Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.6%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
01 Jan 2023NATURGY IBERIA, S.A.Naturgy Iberia was fined for changing a customer's gas and electricity supplier without authorization. The authority found that this breached Article 6(1) of the GDPR because there was no lawful basis for the processing.ESAEPDGDPR€100,000
22 Jun 2023VODAFONE ESPAÑA, S.A.U.Vodafone España, S.A.U. was fined by the AEPD in the amount of 100,000 EUR for issuing a SIM card duplicate without the customer's consent. The authority treated this as a breach of data protection rules.ESAEPDGDPR€100,000
29 Dec 2023SOCIETE DE CONSEIL EN SYSTEMES ET LOGICIELS INFORMATIQUESThe CNIL imposed a fine of EUR 100,000 on SOCIETE DE CONSEIL EN SYSTEMES ET LOGICIELS INFORMATIQUES. The case concerns a breach of personal data protection rules.FRCNILGDPR€100,000
15 Feb 2024Dr TelemarketingBetween 11 February 2021 and 24 January 2022, 80,240 connected unsolicited marketing calls were made to subscribers registered with the TPS who had not consented to receive them. Two complaints were received, and the calls related to the Irish Lottery. The company stopped engaging with the Commissioner during the investigation and did not provide a satisfactory explanation for the Lotto Express calls.GBICOGDPR€116,000
03 Feb 2026TMAC LtdTMAC Ltd was fined GBP 100,000 by the ICO and served with an enforcement notice for breaches of regulations 21 and 24 of PECR. Between 8 February 2024 and 24 September 2024, the company made 260,332 unsolicited direct marketing calls to numbers listed on the Commissioner’s register. It also failed to provide the required information to call recipients.GBICOePrivacy€115,000
23 Apr 2025Diskriminerings­ombudsmannen (DO)The Swedish Authority for Privacy Protection (IMY) fined the Equality Ombudsman (DO) 100,000 SEK. IMY found that DO failed to implement appropriate technical and organizational measures to ensure an adequate level of security for personal data collected via a web form.SEIMYGDPR€9,141
21 May 2019Ferencvárosi Szociális és Gyermekjóléti Intézmények IgazgatóságaThe Ferencvárosi Social and Child Welfare Institutions Directorate was fined for failing to report a personal data breach within the required deadline. The incident involved documents sent to the wrong address, triggering the notification duty under GDPR Article 33.HUNAIHGDPR€306
02 Dec 2021Omnia 24 S.r.l.Omnia 24 S.r.l. was fined EUR 100,000 by the Garante for sending unsolicited promotional SMS messages without proper consent. The authority found that the company’s conduct breached data protection rules.ITGaranteGDPR€100,000
29 Apr 2026Lepida S.c.p.A.Lepida S.c.p.A. was fined by the Italian supervisory authority Garante €100,000 for unauthorized access and data handling violations linked to SPID digital identity management. The authority found breaches of GDPR Articles 25 and 32, covering data protection by design and security of processing.ITGaranteGDPR€100,000
20 Dec 2022Virtue Integrated Elder Care LtdThe Irish DPC imposed a fine of EUR 100,000 on Virtue Integrated Elder Care Ltd in inquiry IN-21-2-5. The penalty has been collected.IEDPCGDPR€100,000
23 Jan 2025XFERA MÓVILES, S.A.XFERA MÓVILES, S.A. was fined 100,000 EUR by the AEPD for inaccuracies in data retention relating to SIM card purchasers. The authority found a breach of the GDPR data accuracy obligation.ESAEPDGDPR€100,000
02 Jul 2025Hrvatski ured za osiguranjeAZOP imposed a 101,000 euro fine on Hrvatski ured za osiguranje (HUO) after finding that it had not implemented adequate technical and organizational measures to protect personal data. The decision followed an investigation into a major data leak affecting about 1.2 million vehicle owners in Croatia.HRAZOPGDPR€101,000
18 Apr 2013Itel s.r.l. UnipersonaleItel s.r.l. Unipersonale was fined EUR 102,000 by the Garante for improper processing of personal data. The case involved registering phone cards to third parties without their knowledge, in breach of privacy rules.ITGaranteGDPR€102,000
02 Jul 2015Lycamobile s.r.l.Lycamobile s.r.l. was fined EUR 102,000 by the Garante for failing to provide requested information on the retention of telephone and telematic traffic data. The case concerned a breach of data protection rules.ITGaranteGDPR€102,000
18 Oct 2023Dane anonimowe (J. Towarzystwo Ubezpieczeń S.A. z siedzibą w N.)UODO imposed an administrative fine of PLN 103,752 on J. Towarzystwo Ubezpieczeń S.A. The authority found that the company failed to notify the supervisory authority of a personal data breach without undue delay.PLUODOGDPR€23,362
29 Dec 2023SOCIETE PERMETTANT D'EFFECTUER DES PAIEMENTS EN LIGNEA fine of EUR 105,000 was imposed by the CNIL. The case concerns a breach of personal data protection rules.FRCNILGDPR€105,000
11 Dec 2025ZMLUK LimitedZMLUK Limited received an MPN from the ICO for sending unsolicited emails promoting energy-saving products. The case concerns a breach of electronic marketing rules and should be reviewed for compliance with applicable consent requirements.GBICOGDPR€119,000
11 Apr 2013Zeno VincoZeno Vinco was fined by the Garante for registering SIM cards to 36 individuals without their knowledge. The case involved a breach of data protection rules.ITGaranteGDPR€108,000
13 Nov 2023Rompetrol Downstream SRLRompetrol Downstream SRL was fined EUR 110,000 by ANSPDCP for failing to ensure the security of personal data. The authority found a breach of Article 32 GDPR, which requires appropriate technical and organizational measures.ROANSPDCPGDPR€110,000
09 Dec 2021Limerick City and County CouncilThe Irish DPC imposed a fine of EUR 110,000 on Limerick City and County Council in inquiry 03/SIU/2018. The penalty has been collected.IEDPCGDPR€110,000