Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.6%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
21 Mar 2018Ordinanza ingiunzione - 21 marzo 2018 [9004702]The Garante imposed a EUR 92,000 fine on a medical professional for processing the personal data of 23 patients without the required consent. The authority found a breach of privacy and data protection rules.ITGaranteGDPR€92,000
15 Oct 2015Ordinanza ingiunzione - 15 ottobre 2015 [4703503]A fine was imposed for activating 85 SIM cards in the names of 31 people without their knowledge. The conduct breached data protection rules.ITGaranteGDPR€93,000
23 Jun 2025Dane anonimowe (U.)UODO imposed a PLN 94,286 administrative fine on an anonymous entity for improperly vetting a processor before entering into a data processing agreement. The authority also found inadequate technical and organizational safeguards, insufficient testing of their effectiveness, and failure to properly involve the data protection officer in privacy matters.PLUODOGDPR€22,053
24 Jan 2024CAJA RURAL DE GIJÓN, S.C.A.C.CAJA RURAL DE GIJÓN was fined by the AEPD 95,000 EUR for breaching data protection principles, specifically confidentiality and integrity. The incident resulted in unauthorized access to personal data and indicates a significant compliance failure.ESAEPDGDPR€95,000
26 Mar 2026Eni S.p.A.Eni S.p.A. was fined 96,000 EUR by the Garante for publishing personal data on its website, including dates of birth and addresses, without proper masking. The authority found this breached GDPR principles of lawfulness, fairness, and transparency.ITGaranteGDPR€96,000
09 Nov 2017GSG Enterprise società cooperativa edileGSG Enterprise was fined EUR 96,000 by the Garante for using the personal data of car owners to demand payment for services that were neither performed nor requested. The case concerns unlawful processing of personal data for debt-collection style demands.ITGaranteGDPR€96,000
10 Dec 2025University of LimerickThe Irish DPC fined University of Limerick 98,000 EUR in inquiry IN-19-7-1. The record notes the status as not confirmed.IEDPCGDPR€98,000
31 Jan 2024EDITEUR DE SITE WEB PROPOSANT AUX PARTICULIERS DE PUBLIER OU CONSULTER DES ANNONCES IMMOBILIERES ET AUTRES SERVICESCNIL imposed an administrative fine of EUR 100,000 on EDITEUR DE SITE WEB PROPOSANT AUX PARTICULIERS DE PUBLIER OU CONSULTER DES ANNONCES IMMOBILIERES ET AUTRES SERVICES. The case concerns identified breaches of rules supervised by the CNIL.FRCNILGDPR€100,000
16 May 2023UK Direct Business Solutions LimitedUK Direct Business Solutions Limited was fined by the ICO for making 410,369 unsolicited marketing calls to businesses registered with the CTPS or TPS. The calls were made between 1 March 2020 and 31 October 2021 and breached rules on telephone marketing.GBICOGDPR€115,000
17 Aug 2021BANCO BILBAO VIZCAYA ARGENTARIA, S.A.Banco Bilbao Vizcaya Argentaria, S.A. was fined by the AEPD for sending unsolicited SMS messages to the complainant's mobile phone. The company also failed to remove the number from its database after the request, which constituted a data protection breach.ESAEPDGDPR€100,000
17 Apr 2024BANCO BILBAO VIZCAYA ARGENTARIA, S.A.BBVA was fined EUR 100,000 by the AEPD for processing a payment to a new account without the account holder’s explicit consent. The authority found this conduct to be a breach of GDPR Article 6.ESAEPDGDPR€100,000
04 Mar 2020Fotó készítése és közzététele Facebookon hozzájárulás nélkülThe authority found unlawful processing and publication of personal data without a valid legal basis. A fine was imposed and the image had to be deleted from Facebook.HUNAIHGDPR€299
12 Jun 2015ALPHA BANKThe HDPA imposed a fine of EUR 100,000 on ALPHA BANK for the unlawful provision of data from the TIRESIAS databases. The case concerned a breach of rules on the processing and disclosure of personal data.GRHDPAGDPR€100,000
11 Apr 2024Facile.Energy S.r.l.Facile.Energy S.r.l. was fined EUR 100,000 by the Garante for making unsolicited promotional calls without prior consent and activating energy supplies without a request from the customer. The authority found that these practices breached GDPR rules on data protection and security measures.ITGaranteGDPR€100,000
14 May 2021SIA "SS"DVI imposed a fine of EUR 100,000 on SIA "SS". According to the record, the sanction was later annulled.LVDVIGDPR€100,000
05 Oct 2017Regione autonoma Valle d'AostaRegione autonoma Valle d'Aosta was fined by the Garante 100,000 EUR for publishing a regional council resolution on its institutional website that contained an employee’s personal data. The document included professional evaluations and transfer details.ITGaranteGDPR€100,000
25 Jun 2025Vodafone-PanafonVodafone-Panafon was fined by the HDPA for failing to notify a data breach in a timely manner. The authority cited a violation of Article 12 of Law L.3471/2006.GRHDPAePrivacy€100,000
16 Dec 2021Ubi Banca S.p.a., ora Intesa Sanpaolo S.p.a.Ubi Banca S.p.a., now Intesa Sanpaolo S.p.a., was fined EUR 100,000 by the Italian Garante. The breach involved sending a letter with the phrase “credito anomalo Chieti” visible on the envelope, which could disclose the recipient’s financial information to third parties.ITGaranteGDPR€100,000
15 Dec 2022Altroconsumo Edizioni S.r.lAltroconsumo Edizioni S.r.l was fined EUR 100,000 by the Garante for making unsolicited promotional calls without a proper legal basis. The authority also found that the company failed to provide adequate information and to obtain free and specific consent from data subjects.ITGaranteGDPR€100,000
28 Jul 2022Intesa Sanpaolo S.p.a.Intesa Sanpaolo S.p.a. was fined EUR 100,000 by Garante after an employee accessed a customer's financial data without authorization. The data was then used in judicial proceedings. The authority found that the bank had not implemented adequate data protection measures.ITGaranteGDPR€100,000