Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
19 Jun 2025SC Diamir SRLIn May 2025, ANSPDCP completed an investigation at SC Diamir SRL and found violations of GDPR provisions. The company received a warning and a fine of EUR 1,000.ROANSPDCPGDPR€1,000
23 Jun 2025City of Dublin Education and Training Board (CDETB)The Irish supervisory authority concluded an inquiry into City of Dublin Education and Training Board (CDETB) and found GDPR infringements linked to a personal data breach. It imposed administrative fines totaling EUR 125,000 and issued a reprimand on 23 June 2025.IEData Protection Commission (Ireland)GDPR€125,000
23 Jun 2025Vodafone Romania S.A.Vodafone Romania S.A. was fined EUR 4,000 by ANSPDCP for GDPR violations. The investigation was completed in May 2025.ROANSPDCPGDPR€4,000
23 Jun 2025City of Dublin Education and Training Board (CDETB)The Irish DPC imposed a fine of EUR 125,000 on City of Dublin Education and Training Board (CDETB) in inquiry IN-19-7-3. The fine status is collected.IEDPCGDPR€125,000
23 Jun 2025Dane anonimowe (Pana A. Z., prowadzącego działalność gospodarczą pod firmą „W.” z siedzibą w T. przy ul.)The President of UODO imposed an administrative fine of PLN 18,941 on an entrepreneur operating under the name “W.”. The sanction concerned failure to provide information and failure to grant access to personal data and other information necessary for the authority to perform its duties.PLUODOGDPR€4,430
23 Jun 2025Ordine delle Professioni Infermieristiche di ViterboThe Garante imposed a fine of EUR 10,000 on the Ordine delle Professioni Infermieristiche di Viterbo for breaches of data protection rules. The case concerned non-compliance with requirements governing the processing of personal data.ITGaranteGDPR€10,000
23 Jun 2025Società Autocooperative Trasporti Italiani S.p.A.The company was fined by the Garante for unlawfully disclosing sensitive personal data about employee absences, including the reasons for absence. The information was posted on company notice boards and sent by email to employees.ITGaranteGDPR€10,000
23 Jun 2025Piraeus Bank S.A.Piraeus Bank S.A. was fined by the HDPA 50,000 EUR for unlawfully transferring personal data to third parties without the data subject's consent. The authority found breaches of GDPR principles of lawfulness and accuracy.GRHDPAGDPR€50,000
23 Jun 2025McDonald's Polska sp. z o.o.The President of the Personal Data Protection Office imposed an administrative fine of PLN 16,932,657 on McDonald's Polska sp. z o.o. and a separate fine on its processor. The decision of 2025-06-23 concerned inadequate processor verification, insufficient risk analysis, and failure to implement appropriate GDPR security measures.PLPresident of the Personal Data Protection OfficeGDPR€3,960,000
23 Jun 2025Dane anonimowe (U.)UODO imposed a PLN 94,286 administrative fine on an anonymous entity for improperly vetting a processor before entering into a data processing agreement. The authority also found inadequate technical and organizational safeguards, insufficient testing of their effectiveness, and failure to properly involve the data protection officer in privacy matters.PLUODOGDPR€22,053
24 Jun 2025I ASPIDA TOU DAVIDThe entity did not inform data subjects about the processing of their personal data. The authority treated this as a GDPR breach and imposed a monetary fine.GRHDPAGDPR€3,000
24 Jun 2025BirthlinkThe UK Information Commissioner’s Office (ICO) fined Scottish charity Birthlink GBP 18,000. The case involved the destruction of about 4,800 personal records, up to 10% of which may have been irreplaceable.GBICOGDPR€21,109
24 Jun 2025I ASPIDA TOU DAVIDThe entity failed to provide the required information and to implement adequate data protection measures. HDPA imposed a fine of EUR 3,000 for breach of GDPR principles.GRHDPAGDPR€3,000
24 Jun 2025PROCONO SAPROCONO SA was fined EUR 300,000 by the AEPD for a data breach. The incident exposed customer data on the internet, including names, addresses, email addresses, and possibly bank account details.ESAEPDGDPR€300,000
24 Jun 2025OLXUOKiK imposed a PLN 28.4 million fine on OLX for irregularities in its ratings system that could mislead consumers. The decision was not yet final, as OLX could appeal.PLUrząd Ochrony Konkurencji i KonsumentówOmnibus€6,676,000
24 Jun 2025I ASPIDA TOU DAVIDThe entity did not satisfy a minor's request to access personal data, which constitutes a breach of GDPR principles. HDPA imposed a fine of EUR 3,000.GRHDPAGDPR€3,000
24 Jun 2025I ASPIDA TOU DAVIDThe HDPA imposed a EUR 1,000 fine on I ASPIDA TOU DAVID. The authority found that the entity failed to cooperate, which breaches GDPR requirements.GRHDPAGDPR€1,000
25 Jun 2025Vodafone-PanafonVodafone-Panafon was fined EUR 150,000 by the HDPA for inadequate technical and organizational security measures. The authority found a violation of Article 12 of Law 3471/2006.GRHDPAePrivacy€150,000
25 Jun 2025Vodafone-PanafonVodafone-Panafon was fined by the HDPA for failing to notify a data breach in a timely manner. The authority cited a violation of Article 12 of Law L.3471/2006.GRHDPAePrivacy€100,000
26 Jun 2025SC Piramida Trade Invest SRLSC Piramida Trade Invest SRL received a fine of EUR 1,000 from ANSPDCP. The sanction concerns a breach of Article 6 GDPR, meaning personal data were processed without a valid legal basis.ROANSPDCPGDPR€1,000