Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
09 Jan 2025SOCIETE REALISANT DES TRAVAUX D'ISOLATION, DE RENOVATION ENERGETIQUE ET DE CHAUFFAGE (procédure simplifiée)The CNIL imposed an administrative fine of 15,000 EUR on SOCIETE REALISANT DES TRAVAUX D'ISOLATION, DE RENOVATION ENERGETIQUE ET DE CHAUFFAGE and issued an injunction. The case was handled under simplified proceedings.FRCNILGDPR€15,000
09 Jan 2025National Bank of GreeceNational Bank of Greece was fined €20,000 by the HDPA. The authority found that the bank failed to provide data subjects with timely access to their personal data, breaching GDPR Articles 15 and 12.GRHDPAGDPR€20,000
10 Jan 2025CRUZ ROJA ESPAÑOLACRUZ ROJA ESPAÑOLA was fined EUR 50,000 by the AEPD for a personal data protection breach. The case involved the unauthorized disclosure of patient data in a communication about a change in embryo bank management.ESAEPDGDPR€50,000
10 Jan 2025Stowarzyszenie „Maraton” z GorlicThe President of the Personal Data Protection Office imposed an administrative fine of PLN 916.71 on Stowarzyszenie „Maraton” z Gorlic. The penalty concerned failure to notify a personal data breach within the required 72-hour deadline, together with related compliance shortcomings.PLPrezes Urzędu Ochrony Danych OsobowychGDPR€215
13 Jan 2025Centrul Medical Unirea S.R.L.The National Supervisory Authority for Personal Data Processing completed an investigation at Centrul Medical Unirea S.R.L. and found a breach of Article 32 of the GDPR. A fine of EUR 2,000 was imposed.ROANSPDCPGDPR€2,000
13 Jan 2025OrangeCNIL imposed a EUR 50 million fine on Orange for displaying commercial ads in email inboxes without prior user consent. The authority also found that advertising and statistical cookies continued to be read after consent had been withdrawn, in breach of the GDPR.FRCommission Nationale de l'Informatique et des LibertésGDPR€50,000,000
13 Jan 2025BLEISOR SOLUTIONS, S.A.S.BLEISOR SOLUTIONS, S.A.S. was fined 600 EUR by the AEPD. The authority found that the company failed to provide access to personal data and information requested by the supervisory authority, in breach of Article 58(1) GDPR.ESAEPDGDPR€600
16 Jan 2025Comune di PaternòThe Garante fined Comune di Paternò EUR 6,000 for failing to communicate the Data Protection Officer’s contact details to the Authority. The breach concerned the obligation under Article 37(7) GDPR.ITGaranteGDPR€6,000
16 Jan 2025CENTRE DE FORMATION A DISTANCE D'APPRENTIS (procédure simplifiée)The CNIL imposed an administrative fine of EUR 10,000 on CENTRE DE FORMATION A DISTANCE D'APPRENTIS and issued an injunction. The case was handled under a simplified procedure.FRCNILGDPR€10,000
16 Jan 2025Comune di CoriThe Garante fined Comune di Cori EUR 2,000 for violations related to the processing of personal data in connection with the issuance of the “Dedicata a te” card. The case involved electronic payment cards provided by Poste Italiane.ITGaranteGDPR€2,000
17 Jan 2025Dane anonimowe (X. z siedzibą w K.)The UODO imposed administrative fines on X. based in K. for breaches of Article 6(1), Article 9(1), Article 13(1) and (2), Article 25(1), and Article 32(1) and (2) of the GDPR. These breaches also resulted in violations of the principles in Article 5(1)(a) and (f) and Article 5(2) of the GDPR.PLUODOGDPR€161,000
17 Jan 2025DELIVERY SOLUTIONS S.A.The company was fined for failing to implement adequate technical and organizational measures to ensure a level of security appropriate to the risk. The authority also found insufficient safeguards to ensure data confidentiality.ROANSPDCPGDPR€2,000
17 Jan 2025OLALA MNG, S.L.OLALA MNG, S.L. was fined by the AEPD EUR 1,600 for requesting excessive personal data from guests booking through a website. The authority found that asking for images of identity documents constituted a data protection breach.ESAEPDGDPR€1,600
20 Jan 2025Vodafone Romania S.A.Vodafone Romania S.A. was fined EUR 15,000 by ANSPDCP for violations of GDPR provisions. The case concerns non-compliance with personal data protection requirements.ROANSPDCPGDPR€15,000
23 Jan 2025Softtehnica S.R.LIn December 2024, ANSPDCP completed an investigation at Softtehnica S.R.L. The authority found a GDPR violation and imposed a fine of EUR 5,000.ROANSPDCPGDPR€5,000
23 Jan 2025SOCIETE DE TRANSPORT ROUTIER DE MARCHANDISES (procédure simplifiée)CNIL imposed an administrative fine of 8,000 EUR on SOCIETE DE TRANSPORT ROUTIER DE MARCHANDISES. The case was handled under a simplified procedure.FRCNILGDPR€8,000
23 Jan 2025XFERA MÓVILES, S.A.XFERA MÓVILES, S.A. was fined 100,000 EUR by the AEPD for inaccuracies in data retention relating to SIM card purchasers. The authority found a breach of the GDPR data accuracy obligation.ESAEPDGDPR€100,000
27 Jan 2025Orange România SAOrange România SA was fined EUR 20,000 by ANSPDCP for GDPR violations. The case concerns non-compliance with personal data protection requirements.ROANSPDCPGDPR€20,000
27 Jan 2025Orange România SAOrange România SA was fined EUR 20,000 by ANSPDCP for GDPR violations. The case concerns non-compliance with personal data protection requirements, creating regulatory risk for organizations processing data in Romania.ROANSPDCPGDPR€20,000
29 Jan 2025SINDICATO DE LA ADMON. PÚBLICA DE LA CGT EN JEREZ Y COSTA NOROESTE DE CÁDIZThe union was fined by the AEPD for failing to comply with data protection principles and for not informing individuals about the processing of their personal data. The case indicates shortcomings in transparency and GDPR compliance obligations.ESAEPDGDPR€2,000