Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
15 Jul 2022URBANO DIVERTIA, S.L.URBANO DIVERTIA, S.L. was fined by the AEPD 2,000 EUR for sending clients documents that contained personal data of third parties. The company also failed to include a reference to its privacy policy in corporate emails, which breached data protection requirements.ESAEPDGDPR€2,000
27 May 2024Urban Home Development S.R.L.Urban Home Development S.R.L. was fined 10,000 RON by ANSPDCP. The sanction was imposed for violating the provisions of Law no. 506/2004.ROANSPDCPePrivacy€2,010
12 Nov 2024Uptime-IT ApSUptime-IT ApS was fined by Datatilsynet 40,000 DKK for failing to implement adequate security measures as a data processor. This led to a ransomware attack that encrypted sensitive personal data, including health information and CPR numbers, which could not be restored.DKDatatilsynetGDPR€5,362
13 Nov 2024UP ROMÂNIA SRLUP ROMÂNIA SRL was fined EUR 4,000 by ANSPDCP for processing employees’ identification and location data during their free time without a legal basis. The authority found breaches of legality, transparency, and data minimization principles.ROANSPDCPGDPR€4,000
14 Dec 2020Uppsalahem ABUppsalahem AB was fined for unlawful video surveillance in a residential building. The authority found that the company did not properly balance its surveillance interests against residents’ privacy rights under GDPR Article 6(1)(f).SEIMYGDPR€29,433
05 Jul 2023UPMOBILE SOLUTIONS, S.L.UPMOBILE SOLUTIONS, S.L. was fined EUR 500 by the AEPD for failing to provide access during the investigation. The authority treated this as a breach of Article 58(1) GDPR and an obstruction of its supervisory function.ESAEPDGDPR€500
11 Dec 2025UPGYMS IBERIA, S.L.UPGYMS IBERIA, S.L. was fined by the AEPD EUR 5,000 for sending unsolicited commercial SMS messages without obtaining recipient consent. The conduct breached the LSSI rules on marketing communications.ESAEPDePrivacy€5,000
30 Oct 2024Untold SRLIn September 2024, ANSPDCP completed an investigation at Untold SRL and found violations of GDPR provisions. As a result, the company was fined EUR 10,000.ROANSPDCPGDPR€10,000
30 Oct 2024Untold SRLUntold SRL was fined EUR 5,000 by ANSPDCP for violations of GDPR provisions. The case concerned non-compliance with personal data protection requirements.ROANSPDCPGDPR€5,000
30 Jan 2026un operator persoană fizicăAn individual operator was fined 3,000 EUR for GDPR violations. The case concerned non-compliant processing of personal data and was handled by ANSPDCP.ROANSPDCPGDPR€3,000
30 Jan 2026un operator persoană fizicăAn individual operator was fined 1,000 EUR by ANSPDCP for GDPR violations. The case concerned non-compliance with personal data protection requirements.ROANSPDCPGDPR€1,000
30 Jan 2026un operator persoană fizicăA 1,000 EUR fine was imposed on an individual operator for GDPR violations. The case concerned non-compliance with personal data protection requirements.ROANSPDCPGDPR€1,000
30 Jan 2026un operator persoană fizicăA fine of 5,000 EUR was imposed on an individual controller by ANSPDCP for GDPR violations. The case concerned non-compliance with personal data protection requirements.ROANSPDCPGDPR€5,000
10 Dec 2024un operatorANSPDCP imposed a fine of 10,000 RON on un operator for non-compliance with the law. A warning was also issued.ROANSPDCPGDPR€2,012
15 May 2026Unnamed Hungarian employerHungary’s data protection authority, NAIH, imposed a HUF 7 million GDPR fine on an unnamed employer. The case involved continuous camera monitoring in employee dining and rest areas, as well as deficiencies in documentation and privacy notices.HUNemzeti Adatvédelmi és Információszabadság HatóságGDPR€19,460
01 Jan 2024Unnamed data controllerNAIH imposed a HUF 50 million fine on an unnamed public body for failing to provide data to the Central Public Information Register. The case concerned non-publication of financial data required by law.HUNemzeti Adatvédelmi és Információszabadság HatóságGDPR€130,000
04 Apr 2025Unnamed bankThe Polish data protection authority imposed a fine of EUR 928,498.06 on a bank. The authority found that the bank failed to inform customers about a personal data breach. The case concerns post-incident notification obligations.PLPolish Data Protection AuthorityGDPR€928,000
04 Jun 2013UN LUGAR DIFERENTE. S.L.UN LUGAR DIFERENTE. S.L. was fined by the AEPD for sending unauthorized commercial SMS messages to a customer. The messages were sent despite the customer's prior request to opt out.ESAEPDePrivacy€600
12 Feb 2026Unleadmited S.r.l.Unleadmited S.r.l. was fined EUR 5,000 by the Garante for violations linked to aggressive telemarketing practices. The authority found non-compliance with data protection requirements.ITGaranteGDPR€5,000
06 Jul 2022Uniwersyteckie CentrumThe Polish DPA (UODO) imposed an administrative fine of PLN 10,000 on Uniwersyteckie Centrum Kliniczne Uniwersytetu Medycznego. The authority found that the entity failed to report the personal data breach without undue delay and did not notify the affected individuals without undue delay.PLUODOGDPR€2,096