Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
10 Dec 2025University of LimerickThe Irish DPC fined University of Limerick 98,000 EUR in inquiry IN-19-7-1. The record notes the status as not confirmed.IEDPCGDPR€98,000
17 Dec 2020University College DublinThe Irish DPC imposed a fine of EUR 70,000 on University College Dublin in inquiry IN-19-7-4. The fine has been collected.IEDPCGDPR€70,000
11 Sept 2024Universitetet i AgderThe Norwegian DPA, Datatilsynet, fined the University of Agder 150,000 NOK for failing to implement adequate measures to protect personal data in Microsoft Teams. The incident exposed sensitive information relating to around 16,000 individuals.NODatatilsynetGDPR€12,566
31 Dec 2025UNIVERSITE (procédure simplifiée)CNIL imposed an administrative fine of EUR 20,000 on UNIVERSITE (procédure simplifiée). The case concerned a confirmed breach of rules supervised by CNIL.FRCNILGDPR€20,000
29 Dec 2022UNIVERSITE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 10,000 on UNIVERSITE (procédure simplifiée). The record indicates a regulatory breach, but no further details are provided.FRCNILGDPR€10,000
02 Oct 2025UNIVERSITE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 15,000 on UNIVERSITE (procédure simplifiée). The case concerns a breach of rules supervised by the CNIL.FRCNILGDPR€15,000
14 Mar 2013Università Telematica San Raffaele RomaUniversità Telematica San Raffaele Roma was fined by the Garante EUR 6,000 for providing inadequate data protection information through its enrollment and information request forms on its website. The case concerned a breach of Article 13 of the Italian Privacy Code.ITGaranteGDPR€6,000
16 Dec 2021Università Telematica Internazionale UninettunoUniversità Telematica Internazionale Uninettuno was fined EUR 1,000 by the Italian supervisory authority Garante. The authority found breaches of lawfulness, fairness, transparency, and data minimization principles.ITGaranteGDPR€1,000
18 Jul 2023Università Telematica E-CampusUniversità Telematica E-Campus was fined EUR 75,000 by the Garante. The authority found that the university sent promotional SMS messages without consent and failed to respond to data deletion requests. These actions breached GDPR requirements.ITGaranteGDPR€75,000
29 Jan 2026Università Telematica e-CampusThe Garante fined Università Telematica e-Campus EUR 50,000 for violations related to biometric data processing. The authority also found that the university failed to carry out a proper Data Protection Impact Assessment (DPIA).ITGaranteGDPR€50,000
01 Jan 2024UNIVERSITAS NEBRISSENSIS, S.A.UNIVERSITAS NEBRISSENSIS, S.A. was fined by the AEPD EUR 50,000 for requesting a full copy of a student's ID. The authority found that this breached GDPR data minimization principles and security requirements.ESAEPDGDPR€50,000
18 Sept 2008Universitalia s.r.l.Universitalia s.r.l. was fined €6,000 by the Italian data protection authority, Garante. The authority found that the company failed to provide adequate privacy information to data subjects as required by the Italian Data Protection Code.ITGaranteGDPR€6,000
11 Sept 2025Università degli Studi di VeronaUniversità degli Studi di Verona was fined by the Garante €9,000 for improperly handling personal data during a research project. The authority found a breach of GDPR requirements for lawful, fair, and transparent processing.ITGaranteGDPR€9,000
11 Mar 2021Università degli Studi di Napoli Federico IIUniversità degli Studi di Napoli Federico II was fined by the Garante in the amount of 10,000 EUR for breaches of data protection principles. The authority found violations of lawfulness, fairness, transparency, and data minimization in the processing of personal data.ITGaranteGDPR€10,000
22 Jul 2021Università degli Studi di Milano-BicoccaUniversità degli Studi di Milano-Bicocca was fined EUR 10,000 by the Garante for data protection violations linked to the publication of personal data on its institutional website. The case concerned the disclosure of information on the university’s website, which breached data processing rules.ITGaranteGDPR€10,000
17 Mar 2016Università degli studi di FoggiaUniversità degli studi di Foggia was fined 4,000 EUR by the Garante for unlawfully disclosing health-related data to third parties. The authority found that the disclosure lacked an appropriate legal basis and breached privacy rules.ITGaranteGDPR€4,000
10 Jul 2025Università degli Studi di Cassino e del Lazio MeridionaleThe University of Cassino and Southern Lazio was fined €8,000 by the Garante for failing to comply with data protection rules. The case concerned improper handling of personal data requests and deficiencies in administrative procedures.ITGaranteGDPR€8,000
27 Apr 2023Università degli studi di Cassino e del Lazio MeridionaleThe University of Cassino and Southern Lazio was fined EUR 4,000 by the Garante for improperly disclosing a complainant’s personal data to all Italian universities. The disclosure also included data relating to criminal offenses, breaching GDPR principles of lawfulness, fairness, and transparency.ITGaranteGDPR€4,000
16 Sept 2021Università Commerciale “Luigi Bocconi” di MilanoUniversità Commerciale “Luigi Bocconi” di Milano was fined EUR 150,000 by the Garante for data protection breaches during remote exams. The authority found an insufficient legal basis, inadequate transparency, and weak security measures for transfers of data to the USA.ITGaranteGDPR€150,000
01 Oct 2020Università Campus Bio-medico di RomaThe Garante fined Università Campus Bio-medico di Roma 20,000 EUR for a data protection breach. Online medical reports were accessible to other patients, resulting in unauthorized disclosure of sensitive information.ITGaranteGDPR€20,000