Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
29 Apr 2025Comune di BolognaThe Garante imposed a fine of 40,000 EUR on Comune di Bologna for breaches of data protection principles. The case concerned non-compliance with requirements on lawfulness, fairness, transparency, and data minimization.ITGaranteGDPR€40,000
29 Apr 2025Energia Verde S.p.A.Energia Verde S.p.A. was fined EUR 100,000 by the Garante for making unsolicited promotional calls without a legal basis. The authority also found that the company did not adequately respond to data subjects' requests, indicating failures in data protection compliance.ITGaranteGDPR€100,000
29 Apr 2025Ordine degli Psicologi della Regione LombardiaThe Garante fined the Ordine degli Psicologi della Regione Lombardia EUR 30,000 for a data breach. The incident exposed personal and sensitive data of about 15,000 individuals, including information covered by professional secrecy and special categories of data.ITGaranteGDPR€30,000
29 Apr 2025Versilmagra Immobiliare di Robertelli Davide & C. S.a.s.Versilmagra Immobiliare was fined EUR 2,000 by the Garante. The authority found that the company sent unsolicited communications via WhatsApp without proper consent and did not facilitate the exercise of data subject rights.ITGaranteGDPR€2,000
29 Apr 2025Cooperativa Sociale QuadrifoglioThe Garante imposed a fine of EUR 20,000 on Cooperativa Sociale Quadrifoglio for violations related to data processing. The case concerned non-compliance with personal data protection requirements.ITGaranteGDPR€20,000
29 Apr 2025Energia Pulita S.r.l.Energia Pulita S.r.l. was fined by the Garante for improper handling of personal data in telemarketing activities. The authority also noted failure to cooperate with the supervisory authority and incorrect identification of roles in data processing.ITGaranteGDPR€10,000
29 Apr 2025Regione Emilia RomagnaThe Garante fined Regione Emilia Romagna EUR 15,000 for violations related to the processing of personal data for official statistical purposes. The authority found incorrect application of data protection principles and measures.ITGaranteGDPR€15,000
29 Apr 2025Comune di NoliComune di Noli was fined EUR 2,000 by the Garante for failing to ensure lawful, fair, and transparent processing of personal data. The authority also found a breach of data minimization because unauthorized access to unredacted images was possible through an online portal.ITGaranteGDPR€2,000
29 Apr 2025Tirrenia Hospital S.r.l.Tirrenia Hospital S.r.l. was fined by the Garante EUR 2,000 for breaching the data processing principles set out in GDPR Article 5. The case concerned processing in the healthcare sector, where a particularly high level of compliance is required.ITGaranteGDPR€2,000
29 Apr 2025Regione LombardiaThe Garante fined Regione Lombardia 50,000 EUR for violations related to the processing of personal data. The authority cited inadequate technical and organizational measures to protect data, as well as improper handling of employee metadata and internet navigation logs.ITGaranteGDPR€50,000
29 Apr 2025Ordine professionale degli psicologi della LombardiaOn 2025-04-29, the Italian Data Protection Authority fined the Ordine professionale degli psicologi della Lombardia EUR 30,000. The sanction concerned breaches of Articles 5(1)(f) and 32 GDPR following a data breach and the failure to implement adequate security measures.ITGarante per la protezione dei dati personaliGDPR€30,000
30 Apr 2025TikTok Technology LimitedThe Irish DPC imposed a fine of EUR 530,000,000 on TikTok Technology Limited in inquiry IN-21-9-2. The decision is currently under appeal.IEDPCGDPR€530,000,000
30 Apr 2025SOCIETE EDITANT UN SITE WEB DE RENCONTRES DESTINE AUX PERSONNES PARTAGEANT DES CONVICTIONS POLITIQUES SIMILAIRES (procédure simplifiée)CNIL imposed an administrative fine of 20,000 EUR on the company operating a dating website for people sharing similar political convictions. The case was handled under a simplified procedure.FRCNILGDPR€20,000
30 Apr 2025Anonymisé (CNPD decision-03-fr-2025)The company did not maintain a complete record of processing activities as required by Article 30 GDPR. CNPD imposed an administrative fine of €11,964.LUCNPDGDPR€11,964
30 Apr 2025BITDEFENDER SRLIn April 2025, the Romanian authority ANSPDCP completed an investigation into BITDEFENDER SRL and found a GDPR violation. The company was fined EUR 10,000.ROANSPDCPGDPR€10,000
01 May 2025VERSON RIOJA, S.L.VERSON RIOJA, S.L. was fined by the AEPD for failing to provide access to personal data and the information requested by the data protection authority. The authority found a breach of Article 58.1 of the GDPR.ESAEPDGDPR€6,000
01 May 2025CURENERGÍA COMERCIALIZADOR DE ÚLTIMO RECURSO S.A.U.CURENERGÍA was fined EUR 10,000 by the AEPD for sharing personal data with IBERDROLA without the data subject’s consent. The disclosure led to a contract offer at a higher price than requested.ESAEPDGDPR€10,000
01 May 2025ALBOR ENERGÍA S.L.ALBOR ENERGÍA S.L. was fined by the AEPD in the amount of 20,000 EUR for a data protection breach. The case concerned unauthorized subcontracting without informing the responsible party, as required by Article 28 of the GDPR.ESAEPDGDPR€20,000
01 May 2025SC Piramida Trade Invest SRLThe Romanian DPA ANSPDCP imposed a total fine of EUR 3,000 on SC Piramida Trade Invest SRL for unlawful audio-video monitoring of employees and inadequate staff information. It also found that the company failed to respond to access, erasure, and objection requests within the legal deadline; a separate email-forwarding issue resulted only in a warning.ROAutoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter PersonalGDPR€3,000
09 May 2025ROUMASPORT SRLIn April 2025, Romania’s data protection authority ANSPDCP completed an investigation at ROUMASPORT SRL. The authority found GDPR violations and imposed a fine of 5,000 EUR.ROANSPDCPGDPR€5,000