Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
12 May 2025CV PRO CONSULT S.R.L.The National Supervisory Authority for Personal Data Processing completed an investigation in April 2025 at CV PRO CONSULT S.R.L. and found a GDPR violation. As a result, a fine of EUR 2,000 was imposed.ROANSPDCPGDPR€2,000
13 May 2025Romoffice Construct Holding Ag SRLThe company was fined by ANSPDCP €2,000 for processing personal data without a legal basis. The breach concerned the principles of lawfulness, fairness, and transparency.ROANSPDCPGDPR€2,000
14 May 2025CVA TAX & FINANCE S.R.L.In April 2025, ANSPDCP completed an investigation at CVA TAX & FINANCE S.R.L. and found a GDPR violation. As a result, a fine of EUR 2,000 was imposed.ROANSPDCPGDPR€2,000
14 May 2025IAB EuropeThe Gegevensbeschermingsautoriteit’s decision concerned IAB Europe and the Transparency and Consent Framework. A fine of EUR 250,000 was imposed for GDPR breaches related to the processing of personal data, and the Brussels Market Court confirmed the violations and sanctions while noting procedural grounds for annulling the original decision.BEGegevensbeschermingsautoriteit (GBA)GDPR€250,000
15 May 2025SOCIETE AYANT UNE ACTIVITE DE MARKETING ET DE CONCEPTION DE SITES WEBThe CNIL imposed an administrative fine of EUR 900,000 on SOCIETE AYANT UNE ACTIVITE DE MARKETING ET DE CONCEPTION DE SITES WEB and issued an injunction. The case concerns a regulatory breach requiring corrective action.FRCNILGDPR€900,000
15 May 2025SOCIETE REALISANT DES OPERATIONS DE PROSPECTION COMMERCIALE PAR VOIE ELECTRONIQUE POUR LE COMPTE D'ANNONCEURS, AVEC UNE ACTIVITE DE COURTIER EN DONNEESThe CNIL imposed an administrative fine of EUR 80,000 on a company engaged in electronic commercial prospecting and data brokering. The decision concerns a breach of rules supervised by the CNIL.FRCNILGDPR€80,000
15 May 2025SOCIETE OFFRANT DES PRESTATIONS DE SECURITE PRIVEE (procédure simplifiée)The CNIL used a simplified procedure against SOCIETE OFFRANT DES PRESTATIONS DE SECURITE PRIVEE and ordered liquidation of a penalty payment of EUR 4,000. The decision concerns failure to comply with a prior obligation imposed by the supervisory authority.FRCNILGDPR€4,000
16 May 2025ACCOUNTING & AUDIT CONSULTING SRLACCOUNTING & AUDIT CONSULTING SRL was fined by ANSPDCP €5,000 for GDPR violations. The investigation was completed in April 2025, and the decision was issued on 16 May 2025.ROANSPDCPGDPR€5,000
19 May 2025GATIGOS, S.L.GATIGOS, S.L. was fined EUR 6,000 by the AEPD for failing to provide access to personal data and the information requested by the data protection authority. The authority found a breach of Article 58(1) GDPR.ESAEPDGDPR€6,000
19 May 2025REAL FEDERACIÓN ESPAÑOLA DE TENIS DE MESAREAL FEDERACIÓN ESPAÑOLA DE TENIS DE MESA was fined by the AEPD 2,000 EUR for publishing personal data of individuals involved in an electoral process on its website. This conduct breached data protection principles.ESAEPDGDPR€2,000
19 May 2025Maravet S.R.L.The National Supervisory Authority for Personal Data Processing completed an investigation at Maravet S.R.L. and found a violation of GDPR provisions. The operator was fined EUR 5,000.ROANSPDCPGDPR€5,000
20 May 2025TRUEBA SPORT S.L.TRUEBA SPORT S.L. was fined by the AEPD 2,000 EUR for sending an email to more than 300 recipients without hiding their email addresses. The authority found this breached data protection principles and failed to properly inform the affected individuals about data processing.ESAEPDGDPR€2,000
21 May 2025Autostrade per l'Italia SpaThe Italian data protection authority fined Autostrade per l'Italia Spa EUR 420,000 for unlawfully processing an employee's personal data. The company used content from her Facebook profile and private Messenger and WhatsApp chats to support disciplinary proceedings and justify her dismissal.ITGarante per la protezione dei dati personaliGDPR€420,000
21 May 2025Data Diggers Market Research SRLData Diggers Market Research SRL was fined EUR 2,000 by ANSPDCP for another violation related to the processing of personal data. The case indicates non-compliance with data protection requirements and calls for a review of processing procedures.ROANSPDCPGDPR€2,000
21 May 2025Data Diggers Market Research SRLThe company was fined EUR 5,000 by ANSPDCP for failing to provide complete information to complainants exercising their right of access to personal data. The case concerns the obligation to respond fully to access requests.ROANSPDCPGDPR€5,000
21 May 2025SILVANERGIA 2022, S.L.SILVANERGIA 2022, S.L. was fined by the AEPD EUR 5,000 for processing personal data without a legal basis, in breach of Article 6(1) GDPR. The case involved misleading a customer into confirming personal data over the phone.ESAEPDGDPR€5,000
21 May 2025Data Diggers Market Research SRLData Diggers Market Research SRL was fined EUR 5,000 by ANSPDCP. The authority found that the company did not provide complainants with complete information when they exercised their right of access to personal data.ROANSPDCPGDPR€5,000
21 May 2025Menarini Silicon Biosystems SpAThe Garante imposed a 21,000 EUR fine on Menarini Silicon Biosystems SpA for violations related to personal data processing. The case involved inadequate safeguards in the use of algorithms to identify at-risk patients and online reports accessible to other patients.ITGaranteGDPR€21,000
21 May 2025NN ΕλληνικήThe Greek Data Protection Authority imposed a €22,000 fine on NN Ελληνική for refusing to provide recorded telephone calls in response to a data subject access request. The case concerns failure to comply with access rights obligations under data protection law.GRΑρχή Προστασίας Δεδομένων Προσωπικού ΧαρακτήραGDPR€22,000
21 May 2025Agenzia di Tutela della Salute, della Città Metropolitana di Milano, Servizio Prevenzione e Sicurezza Ambienti di Lavoro Milano Città NordAgenzia di Tutela della Salute was fined EUR 7,000 by the Garante for improperly sending medical reports and certificates. The authority found a breach of data protection rules.ITGaranteGDPR€7,000