Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
29 Feb 2024WATIUM S.L.WATIUM S.L. was fined by the Spanish Data Protection Agency (AEPD) in the amount of EUR 160,000. The case concerned the failure to provide the required information, which constitutes a breach of Article 58.1 of the GDPR.ESAEPDGDPR€160,000
21 Dec 2011Edreams s.r.l.Edreams s.r.l. was fined €160,000 by the Garante for sending unsolicited commercial emails without obtaining the required consent. The case concerned breaches of data protection rules and direct marketing requirements.ITGaranteGDPR€160,000
08 Mar 2018Yahoo! Emea Limited oggi Oath (Emea) LimitedYahoo! Emea Limited, now Oath (Emea) Limited, was fined 160,000 EUR by the Garante. The authority found that the company failed to comply with a request to remove specific URLs containing personal information from Yahoo! Search.ITGaranteGDPR€160,000
12 Dec 2024Breathe Services LtdBreathe Services Ltd, a debt advice company based in Bolton, was investigated by the ICO following complaints about unsolicited calls to potentially vulnerable individuals. The ICO found that the company spoofed outbound numbers and made 4,376,037 unsolicited direct marketing calls to numbers registered with the Telephone Preference Service, generating multiple complaints.GBICOGDPR€206,000
03 Feb 2021MERCADONA S.A.MERCADONA S.A. was fined EUR 170,000 by the AEPD for failing to respond to a data access request within the required timeframe and for deleting security camera footage. The authority found that these actions breached GDPR obligations, including Articles 12 and 6.ESAEPDGDPR€170,000
28 May 2015El Dom S.a.s.El Dom S.a.s. was fined EUR 174,000 by the Garante for activating 185 phone cards under the names of 58 individuals without their knowledge. The case involved a breach of data protection rules and the unauthorized use of personal identification data.ITGaranteGDPR€174,000
17 Dec 2025Stichting Hogeschool van Arnhem en NijmegenThe Autoriteit Persoonsgegevens imposed a fine of €175,000 on Stichting Hogeschool van Arnhem en Nijmegen for failing to implement adequate technical and organizational measures appropriate to the risk. These deficiencies resulted in a data breach.NLAPGDPR€175,000
20 Mar 2025FAVORIT SPORTSKA KLADIONICA d.o.o.FAVORIT SPORTSKA KLADIONICA d.o.o. was fined by AZOP EUR 175,000 for failing to store personal data only as long as necessary and for not implementing appropriate technical safeguards. The case concerned breaches of Articles 5 and 32 of the GDPR.HRAZOPGDPR€175,000
08 Oct 2020Anonymizováno (ÚOOÚ UOOU-00179/19-38)The entity was fined for retaining personal data of financial service applicants longer than necessary, failing to inform them about potential data recipients, and lacking internal data protection measures. The authority found these practices inconsistent with data protection obligations.CZUOOUGDPR€6,459
07 Jul 2022SOCIETE DE LOCATION DE VEHICULESCNIL imposed a fine of EUR 175,000 on SOCIETE DE LOCATION DE VEHICULES. The case concerned a breach of personal data protection rules.FRCNILGDPR€175,000
10 Oct 2023Hogeschool van Arnhem en Nijmegen (HAN)The Autoriteit Persoonsgegevens imposed a fine of EUR 175,000 on Hogeschool van Arnhem en Nijmegen (HAN). The authority found that the institution did not provide sufficient protection for students’ personal data.NLAutoriteit PersoonsgegevensGDPR€175,000
27 Apr 2023Roma CapitaleRoma Capitale was fined EUR 176,000 by the Garante for the unlawful processing and dissemination of personal health data relating to women who had terminated pregnancies. The sensitive information was displayed on crosses at a cemetery, creating a serious data protection breach.ITGaranteGDPR€176,000
18 Jan 2018KRI S.p.A.KRI S.p.A. was fined by the Italian data protection authority, Garante, for failing to notify the cessation of certain personal data processing activities. The case involved geolocation data and profiling, and the required notification was not made under the Italian data protection code.ITGaranteGDPR€180,000
21 Feb 2019Anonymizováno (ÚOOÚ UOOU-05185/14-53)The entity was fined by UOOU for publishing information about wiretaps and telecommunications records without consent. The authority treated this as a breach of privacy and personal data protection rules.CZUOOUGDPR€7,018
14 May 2026EmiratesEmirates was fined by the Italian Garante €180,000 for breaching data protection rules. The airline required passengers with reduced mobility to complete a medical form without providing adequate information about how their data would be processed.ITGaranteGDPR€180,000
31 Mar 2016avv. Gioacchino GenchiAvv. Gioacchino Genchi was fined by the Italian Garante for creating a database containing personal data, including phone traffic data. The database was accessible to his collaborators, which breached data protection rules.ITGaranteGDPR€192,000
21 Sept 2023F12 Management LtdF12 Management Ltd made 1,346,019 marketing calls to individuals in breach of regulation 21 of PECR. The ICO imposed a £200,000 fine and issued an enforcement notice.GBICOePrivacy€230,000
15 Feb 2023It's OK LimitedBetween 1 July 2019 and 1 June 2020, It's OK Limited made 1,752,149 unsolicited direct marketing calls to subscribers who had been registered with the TPS for at least 28 days. The company had no evidence that the recipients had not objected to receiving such calls, breaching regulation 21 of PECR.GBICOePrivacy€225,000
08 Jun 2020Volt munkavállaló munkavégzési célú elektronikus leveleihez való hozzáféréseThe controller unlawfully denied access to the complainant's archived personal emails from 2018. It also failed to provide transparent information about the actions taken in response to the data subject's request.HUNAIHGDPR€582
01 Jan 2024DIGI SPAIN TELECOM, S.L.DIGI SPAIN TELECOM, S.L. was fined by the AEPD 200,000 EUR for issuing a duplicate SIM card to a third party without the original user's consent. The incident led to unauthorized access to personal and banking data.ESAEPDGDPR€200,000