Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.6%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
15 Dec 2022Assiteca S.p.A.Assiteca S.p.A. was fined EUR 120,000 by the Garante for violations related to the processing of personal data for marketing purposes. The authority also found inadequate responses to data subject requests. The case highlights the need for proper handling of individual rights and GDPR-compliant marketing practices.ITGaranteGDPR€120,000
04 Oct 2025OVH HISPANO, S.L.U.OVH HISPANO, S.L.U. was fined by the AEPD 120,000 EUR for a data protection breach. Confidential emails and documents of third parties were improperly shared due to inadequate data protection measures.ESAEPDGDPR€120,000
16 Jan 2020VODAFONE ESPAÑA SAUVODAFONE ESPAÑA SAU was fined 120,000 EUR by the AEPD for unlawful processing of personal data. The case involved threatening to include a minor's data in a credit file over an alleged unpaid debt.ESAEPDGDPR€120,000
18 Dec 2025Pioneer Hi-Bred Italia Sementi s.r.l.Pioneer Hi-Bred Italia Sementi s.r.l. was fined by the Garante 120,000 EUR for installing telematic devices in company vehicles to monitor employees' driving behavior. The authority found that the processing lacked proper data protection safeguards and privacy information.ITGaranteGDPR€120,000
20 Dec 2019Anonymizováno (ÚOOÚ UOOU-00136/19-31)The company was fined for disseminating commercial communications without a legal basis and without proper labeling. The authority found a breach of Czech rules on information society services.CZUOOUePrivacy€4,716
23 Jun 2025City of Dublin Education and Training Board (CDETB)The Irish supervisory authority concluded an inquiry into City of Dublin Education and Training Board (CDETB) and found GDPR infringements linked to a personal data breach. It imposed administrative fines totaling EUR 125,000 and issued a reprimand on 23 June 2025.IEData Protection Commission (Ireland)GDPR€125,000
23 Jun 2025City of Dublin Education and Training Board (CDETB)The Irish DPC imposed a fine of EUR 125,000 on City of Dublin Education and Training Board (CDETB) in inquiry IN-19-7-3. The fine status is collected.IEDPCGDPR€125,000
14 Dec 2022Monetise Media LimitedBetween 28 July 2020 and 28 July 2021, Monetise Media Limited sent 3,506,157 direct marketing emails and text messages. The recipients had not provided valid consent, which breached regulation 22 of PECR.GBICOePrivacy€145,000
16 Mar 2023SOCIETE DE LOCATION DE SCOOTERS ELECTRIQUES EN LIBRE-SERVICEThe CNIL imposed a fine of EUR 125,000 on SOCIETE DE LOCATION DE SCOOTERS ELECTRIQUES EN LIBRE-SERVICE. The case concerns a confirmed breach of rules supervised by the data protection authority.FRCNILGDPR€125,000
18 Jun 2015Wind Telecomunicazioni SpaWind Telecomunicazioni Spa was fined EUR 130,000 by the Garante. The case concerned the unlawful disclosure of mobile phone numbers in the White Pages directory without proper consent.ITGaranteGDPR€130,000
02 Oct 2014Addressvitt s.r.l.Addressvitt s.r.l. was fined by the Garante in the amount of EUR 130,000 for processing personal data without providing adequate information or obtaining consent. The case also involved data taken from public telephone directories and used without proper authorization.ITGaranteGDPR€130,000
14 Apr 2023Join the Triboo LimitedBetween 1 August 2019 and 19 August 2020, Join the Triboo Limited sent a confirmed total of 107 million direct marketing messages, of which 437,324 were received by distinct individuals. On average, each person received 244 emails during the period, and the messages contained direct marketing material without valid subscriber consent.GBICOGDPR€146,000
08 Jun 2023Crown Glazing LtdThe case was part of Operation Tinago, which assessed complaint trends in the energy and home improvements sector. Crown Glazing Ltd made 503,445 unsolicited calls to TPS-registered numbers between 4 January and 11 November 2021, resulting in 37 complaints.GBICOGDPR€150,000
01 Jan 2013GOOGLE INCGoogle Inc. was fined by the AEPD EUR 130,000 for failing to provide adequate information on privacy and cookie policies on a website. The authority found a breach of the LSSI information requirements toward users.ESAEPDePrivacy€130,000
01 Jan 2024DIGI SPAIN TELECOM, S.L.DIGI SPAIN TELECOM, S.L. was fined by the AEPD 130,000 EUR for unauthorized SIM card duplication. The incident led to identity theft and fraudulent charges, and the authority found the data protection measures insufficient.ESAEPDGDPR€130,000
18 Dec 2024Toyota Bank Polska S.A.The Polish supervisory authority imposed an administrative fine of EUR 132,000 on Toyota Bank Polska S.A. on 18 December 2024. The penalty concerned breaches of GDPR Articles 30, 35, and 38, including DPO independence, profiling documentation, and DPIA obligations.PLPresident of the Personal Data Protection Office (UODO)GDPR€132,000
11 Jan 2021Dane anonimowe (M. S.A. z siedzibą w Z. przy ul.)The President of UODO imposed an administrative fine of PLN 136,437 on M. S.A. The penalty was issued because the company did not report a personal data breach to the supervisory authority without undue delay.PLUODOGDPR€30,123
18 Apr 2023VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD 140,000 EUR for a data protection breach involving incorrect billing information. A customer's mobile line was charged under another person's name, indicating an error in the processing of personal data.ESAEPDGDPR€140,000
12 Jan 2024Grocery Delivery E-Services UK Ltd t/a HelloFreshThe ICO fined Grocery Delivery E-Services UK Ltd t/a HelloFresh 140,000 GBP for sending 79 million spam emails and 1 million spam texts over seven months. The marketing consent was inadequate because it did not mention text messages and was bundled with an age confirmation statement that may have unfairly encouraged agreement. Customers were also not clearly told that their data would continue to be used for marketing for up to 24 months after cancelling subscriptions.GBICOGDPR€162,000
01 Mar 2022VODAFONE ESPAÑA, S.A.U.Vodafone España was fined by the AEPD for failing to adequately prevent unauthorized SIM card duplication. The incident enabled fraudulent access and transactions on a customer's accounts.ESAEPDGDPR€140,000