Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
08 Apr 2025Adatbiztonsági problémák ügyféladatbázis adatfeldolgozó általi költöztetése soránThe authority found that Ügyfél1 failed to implement appropriate security measures when processing data during the database migration. This breach of GDPR Article 32 resulted in a fine of 2,000,000 HUF.HUNAIHGDPR€4,920
10 Apr 2025Tensa Art Design S.A.Tensa Art Design S.A. was fined by ANSPDCP EUR 10,000 for GDPR violations related to its website www.lensa.ro. The case concerned non-compliant processing of personal data under data protection requirements.ROANSPDCPGDPR€10,000
10 Apr 2025Ente di Patrocinio ed Assistenza per i Cittadini e l’Agricoltura (EPACA)EPACA was fined EUR 5,000 by the Italian Garante. The authority found that the organization retained personal data beyond the legally permitted period and accessed the INPS database without a valid mandate.ITGaranteGDPR€5,000
10 Apr 2025Yolo Group S.p.a.Yolo Group S.p.a. was fined by the Garante 30,000 EUR for a data breach involving personal and contact data of a large number of individuals. The authority found a violation of Article 33 of the GDPR, which concerns notification of personal data breaches.ITGaranteGDPR€30,000
10 Apr 2025Gioele MagaldiThe Garante fined Gioele Magaldi, the manager of a blog, EUR 4,000 for publishing defamatory articles. The authority found that the content contained false information and exceeded the limits of the right to report because it lacked social utility.ITGaranteGDPR€4,000
10 Apr 2025Undici S.r.l.s.Undici S.r.l.s. was fined 8,000 EUR by the Garante for making unsolicited telemarketing calls. The authority found that the company did not verify the lawfulness of the data used for contact, breaching GDPR requirements on consent and data processing.ITGaranteGDPR€8,000
10 Apr 2025Unione Montana Appennino Parma EstUnione Montana Appennino Parma Est was fined by the Italian supervisory authority, Garante, in the amount of EUR 8,000. The authority found a lack of required transparency in data processing and failure to carry out a data protection impact assessment for workplace video surveillance.ITGaranteGDPR€8,000
10 Apr 2025Aliseo s.r.l.Aliseo s.r.l. was fined by the Garante for operating a video surveillance system without proper notice and for monitoring employees, including audio recording. The authority found the monitoring disproportionate to the stated security purpose.ITGaranteGDPR€5,000
10 Apr 2025Azienda Ospedaliera Universitaria Integrata VeronaAzienda Ospedaliera Universitaria Integrata Verona was fined by the Garante for failing to adequately protect personal data. After a ransomware attack, 612 GB of data was published on the dark web, indicating serious security shortcomings.ITGaranteGDPR€10,000
10 Apr 2025Acea EnergiaAcea Energia was fined EUR 3,000,000 by the Garante. The authority found unauthorized telemarketing activities and insufficient protection of databases against access by unauthorized agents.ITGaranteGDPR€3,000,000
10 Apr 2025SOCIETE DE COMMERCE DE DETAIL D'ARTICLES DE SPORT EN MAGASIN SPECIALISE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 20,000 on SOCIETE DE COMMERCE DE DETAIL D'ARTICLES DE SPORT EN MAGASIN SPECIALISE. The case was handled under a simplified procedure.FRCNILGDPR€20,000
10 Apr 2025Luka Inc.The Italian data protection authority fined Luka Inc., the US company behind the Replika chatbot, EUR 5,000,000. The 2025-04-10 decision concerned inadequate age verification, an unlawful processing basis, and missing privacy notice information required under the GDPR.ITGarante per la protezione dei dati personaliGDPR€5,000,000
10 Apr 2025Provvedimento del 10 aprile 2025 [10144184]A healthcare organization was fined after an employee accessed a patient's health dossier without authorization. The case highlights a breach of data protection rules in the healthcare sector.ITGaranteGDPR€18,000
10 Apr 2025Agenzia Mobilità Ambiente e Territorio S.r.l.The Garante fined Agenzia Mobilità Ambiente e Territorio S.r.l. 9,000 EUR for failing to provide sufficient transparency to data subjects. The authority found a breach of the GDPR principles of lawfulness, fairness, and transparency.ITGaranteGDPR€9,000
10 Apr 2025Immobiliare Valdalpone S.r.l.Immobiliare Valdalpone S.r.l. was fined by the Garante 15,000 EUR for making unsolicited marketing calls without proper consent. The authority also found inadequate data protection measures.ITGaranteGDPR€15,000
10 Apr 2025Vogliocasa Holding & Servizi S.r.l.Vogliocasa Holding & Servizi S.r.l. was fined by the Garante EUR 5,000 for making unsolicited telemarketing calls promoting real estate brokerage services without valid consent. The company also failed to respond to the authority's information requests, which hindered the supervisory process.ITGaranteGDPR€5,000
10 Apr 2025Stefanelli FedericaThe Garante imposed a 45,000 EUR fine on Stefanelli Federica for processing personal data without proper consent in unauthorized call-center operations. The case also involved sensitive data, including payment method information, which could have led to unauthorized contract activations.ITGaranteGDPR€45,000
10 Apr 2025SOCIETE EXERCANT UNE ACTIVITE DE RESTAURATION (procédure simplifiée)The CNIL imposed an administrative fine of EUR 6,000 on SOCIETE EXERCANT UNE ACTIVITE DE RESTAURATION. The case was handled under a simplified procedure.FRCNILGDPR€6,000
10 Apr 2025Comune di Ponte nelle AlpiThe Garante fined Comune di Ponte nelle Alpi 4,000 EUR for breaches of GDPR Articles 5 and 6 and Article 2-ter of the Codice. The case concerned improper personal data processing activities.ITGaranteGDPR€4,000
10 Apr 2025Tensa Art Design S.A.Tensa Art Design S.A. was fined by ANSPDCP EUR 5,000 for GDPR violations related to its website www.lensa.ro. The case concerned non-compliant processing of personal data under data protection requirements.ROANSPDCPGDPR€5,000