Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
02 Oct 2025RETSINNAL GROUP, S.L.U.RETSINNAL GROUP, S.L.U. was fined 1,000 EUR by the AEPD for deficiencies in its website privacy policy. The authority found that the company did not provide adequate information about the data controller, in breach of Article 13 GDPR.ESAEPDGDPR€1,000
02 Oct 2025UNIVERSITE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 15,000 on UNIVERSITE (procédure simplifiée). The case concerns a breach of rules supervised by the CNIL.FRCNILGDPR€15,000
25 Sept 2025JacksonsThe ODPA fined Jacksons £65,000 after finding that the company unlawfully changed customer marketing preferences. The investigation identified anomalies in customer records and direct marketing communications made against customers’ wishes.GGODPAGDPR€74,302
25 Sept 2025Officine Serena s.r.l.Green.mec. s.r.l. did not respond to a data subject’s request for training certificates and communications related to the termination of employment. The Garante imposed a fine of 1,000 EUR on Officine Serena s.r.l., the incorporating company.ITGaranteGDPR€1,000
25 Sept 2025Vimar S.p.A.Vimar S.p.A. was fined EUR 15,000 by the Garante for failing to provide adequate information to a complainant and for improper account handling. The account was accessible to unauthorized individuals, indicating weaknesses in access control and safeguards.ITGaranteGDPR€15,000
25 Sept 2025RCS MediaGroup S.p.a.RCS MediaGroup S.p.a. was fined by the Italian data protection authority, Garante, in the amount of EUR 100,000. The case concerned the publication of images of a person in a private setting without consent, which infringed privacy rights.ITGaranteGDPR€100,000
25 Sept 2025Provincia Autonoma di TrentoProvincia Autonoma di Trento was fined for processing personal data without a legal basis, lacking transparency, and failing to conduct a data protection impact assessment. The authority found breaches of several GDPR provisions.ITGaranteGDPR€8,000
25 Sept 2025S.C. PRIMONET RO S.R.L.The company was fined for a data security breach that enabled unauthorized transactions on affected cards. The incident caused financial losses to the data subjects.ROANSPDCPGDPR€20,000
25 Sept 2025Comune di Isola del Gran Sasso d’ItaliaThe Garante fined the Comune di Isola del Gran Sasso d’Italia EUR 3,000 for unlawfully publishing personal data on its institutional website, including information related to criminal proceedings. The authority found breaches of lawfulness, fairness, transparency, and data minimization.ITGaranteGDPR€3,000
25 Sept 2025Comune di PazzanoThe Garante imposed a fine of 3,960 EUR on Comune di Pazzano for failing to meet data protection obligations. The case concerned, among other issues, the improper provision of the Data Protection Officer’s contact details and other GDPR requirements.ITGaranteGDPR€3,960
25 Sept 2025La Prima SrlLa Prima Srl was fined EUR 10,000 by the Garante for sending unsolicited emails. The authority also found that the company failed to respond to a data deletion request, in breach of the GDPR.ITGaranteGDPR€10,000
25 Sept 2025E-Power S.r.l.E-Power S.r.l. was fined EUR 35,000 by the Garante for making promotional calls without a valid legal basis. The authority also found that the company failed to respond to data subject rights requests, which breaches GDPR requirements.ITGaranteGDPR€35,000
25 Sept 2025Azienda Ospedaliero Universitaria di FerraraAzienda Ospedaliero Universitaria di Ferrara was fined EUR 20,000 by the Garante for irregularities in the handling of personal data in its health dossier system. The authority found that the organization failed to implement adequate measures to protect data privacy.ITGaranteGDPR€20,000
18 Sept 2025SOCIETE EXPLOITANT UN GRAND MAGASINCNIL imposed an administrative fine of EUR 100,000 on SOCIETE EXPLOITANT UN GRAND MAGASIN. The case concerns a breach of rules supervised by CNIL.FRCNILGDPR€100,000
18 Sept 2025Dr.Max SRLIn August of the current year, ANSPDCP completed an investigation at Dr.Max SRL and found a breach of GDPR provisions. As a result, the operator was fined EUR 1,000.ROANSPDCPGDPR€1,000
16 Sept 2025Bharat Singh ChandBharat Singh Chand, a self-employed lead generator, sent or instigated the sending of 966,449 direct marketing SMS messages between 3 December 2023 and 3 July 2024. The activity breached regulations 22 and 23 of PECR and generated 19,138 complaints to the 7726 spam reporting service. He was fined £200,000 and issued with an enforcement notice.GBICOePrivacy€231,000
12 Sept 2025Dane anonimowe (Q. Sp. z o.o.)The Polish DPA (UODO) imposed an administrative fine of PLN 11,365 on Q. Sp. z o.o. The authority found a breach of Article 38(6) GDPR because the data protection officer role was performed by the company’s president.PLUODOGDPR€2,669
12 Sept 2025A Düsseldorf-based personnel recruitment companyOn 2025-09-12, the LDI NRW announced a data protection fine of over 35,000 EUR against a Düsseldorf-based personnel recruitment company. The authority said the company repeatedly ignored job seekers’ requests for access and deletion and failed to respond to the supervisory authority’s inquiries.DELandesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-WestfalenGDPR€35,000
11 Sept 2025ISV Group SrlsISV Group Srls was fined €15,000 by the Garante for sending unsolicited promotional emails without consent. The authority also found that the company failed to properly control its partner Ismax, which carried out unlawful data processing activities.ITGaranteGDPR€15,000
11 Sept 2025Ministero dell’Interno - Dipartimento dei Vigili del Fuoco, del Soccorso Pubblico e della Difesa CivileThe Ministry of the Interior – Department of Firefighters was fined EUR 12,000 by the Garante. The case concerned personal data processing in breach of GDPR Articles 5, 6 and 9, as well as Articles 2-ter and 2-sexies of the Italian Privacy Code.ITGaranteGDPR€12,000