Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
23 Feb 2023Okmánymásolás és fényképek készítése és közzététele munkahelyenThe authority imposed a fine for copying applicants’ identity documents and for failing to provide adequate information to data subjects during the recruitment process. The case concerned breaches of information duties and personal data processing rules in the workplace.HUNAIHGDPR€524
01 Jun 2023NH Italia S.p.A.NH Italia S.p.A. was fined EUR 200,000 by the Garante for failing to appoint specific data processors responsible for the installation and maintenance of video surveillance systems. The authority found this breached the GDPR principles of lawful, fair, and transparent processing of personal data.ITGaranteGDPR€200,000
21 Sept 2023Cover Appliance LtdCover Appliance Ltd made 511,499 marketing calls to individuals in breach of regulation 21 of PECR. The ICO imposed a fine of 200,000 GBP and issued an enforcement notice.GBICOePrivacy€230,000
02 Feb 2023VODAFONE ESPAÑA, S.A.U.Vodafone España was fined by the AEPD for changing a customer's contract ownership and activating services without consent. The authority found a breach of Article 6(1) GDPR.ESAEPDGDPR€200,000
26 Apr 2023Regionstyrelsen i Region SkåneRegionstyrelsen i Region Skåne was fined by IMY for storing unencrypted sensitive patient data on a USB drive that was lost. The authority found this to be a breach of Article 32 GDPR, which requires appropriate technical and organisational security measures.SEIMYGDPR€17,566
16 Oct 2019Dane anonimowe (S. Sp. z o.o. z siedzibą w P., karę pieniężną w kwocie 201 559,50 PLN)UODO imposed a fine of PLN 201,559.50 on S. Sp. z o.o. for failing to implement appropriate technical and organizational measures. The authority also found that personal data were processed without a lawful basis, which led to the sanction.PLUODOGDPR€46,923
01 Jan 2025Εθνική Τράπεζα της Ελλάδος Α.Ε.The data protection authority imposed a EUR 220,000 fine on Εθνική Τράπεζα της Ελλάδος Α.Ε. for a GDPR violation. The case concerned deficiencies in personal data protection and compliance with GDPR requirements.GRΑρχή Προστασίας Δεδομένων Προσωπικού ΧαρακτήραGDPR€220,000
01 Jan 2024GESTERNOVA, S.A.GESTERNOVA, S.A. was fined by the AEPD in the amount of 220,000 EUR for processing personal data without a valid legal basis. The authority also found that the company failed to provide the required information to the data subject, in breach of GDPR Articles 6(1), 13, and 14.ESAEPDGDPR€220,000
26 Apr 2023CARTONAJES BAÑERES, S.A.CARTONAJES BAÑERES, S.A. was fined by the AEPD 220,000 EUR for processing biometric data without the required data protection impact assessment. The authority also found a failure to comply with data subjects’ access rights.ESAEPDGDPR€220,000
21 Feb 2013Elettrodomestici Parise sncElettrodomestici Parise snc was fined 222,000 EUR by the Italian Garante. The company improperly registered numerous phone cards to unaware third parties and then sold them to phone centers, breaching data protection rules.ITGaranteGDPR€222,000
12 May 2021xy d.o.o.The company xy d.o.o. was fined by AZOP for failing to implement appropriate technical security measures. This resulted in unauthorized processing of personal data of 28,085 data subjects, indicating a data protection compliance failure.HRAZOPGDPR€30,553
05 Apr 2018I Tel s.r.l.I Tel s.r.l. was fined EUR 230,000 by the Italian data protection authority, Garante. The case concerned the registration of phone cards to 23 individuals without their consent, in breach of data protection rules.ITGaranteGDPR€230,000
14 Apr 2023Green Network S.p.a.Green Network S.p.a. was fined by the Garante for illegal telemarketing practices in the energy sector. The authority found a breach of data protection principles.ITGaranteGDPR€237,000
24 Jun 2010Enterprise Group s.r.l.Enterprise Group s.r.l. was fined EUR 238,000 by the Garante. The authority found that the company failed to provide timely information to data subjects and sent unsolicited marketing communications without prior consent.ITGaranteGDPR€238,000
29 Apr 2024Dane anonimowe (A. Sp. k. z siedzibą w T.)UODO imposed a PLN 238,345 administrative fine on A. Sp. k. for failing to implement appropriate technical and organizational measures proportionate to the risk of data processing, including the use of external storage media. The authority also found a lack of regular testing, measurement, and evaluation of the effectiveness of the security measures in place.PLUODOGDPR€55,103
27 Apr 2023Ama S.p.a.Ama S.p.a. was fined €239,000 by the Garante for the unlawful processing and dissemination of personal health data concerning women who had terminated pregnancies. The identities were displayed on crosses at a cemetery, resulting in an unlawful disclosure of sensitive data.ITGaranteGDPR€239,000
20 Oct 2023Outsource Strategies LtdOutsource Strategies Ltd made 1,346,503 unwanted marketing calls between 11 February 2021 and 22 March 2022 to numbers registered with the TPS. The ICO received 74 complaints, including reports of repeated calls despite requests to stop and aggressive caller behaviour.GBICOGDPR€275,000
05 Dec 2024SOCIETE DEVELOPPANT ET COMMERCIALISANT UNE EXTENSION POUR NAVIGATEURThe CNIL imposed an administrative fine of EUR 240,000 on SOCIETE DEVELOPPANT ET COMMERCIALISANT UNE EXTENSION POUR NAVIGATEUR and issued an injunction. The case concerns identified regulatory breaches.FRCNILGDPR€240,000
27 Apr 2023Benetton Group S.r.l.Benetton Group S.r.l. was fined €240,000 by the Italian data protection authority, Garante. The authority found violations in the processing of personal data for marketing and profiling purposes, including the retention of former customers’ data for more than 10 years without proper justification.ITGaranteGDPR€240,000
05 Dec 2024KASPRThe CNIL imposed an administrative fine of €240,000 on KASPR on 5 December 2024. The case concerned data scraping and multiple GDPR breaches, including lack of lawful basis, poor transparency, excessive retention, and failure to respect access rights.FRCNILGDPR€240,000