Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
04 Jun 2025Istituto d’Istruzione Superiore “Carlo e Nello Rosselli”The Garante imposed a EUR 4,000 fine on Istituto d’Istruzione Superiore “Carlo e Nello Rosselli” for failing to appoint a Data Protection Officer and for delaying notification of the DPO’s contact details to the authority. The authority also found that transparency obligations toward data subjects were not met.ITGaranteGDPR€4,000
05 Jun 202523andMeThe UK ICO imposed a GBP 2,310,000 fine on 23andMe for personal data protection breaches. The case concerned inadequate safeguards and processing failures that increased the risk of unauthorized access to user data.GBICOGDPR€2,743,000
05 Jun 2025SOCIETE AYANT POUR ACTIVITE PRINCIPALE L'EDITION (procédure simplifiée)CNIL imposed an administrative fine of EUR 10,000 on SOCIETE AYANT POUR ACTIVITE PRINCIPALE L'EDITION and issued an injunction. The case was handled under a simplified procedure.FRCNILGDPR€10,000
05 Jun 2025SOCIETE AYANT POUR ACTIVITE LA FABRICATION ET LE COMMERCE DE PRODUITS PHARMACEUTIQUES DESTINES AU SECTEUR ALIMENTAIRE (procédure simplifiée)The CNIL imposed an administrative fine of 5,000 EUR on the company. The decision was issued under a simplified procedure.FRCNILGDPR€5,000
05 Jun 2025SOCIETE EXERCANT UNE ACTIVITE HOSPITALIERE A BUT LUCRATIF EN MEDECINE-CHIRURGIE-OBSTETRIQUE (procédure simplifiée)The CNIL imposed an administrative fine of 5,000 EUR on SOCIETE EXERCANT UNE ACTIVITE HOSPITALIERE A BUT LUCRATIF EN MEDECINE-CHIRURGIE-OBSTETRIQUE under a simplified procedure. The decision concerns a confirmed compliance breach and was issued by the French data protection authority.FRCNILGDPR€5,000
09 Jun 2025Department of Social ProtectionThe Irish DPC imposed a fine of €550,000 on the Department of Social Protection in inquiry IN-21-7-3. The matter is currently pending appeal (TBC).IEDPCGDPR€550,000
10 Jun 2025Accounting Audit SRLAccounting Audit SRL was fined by ANSPDCP for a data security breach caused by a cyber attack. The incident led to unauthorized disclosure of personal data, including identification data and financial documents, affecting a large number of data subjects, mainly employees of the company’s clients.ROANSPDCPGDPR€10,000
12 Jun 2025Krajowa Szkoła Sądownictwa i Prokuratury (KSSiP)The President of the Polish data protection authority imposed a PLN 100,000 fine on the National School of Judiciary and Public Prosecution for breaching data protection rules during a data migration. The Supreme Administrative Court upheld the decision, making the sanction final.PLUrząd Ochrony Danych OsobowychGDPR€23,425
13 Jun 2025GRUPO BONATEL SLGRUPO BONATEL SL was fined by the AEPD after an incident in which its database was encrypted and a ransom was demanded to prevent public disclosure. The authority found a breach of Article 5(1)(f) GDPR on integrity and confidentiality of personal data.ESAEPDGDPR€30,000
13 Jun 2025Anonymised (HDPA 21/2025)A fine of EUR 1,000 was imposed for violating the data subject’s right of access. The entity did not provide the requested video footage.GRHDPAGDPR€1,000
13 Jun 2025HEP - Toplinarstvo d.o.o.HEP - Toplinarstvo d.o.o. was fined EUR 320,000 for failing to implement appropriate technical and organizational measures to protect data in its “Moj račun” application. The authority also found a lack of cooperation with the supervisory authority, including refusal to provide required information.HRAZOPGDPR€320,000
13 Jun 2025Anonymised (HDPA 21/2025)A fine was imposed for breaching the principles of lawfulness, fairness, and transparency in data processing in connection with a video surveillance system. The case concerned improper processing of personal data through video monitoring.GRHDPAGDPR€2,000
16 Jun 2025SC Kashto Concept SRLANSPDCP completed an investigation at SC Kashto Concept SRL and found a breach of the GDPR. The operator was fined 5,000 RON.ROANSPDCPGDPR€995
16 Jun 2025Υφυπουργείο Κοινωνικής ΠρόνοιαςThe Cypriot Data Protection Commissioner imposed an administrative fine of EUR 5,000 on Υφυπουργείο Κοινωνικής Πρόνοιας on 16 June 2025. The case concerned CCTV cameras at the ministry’s headquarters, including three cameras that recorded audio without a legal basis and without the required GDPR safeguards.CYΕπίτροπος Προστασίας Δεδομένων Προσωπικού ΧαρακτήραGDPR€5,000
17 Jun 2025Szpital, za naruszenie przepisów art. 5 ust. 1 lit. f) i ust. 2, art. 25 ust. 1 oraz art. 32 ust. 1 i 2 rozporządzenia 2016/679,UODO imposed an administrative fine of PLN 66,500 on the hospital. The authority found that the hospital failed to implement appropriate technical and organizational measures to secure personal data and protect data subjects' rights. It also failed to regularly test, measure, and assess the effectiveness of those safeguards.PLUODOGDPR€15,546
18 Jun 2025Dincă Viorel GeorgeThe operator was fined for failing to respond to prior requests from the National Supervisory Authority for Personal Data Processing. The authority also found that a previously imposed corrective measure had not been implemented.ROANSPDCPGDPR€200
18 Jun 2025SOCIETE AYANT POUR ACTIVITE LA VENTE A DISTANCE SUR CATALOGUE GENERAL (procédure simplifiée)The CNIL imposed an administrative fine of 3,000 EUR on SOCIETE AYANT POUR ACTIVITE LA VENTE A DISTANCE SUR CATALOGUE GENERAL. The case was handled under a simplified procedure.FRCNILGDPR€3,000
18 Jun 2025SUNERIS, S.A.SUNERIS, S.A. was fined by the AEPD in the amount of 9,000 EUR for improper handling of personal data. The case involved copying a guest’s information without consent and leaving a master key card accessible, which breached data protection principles.ESAEPDGDPR€9,000
18 Jun 2025Waxholms Ångfartygs AB (WÅAB)IMY fined Waxholms Ångfartygs AB SEK 75,000 for processing personal data without a lawful basis. The authority also found processing of sensitive personal data without an applicable exception, in breach of GDPR Articles 6 and 9.SEIMYGDPR€6,802
18 Jun 2025Aktiebolaget Storstockholms Lokaltrafik (SL)Aktiebolaget Storstockholms Lokaltrafik (SL) was fined 75,000 SEK by IMY for processing personal data without a legal basis and special-category data without a valid exception. The authority found breaches of GDPR Articles 6 and 9.SEIMYGDPR€6,802