Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
31 Dec 2024SOCIETE DE TRANSPORT AMBULANCIER (procédure simplifiée)The CNIL imposed an administrative fine of EUR 10,000 on SOCIETE DE TRANSPORT AMBULANCIER. The case was handled under a simplified procedure.FRCNILGDPR€10,000
31 Dec 2024PARTICULIERS (procédure simplifiée)An administrative fine of EUR 5,000 was imposed by the CNIL. The case was handled under a simplified procedure.FRCNILGDPR€5,000
31 Dec 2024SOCIETE GERANT UN ROBOT CONVERSATIONNEL UTILISANT L'INTELLIGENCE ARTIFICELLE (procédure simplifiée)The CNIL imposed an administrative fine of 5,000 EUR on the company operating an AI-based conversational robot. The case was handled under a simplified procedure.FRCNILGDPR€5,000
01 Jan 2025MONUMENTAL FORMA SPORT, S.L.MONUMENTAL FORMA SPORT, S.L. was fined by the AEPD EUR 3,000 for requesting excessive personal data, including banking information, in connection with a free gym access promotion. The authority found that the data requested breached the GDPR data minimisation principle under Article 5(1)(c).ESAEPDGDPR€3,000
01 Jan 2025Εθνική Τράπεζα της Ελλάδος Α.Ε.The data protection authority imposed a EUR 220,000 fine on Εθνική Τράπεζα της Ελλάδος Α.Ε. for a GDPR violation. The case concerned deficiencies in personal data protection and compliance with GDPR requirements.GRΑρχή Προστασίας Δεδομένων Προσωπικού ΧαρακτήραGDPR€220,000
01 Jan 2025SGKLegalThe Greek data protection authority, ΑΠΔΠΧ, imposed a fine of EUR 22,000 on SGKLegal for a GDPR violation. The case involved recorded conversations and deficiencies in personal data protection compliance.GRΑρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (ΑΠΔΠΧ)GDPR€22,000
01 Jan 2025B3C CONSULTORÍA DE SERVICIOS 2010 S.L.B3C CONSULTORÍA DE SERVICIOS 2010 S.L. was fined by the AEPD EUR 800 for subcontracting TELCO without authorization from the data controller, AIRE NETWORKS. The company also failed to impose the required contractual obligations on TELCO, breaching GDPR Articles 28.2 and 28.4.ESAEPDGDPR€800
01 Jan 2025STRATESYS TECHNOLOGY SOLUTIONS, S.L.STRATESYS TECHNOLOGY SOLUTIONS, S.L. was fined EUR 100,000 by the AEPD for breaching Article 5(1)(f) of the GDPR. The case concerned a failure to protect the integrity and confidentiality of personal data.ESAEPDGDPR€100,000
01 Jan 2025A.A.A.A.A.A. failed to properly handle a data access request, which constitutes a breach of Article 15 GDPR. The AEPD imposed a fine of EUR 200, reduced to EUR 160 for early payment.ESAEPDGDPR€200
01 Jan 2025TELEROSA SPAIN, S.L.TELEROSA SPAIN, S.L. was fined 450 EUR by the AEPD for sending unsolicited commercial SMS messages without prior express consent. The authority also noted that there was no pre-existing contractual relationship with the recipients.ESAEPDePrivacy€450
01 Jan 2025FEMXA FORMACIÓN, S.L.FEMXA FORMACIÓN, S.L. was fined by the AEPD 25,000 EUR for requiring a full copy of a student's ID during course enrollment. The authority found the data request unnecessary and inconsistent with data protection principles.ESAEPDGDPR€25,000
01 Jan 2025MALAGASUITE SHOWROOM, S.L.MALAGASUITE SHOWROOM, S.L. was fined by the AEPD 2,000 EUR for failing to inform guests about the processing of their personal data. The authority found a breach of Article 13 GDPR.ESAEPDGDPR€2,000
01 Jan 2025AMADEUSAMADEUS was fined EUR 9,000,000 by the AEPD for breaching GDPR Articles 14 and 6. The authority found that the company failed to inform data subjects about the processing of their personal data.ESAEPDGDPR€9,000,000
01 Jan 2025Sambla GroupThe Finnish Data Protection Authority fined Sambla Group EUR 950,000 after unauthorized parties accessed credit application data by manipulating web addresses. The authority found that the company had not implemented adequate safeguards to prevent the breach.FITietosuojavaltuutetun toimistoGDPR€950,000
01 Jan 2025Diskrimineringsombudsmannen (DO)Integritetsskyddsmyndigheten (IMY) imposed a 100,000 SEK administrative sanction on Diskrimineringsombudsmannen (DO). The case concerned insufficient security measures for personal data collected via a web form, which resulted in unintended disclosure to a processor.SEIntegritetsskyddsmyndigheten (IMY)GDPR€8,727
01 Jan 2025RaiItaly’s data protection authority fined Rai EUR 150,000 over a Report broadcast on 8 December 2024 that disclosed a private conversation. The case concerns unlawful processing of personal data in a television report.ITGarante per la protezione dei dati personaliGDPR€150,000
01 Jan 2025ASESORAMOS TU FORMACIÓN CON CALIDAD S.L.ASESORAMOS TU FORMACIÓN CON CALIDAD S.L. was fined by the AEPD 10,000 EUR for processing personal data without a legal basis. The case also involved the improper inclusion of individuals in credit information systems.ESAEPDGDPR€10,000
01 Jan 2025PROYECTOS VISUALES ZARAGOZA SLPROYECTOS VISUALES ZARAGOZA SL was fined by the AEPD 50,000 EUR for a personal data breach. The authority found that the company failed to ensure data integrity and confidentiality under Article 5(1)(f) GDPR.ESAEPDGDPR€50,000
01 Jan 2025Posti Jakelu OyPosti Jakelu Oy was fined EUR 2,400,000 by the Data Protection Ombudsman for deficiencies in data protection related to the OmaPosti service. The case concerned inadequate safeguards and failures to meet personal data protection requirements.FITietosuojavaltuutettuGDPR€2,400,000
06 Jan 2025Anonymisé (CNPD decision-01-fr-2025)The entity failed to comply with the response time requirements for data subject requests, which constitutes a breach of Article 12 GDPR. CNPD imposed a fine of EUR 493,560.LUCNPDGDPR€493,000