Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
11 Jul 2022Anonymizováno (ÚOOÚ UOOU-04856/21-13)The entity was fined by the UOOU 250,000 CZK for sending unsolicited commercial communications by email to approximately 266,607 recipients without their consent. This conduct violated Czech rules on certain information society services.CZUOOUePrivacy€10,165
09 Jan 2024Det Kongelige TeaterThe Danish DPA reported Det Kongelige Teater to the police and recommended a fine of 250,000 DKK. The case concerned the absence of deletion rules for customer data used for marketing, affecting about 520,000 individuals.DKDatatilsynetGDPR€33,523
15 Mar 2012Ammiro Partners s.r.l.Ammiro Partners s.r.l. was fined for violations related to the processing of personal data. The authority cited failure to comply with a prior injunction and failure to respond to requests from the Garante.ITGaranteGDPR€250,000
29 Oct 2024Grue kommuneGrue kommune was fined 250,000 NOK by Datatilsynet after personal data was made accessible in its public journal. The authority found breaches of confidentiality requirements and GDPR rules on legal basis and security.NODatatilsynetGDPR€21,113
25 Mar 2019Taxa 4x35The Danish data protection authority recommended a fine for Taxa 4x35 for failing to delete customer data. The company retained personal data from taxi rides without a legitimate purpose, and the court ultimately imposed a fine of DKK 250,000.DKDatatilsynetGDPR€33,493
24 Jan 2024CAJA RURAL DE ASTURIAS, S.C.C.CAJA RURAL DE ASTURIAS was fined by the AEPD EUR 250,000 for breaching the confidentiality and integrity principles of personal data. The incident allowed unauthorized access to personal data, indicating a failure to protect data appropriately.ESAEPDGDPR€250,000
23 Jan 2024CAJA RURAL DE SALAMANCA, S.C.C.CAJA RURAL DE SALAMANCA, S.C.C. was fined by the AEPD 250,000 EUR for failing to ensure the confidentiality and integrity of personal data. The breach resulted in unauthorized access following a data security incident.ESAEPDGDPR€250,000
26 Sept 2024SOCIETE PROPOSANT DES SERVICES A DISTANCE D'ART DIVINATOIRECNIL imposed an administrative fine of EUR 250,000 on SOCIETE PROPOSANT DES SERVICES A DISTANCE D'ART DIVINATOIRE. The case concerns a breach of rules supervised by CNIL.FRCNILGDPR€250,000
28 Aug 2025Green Spark Energy LtdThe ICO investigated Green Spark Energy Ltd as part of a wider operation focused on complaint trends in the energy and home improvements sector. It found that between May 2023 and May 2024 the company initiated 9,587,050 automated recorded marketing calls in breach of regulation 19 of PECR, leading to 497 complaints. The recordings used misleading claims to pressure homeowners, and some recipients believed the calls were a scam.GBICOePrivacy€289,000
08 Sept 2022GROUPEMENT D'INTÉRÊT ÉCONOMIQUE DES GREFFES DE TRIBUNAUX DE COMMERCE DE FRANCECNIL imposed a fine of 250,000 EUR on GROUPEMENT D'INTÉRÊT ÉCONOMIQUE DES GREFFES DE TRIBUNAUX DE COMMERCE DE FRANCE. The record states that the sanction concerns a violation, but no further details are provided.FRCNILGDPR€250,000
18 Dec 2024Dane anonimowe (C. S.A. z siedzibą w D. przy ul.)UODO imposed an administrative fine of PLN 261,918 on C. S.A. for breaches of GDPR obligations. The case concerned, among others, Article 38(3), Article 30(1), and Article 35(1) and (7) of Regulation 2016/679.PLUODOGDPR€61,514
29 Dec 2025SOCIETE EDITANT UNE APPLICATION MOBILECNIL imposed an administrative fine of EUR 270,000 on SOCIETE EDITANT UNE APPLICATION MOBILE. The case concerns a breach of personal data protection rules and should be considered in compliance assessments.FRCNILGDPR€270,000
21 Mar 2024LAZIOcrea S.p.a.LAZIOcrea S.p.a. was fined by the Garante for failing to implement adequate technical and organizational measures to ensure data security. The deficiencies led to unauthorized access attempts and temporary unavailability of regional services.ITGaranteGDPR€271,000
05 Aug 2021Anonymisé (CNPD decision-31-fr-2021)The company sent emails containing sensitive medical data to incorrect recipients. The authority also found a breach of data protection duties due to improper documentation of the incidents.LUCNPDGDPR€275,000
08 May 2026Permanent TSBPermanent TSB was fined EUR 277,500 by Ireland's Data Protection Commission. The case involved fraudsters impersonating customers at a contact centre, resulting in three GDPR breaches and financial loss to three customers.IEData Protection CommissionGDPR€277,000
01 Mar 2018Massimo FarinaMassimo Farina was fined EUR 280,000 by the Garante. The case concerned the use of prepaid credit cards under false names without obtaining consent, which breached data protection rules.ITGaranteGDPR€280,000
30 Nov 2023Dane anonimowe (V. S.A. z siedzibą w P. ul.)UODO imposed an administrative fine of PLN 282,960 on the controller for failing to report a personal data breach to the supervisory authority. The authority also found that the affected data subject was not notified of the breach.PLUODOGDPR€65,064
08 Jun 2023La Rinascente S.p.A.La Rinascente S.p.A. was fined by the Garante for unauthorized access to customer data and its modification. The breach led to the issuance of a new loyalty card containing incorrect personal details.ITGaranteGDPR€300,000
20 May 2026KRA Consultancy LtdKRA Consultancy Ltd was fined £300,000 by the ICO for sending more than 5.5 million unsolicited direct marketing texts and fake bailiff messages. The conduct breached regulations 22 and 23 of PECR and generated over 60,000 complaints to the 7726 spam reporting service.GBICOePrivacy€346,000
29 Aug 2024EDITEUR DE SITE WEB DANS LE DOMAINE DES TRANSPORTSEDITEUR DE SITE WEB DANS LE DOMAINE DES TRANSPORTS was fined EUR 300,000 by the CNIL. The case concerns a breach of personal data protection rules.FRCNILGDPR€300,000