Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
27 Mar 2025Comune di PolinoComune di Polino was fined by the Garante for breaches of transparency and information obligations in data processing under GDPR Articles 6, 12, 13, and 14. The case concerned insufficient information provided to data subjects about how their personal data was processed.ITGaranteGDPR€2,500
27 Mar 2025Comune di MilazzoThe Garante fined the Comune di Milazzo €3,600 for failing to provide adequate data protection information on its website. The authority found a breach of GDPR principles of lawfulness, fairness, and transparency.ITGaranteGDPR€3,600
27 Mar 2025AFK Letters Co LtdBetween January and September 2023, AFK Letters Co Ltd made 95,277 spam calls, leading to multiple complaints to the ICO and TPS. The company did not provide evidence that the called numbers had consented to receiving calls. The ICO imposed a £90,000 fine.GBICOGDPR€108,000
27 Mar 2025Provvedimento del 27 marzo 2025 [10140216]The Garante fined Powerfit, Soleo, and Zero Due Villa for sending promotional SMS messages without the recipients’ consent. The messages also did not provide an opt-out mechanism, which breached GDPR requirements.ITGaranteGDPR€6,000
27 Mar 2025Corriere del Giorno 1947 Media Group Soc. Coop. ArlThe Garante imposed a fine of 6,000 EUR on Corriere del Giorno 1947 Media Group Soc. Coop. Arl for violations related to the right to be forgotten. The authority found that certain articles were no longer relevant and were not in the public interest.ITGaranteGDPR€6,000
27 Mar 2025Comune di Palma di MontechiaroThe Municipality of Comune di Palma di Montechiaro was fined EUR 3,000 by the Italian data protection authority, Garante. The sanction concerned the failure to communicate the contact details of its Data Protection Officer to the authority, as required by Article 37 GDPR.ITGaranteGDPR€3,000
27 Mar 2025SOCIETE DE CONSEILS POUR LES AFFAIRES ET AUTRES CONSEILS DE GESTION (procédure simplifiée)The CNIL imposed an administrative fine of EUR 6,000 on SOCIETE DE CONSEILS POUR LES AFFAIRES ET AUTRES CONSEILS DE GESTION. The case was handled under a simplified procedure.FRCNILGDPR€6,000
27 Mar 2025Istituto di Istruzione Superiore “P. 96012510796The Garante imposed a fine on an educational institution for breaches of GDPR Articles 5, 6, and 9 in connection with data processing activities. The case concerned deficiencies in the lawful basis and principles of processing, including special-category data.ITGaranteGDPR€4,000
30 Mar 2025MODEL REYNA, C.B.MODEL REYNA, C.B. was fined by the AEPD EUR 3,000 for failing to provide access to personal data and related information. The authority found a breach of Article 58.1 of the GDPR.ESAEPDGDPR€3,000
31 Mar 2025BAR EL ANDÉN M. ROJO, S.L.The entity was fined for recording audio and video in the establishment without proper informational signage. The authority considered this a breach of data protection requirements.ESAEPDGDPR€1,000
01 Apr 2025Dane anonimowe (G. M. prowadzącą działalność gospodarczą pod firmą)UODO imposed an administrative fine of PLN 29,043 on the business operator. The authority found that appropriate technical and organizational measures proportionate to the risk of personal data processing were not implemented, and that their effectiveness was not regularly tested, measured, and assessed.PLUODOGDPR€6,938
01 Apr 2025BitdefenderBitdefender received a GDPR fine of EUR 10,000 from the Romanian data protection authority. The sanction followed an investigation completed in April 2025 after a data breach notification, with the authority citing inadequate technical and organizational security measures.ROAutoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal€10,000
01 Apr 2025EL LEÓN DE EL ESPAÑOL PUBLICACIONES, S.A.The AEPD fined EL LEÓN DE EL ESPAÑOL PUBLICACIONES, S.A. 20,000 EUR for publishing unnecessary personal data in a news article. A video in the article revealed the identity of a minor, which was considered disproportionate and unnecessary for the informational purpose.ESAEPDGDPR€20,000
01 Apr 2025Anonymised (IDPC 0476_001)The IDPC imposed a EUR 20,000 fine on Anonymised (IDPC 0476_001) for breaches of several GDPR provisions. The case concerned lawfulness, fairness and transparency, purpose limitation, information duties, the right to rectification, and the appointment of a data protection officer.MTIDPCGDPR€20,000
02 Apr 2025BINBOX GLOBAL SERVICES S.R.L.In March 2025, Romania’s data protection authority ANSPDCP completed an investigation into BINBOX GLOBAL SERVICES S.R.L. The authority found a GDPR violation and imposed a fine of EUR 3,000.ROANSPDCPGDPR€3,000
03 Apr 2025SOCIETE DE COURTAGE EN TRAVAUX, CONSULTING EN BATIMENT ET TRAVAUX PUBLICS, ACHAT ET REVENTE DE MATERIEL, TRANSACTION IMMOBILIERE ET MAITRISE D'ŒUVRE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 10,000 and issued an injunction. The case was handled under a simplified procedure.FRCNILGDPR€10,000
03 Apr 2025Banca Transilvania S.A.Banca Transilvania S.A. was fined EUR 5,000 by ANSPDCP for processing personal data without a legal basis. The authority found a breach of the GDPR principle of lawfulness, fairness, and transparency.ROANSPDCPGDPR€5,000
03 Apr 2025SOCIETE SPECIALISEE DANS LE SECTEUR D'ACTIVITE DES SUPERETTES (procédure simplifiée)The CNIL imposed an administrative fine of EUR 5,000 on SOCIETE SPECIALISEE DANS LE SECTEUR D'ACTIVITE DES SUPERETTES and issued an injunction. The case was handled under a simplified procedure.FRCNILGDPR€5,000
04 Apr 2025Unnamed bankThe Polish data protection authority imposed a fine of EUR 928,498.06 on a bank. The authority found that the bank failed to inform customers about a personal data breach. The case concerns post-incident notification obligations.PLPolish Data Protection AuthorityGDPR€928,000
04 Apr 2025MEDCENTER SRLMEDCENTER SRL was fined EUR 30,000 by ANSPDCP for breaching GDPR requirements. The company failed to inform affected individuals about a personal data security breach.ROANSPDCPGDPR€30,000