Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
23 Jun 2025Piraeus Bank S.A.Piraeus Bank S.A. was fined by the HDPA 50,000 EUR for unlawfully transferring personal data to third parties without the data subject's consent. The authority found breaches of GDPR principles of lawfulness and accuracy.GRHDPAGDPR€50,000
16 Jun 2010Anonymised (HDPA 29/2010)The company was fined 3,000 EUR by the HDPA for unlawfully processing email addresses without prior consent. This conduct breached Greek data protection law.GRHDPAGDPR€3,000
08 Aug 2014Anonymised (HDPA 112/2014)The controller sent unsolicited marketing SMS messages without recipients' consent, breaching data protection rules. The case concerned the use of contact data for marketing without a valid legal basis.GRHDPAePrivacy€1,000
09 Jan 2025National Bank of GreeceNational Bank of Greece was fined €20,000 by the HDPA. The authority found that the bank failed to provide data subjects with timely access to their personal data, breaching GDPR Articles 15 and 12.GRHDPAGDPR€20,000
09 Oct 2018CosmoteCosmote was fined EUR 150,000 by the HDPA for making unsolicited promotional calls to subscribers who had opted out of such contact. The authority found that this conduct breached privacy and personal data protection rules.GRHDPAePrivacy€150,000
21 Feb 2017MILI CAFEMILI CAFE was fined EUR 1,000 for unlawful video surveillance practices. The violations included recording audio without proper security measures and retaining footage for more than 15 days.GRHDPAGDPR€1,000
15 Feb 2022Organismos Limenos Irakleiou A.E.Organismos Limenos Irakleiou A.E. was fined 30,000 EUR by the HDPA for breaching the data subject’s right of access. The company failed to provide requested video footage and incorrectly claimed that the data had been deleted.GRHDPAGDPR€30,000
22 Sept 2022Anonymised (HDPA 51/2022)The fined entity did not comply with a data subject access request and did not provide any justification for failing to act on it. It also failed to inform the data subject about further processing and the transfer of their data to the police.GRHDPAGDPR€3,000
12 Jun 2015ALPHA BANKALPHA BANK was fined 30,000 EUR by the HDPA. The authority found that the bank failed to notify the location and facilities used for ICAP data processing.GRHDPAGDPR€30,000
12 Jun 2015Tiresias AETiresias AE was fined for failing to implement measures to control access to personal data files. This failure led to unauthorized access by ICAP.GRHDPAGDPR€30,000
30 Mar 2023Vodafone-PanafonVodafone-Panafon was fined by the HDPA for failing to respond to a data subject access request concerning recorded calls. The authority also found that the company did not notify a personal data breach to the regulator.GRHDPAGDPR€40,000
22 Oct 2024political partyThe Hellenic Data Protection Authority imposed a 10,000 EUR fine on a political party for unlawful processing of the personal data of overseas voters. The case concerns data protection breaches in the handling of electoral information.GRHellenic Data Protection AuthorityGDPR€10,000
11 Feb 2025Primary Health Care of the Capital AreaThe Icelandic Supervisory Authority imposed an administrative fine on Primary Health Care of the Capital Area for unlawful processing related to the integration of medical record systems. The decision was finalized on 11 February 2025, and the fine amounted to 5,000,000 ISK.ISIcelandic Data Protection AuthorityGDPR€34,100
21 Sept 2023F12 Management LtdF12 Management Ltd made 1,346,019 marketing calls to individuals in breach of regulation 21 of PECR. The ICO imposed a £200,000 fine and issued an enforcement notice.GBICOePrivacy€230,000
24 Apr 2025Darian Bishop trading as ECO4UBetween 9 January 2023 and 9 October 2023, 194,110 unsolicited direct marketing calls were made to subscribers registered with the TPS who had not indicated consent to receive such calls. The conduct generated 21 complaints to the Commissioner and the TPS, leading to an ICO fine.GBICOGDPR€58,480
15 Aug 2024Coastal Windows & Conservatories (UK) LimitedCoastal Windows & Conservatories (UK) Limited made more than 18,000 unsolicited marketing calls between 1 January and 1 June 2023 to numbers registered with the TPS. The ICO and TPS received numerous complaints from people who said they had not consented to the calls or continued to receive them after asking for the calls to stop.GBICOGDPR€46,720
15 Feb 2023It's OK LimitedBetween 1 July 2019 and 1 June 2020, It's OK Limited made 1,752,149 unsolicited direct marketing calls to subscribers who had been registered with the TPS for at least 28 days. The company had no evidence that the recipients had not objected to receiving such calls, breaching regulation 21 of PECR.GBICOePrivacy€225,000
10 Oct 2024Service Box Group LimitedService Box Group Limited made 5,361 marketing calls to individuals in breach of regulation 21 of PECR. The ICO imposed a fine of GBP 40,000 and issued an enforcement notice.GBICOePrivacy€47,796
26 Oct 2023Argentum Data Solutions LtdBetween 1 January 2021 and 31 January 2022, a total of 2,330,423 SMS messages were sent without consent. Argentum Data Solutions Ltd sent 24,309 messages directly and allowed its lines to be used by third parties to send the remaining 2,306,114. The conduct breached regulation 22 of PECR and came to the ICO’s attention through complaints reported via the 7726 spam tool.GBICOePrivacy€74,568
20 May 2026KRA Consultancy LtdKRA Consultancy Ltd was fined £300,000 by the ICO for sending more than 5.5 million unsolicited direct marketing texts and fake bailiff messages. The conduct breached regulations 22 and 23 of PECR and generated over 60,000 complaints to the 7726 spam reporting service.GBICOePrivacy€346,000