible to third parties without clear information about the processing.HUNAIHGDPR€1,848
03 Jul 2025SOCIETE AYANT POUR ACTIVITE LA VENTE A DISTANCE DE MOBILIER, DECORATION ET D'EQUIPEMENTS DOMESTIQUESThe CNIL imposed an administrative fine of 600,000 EUR on a company engaged in distance selling of furniture, decoration, and household equipment. The case concerns a breach of rules supervised by the CNIL.FRCNILGDPR€600,000
08 Jul 2022Egészségügyi dokumentáció másolatának kiadásaThe controller breached the GDPR by failing to provide adequate access to personal health data and by not ensuring transparency and information rights. As a result, the authority imposed a fine of HUF 600,000.HUNAIHGDPR€1,488
05 Apr 2019Budapesti Műszaki és Gazdaságtudományi EgyetemBudapest University of Technology and Economics was fined 600,000 HUF by NAIH. The authority found that the university failed to comply with a data subject's request for access to personal data.HUNAIHGDPR€1,872
16 Jul 2024AS Watson / KruidvatThe Dutch data protection authority, Autoriteit Persoonsgegevens, imposed a fine of EUR 600,000 on AS Watson / Kruidvat. The case concerns a breach of GDPR cookie consent rules.NLAutoriteit PersoonsgegevensGDPR€600,000
22 May 2018Wind Tre s.p.a.Wind Tre s.p.a. was fined by the Garante EUR 600,000 for conducting marketing campaigns without obtaining the required user consent. The conduct breached data protection rules.ITGaranteGDPR€600,000
29 Apr 2021Gemeente EnschedeThe municipality of Enschede was fined by AP for processing personal data of mobile device owners and users without a legal basis. The authority found violations of GDPR Articles 5 and 6.NLAPGDPR€600,000
06 Apr 2022Minister van Buitenlandse ZakenThe Dutch Data Protection Authority fined the Minister of Foreign Affairs for failing to provide adequate information to data subjects and for insufficient security measures. The issues concerned the processing of personal data in connection with Schengen visa applications.NLAPGDPR€565,000
12 Mar 2026Enel Energia S.p.A.Enel Energia S.p.A. was fined by the Italian data protection authority, Garante, for making unwanted telemarketing calls without a proper legal basis. The authority found that the company’s conduct breached data protection principles.ITGaranteGDPR€563,000
09 Jun 2025Department of Social ProtectionThe Irish DPC imposed a fine of €550,000 on the Department of Social Protection in inquiry IN-21-7-3. The matter is currently pending appeal (TBC).IEDPCGDPR€550,000
10 Dec 2020Umeå universitetUmeå University was fined by IMY 550,000 SEK for sending sensitive personal data via unencrypted email and open networks. The authority found that this breached GDPR security requirements.SEIMYGDPR€53,713
01 Jan 2022GLOVOAPP23, S.L.GLOVOAPP23, S.L. was fined by the AEPD for processing a broad range of delivery riders’ personal data without adequate data protection measures. The authority found breaches of GDPR Articles 25 and 32, relating to privacy by design and processing security.ESAEPDGDPR€550,000
19 Jan 2022Dane anonimowe (U.)UODO imposed an administrative fine of 545,748 PLN on Dane anonimowe (U.) for failing to notify data subjects without undue delay about a personal data breach. The case concerns the obligation to promptly inform affected individuals under data protection rules.PLUODOGDPR€120,000
13 Nov 2020Y HuisvestingsmaatschappijThe social housing company was fined for breaching GDPR principles, including lawfulness and transparency in personal data processing. The authority also identified deficiencies in access rights handling and privacy policy transparency.BEAPDGDPR€528,000
04 Apr 2024COMMERCE DE DETAIL DE MATERIEL DE TELECOMMUNICATIONCNIL imposed an administrative fine of EUR 525,000 on COMMERCE DE DETAIL DE MATERIEL DE TELECOMMUNICATION. The case concerns identified breaches of rules supervised by CNIL.FRCNILGDPR€525,000
12 May 2021Locatefamily.comLocatefamily.com was fined for failing to appoint an EU representative, in breach of GDPR Article 27. The authority also imposed a penalty payment because the violation remained unresolved.NLAPGDPR€525,000