Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-24%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
17 Jul 2025Juna S.r.l.Juna S.r.l. was fined €25,000 by the Garante for making repeated unwanted and fraudulent promotional calls to individuals. The conduct breached data protection principles, including lawful and fair processing requirements.ITGaranteGDPR€25,000
17 Jul 2025Comune di Tocco da CasauriaComune di Tocco da Casauria was fined EUR 2,000 by the Garante for publishing personal data on its institutional website. The authority found that the processing did not comply with the principles of lawfulness, fairness, transparency, and data minimization.ITGaranteGDPR€2,000
17 Jul 2025Associazione Il Cavallo Rosa/ChangeTheGame ODVThe Garante fined Associazione Il Cavallo Rosa/ChangeTheGame ODV 10,000 EUR for publishing a minor’s personal data on its Facebook page without anonymization. The authority found a breach of the data subject’s rights under the GDPR.ITGaranteGDPR€10,000
17 Jul 2025Poliambulatorio San Liberale S.r.l.The Garante imposed a EUR 12,500 fine on Poliambulatorio San Liberale S.r.l. for failing to meet information and transparency obligations in the processing of personal data, including health data. The company also did not respond to a data access request, adding a further breach of data subject rights.ITGaranteGDPR€12,500
17 Jul 2025AVOCAT (procédure simplifiée)The CNIL imposed an administrative fine of 3,000 EUR on AVOCAT and issued an injunction. The case was handled under a simplified procedure.FRCNILGDPR€3,000
18 Jul 2025***COMUNIDAD.1The entity was fined for including personal data in community meeting minutes distributed to residents and for inadequate security measures on its community website. The authority found that these failures breached Article 32 of the GDPR on processing security.ESAEPDGDPR€1,000
18 Jul 2025LUXURY ANGELS, S.L.LUXURY ANGELS, S.L. was fined EUR 500 by the AEPD for sending a client a form that contained a third party’s personal data. The authority treated this as a breach of data protection principles.ESAEPDGDPR€500
18 Jul 2025EUROPEAN ENERGY TRADE S.L.EUROPEAN ENERGY TRADE S.L. was fined 600 EUR by the AEPD. The company failed to provide access to data and information requested by the data protection authority, breaching Article 58.1 of the GDPR.ESAEPDGDPR€600
18 Jul 2025LEIVA BUS, S.L.LEIVA BUS, S.L. was fined by the AEPD 3,000 EUR for disclosing the personal data of a claimant and a third party in a damage assessment document. The case concerned a breach of data protection rules and unauthorized disclosure of information.ESAEPDGDPR€3,000
21 Jul 2025VIVLIOPOLEION TIS ESTIAS, I.D. KOLLAROU & SIA A.E.The company was fined by the HDPA 3,000 EUR for failing to implement appropriate technical and organizational measures to secure personal data. The deficiency resulted in unauthorized disclosure of personal data.GRHDPAGDPR€3,000
21 Jul 2025VIVLIOPOLEION TIS ESTIAS, I.D. KOLLAROU & SIA A.E.The company was fined by the HDPA 4,000 EUR for failing to notify the data breach to the supervisory authority and the affected data subjects in a timely manner. The case indicates non-compliance with the statutory notification deadlines following a security incident.GRHDPAGDPR€4,000
21 Jul 2025VIVLIOPOLEION TIS ESTIAS, I.D. KOLLAROU & SIA A.E.The company was fined by the HDPA in the amount of €2,000 for failing to build data protection into the design of its processing and for not applying privacy by default. The authority treated this as a breach of GDPR requirements on privacy by design and by default.GRHDPAGDPR€2,000
22 Jul 2025KVIKU SPAIN, S.L.KVIKU SPAIN, S.L. was fined by the AEPD in the amount of EUR 4,000 for sending unsolicited messages and processing personal data without a legal basis. The authority found a breach of Article 6(1) GDPR.ESAEPDGDPR€4,000
22 Jul 2025Anonimizirano (IP-RS 0609-101/2024/5)A legal entity was fined by IP-RS for a GDPR breach involving the unauthorized disclosure of personal data, including hospital treatment details, via email. The case concerned processing that failed to meet confidentiality and access-control requirements.SIIP-RSGDPR€2,000
23 Jul 2025Agricola International SAAgricola International SA was fined EUR 5,000 by ANSPDCP for a data security breach. The incident was reported by the company itself, indicating an internally detected event that required compliance review.ROANSPDCPGDPR€5,000
23 Jul 2025ING Bank Śląski SAThe Polish supervisory authority imposed an administrative fine on ING Bank Śląski SA for scanning the identity documents of customers and prospective customers without properly assessing whether this was necessary under AML rules. The decision became final on 23 July 2025 and concerns breaches of Articles 5(1)(a), (b) and (c) and 6(1) of the GDPR.PLPresident of the Personal Data Protection OfficeGDPR€4,375,000
23 Jul 2025Dane anonimowe (K.)UODO imposed an administrative fine of PLN 18,416,400 for processing personal data without a lawful basis. The case concerned copying and scanning customers’ identity documents without properly verifying whether this was justified by AML obligations.PLUODOGDPR€4,328,000
24 Jul 2025CURENERGÍACURENERGÍA was fined by the AEPD EUR 1,000,000 for a data protection breach involving improper handling of personal data due to human error. The issue was corrected after notification.ESAEPDGDPR€1,000,000
24 Jul 2025Követeléskezeléssel összefüggő jogalap nélküli adatkezelés és törlési kérelem nem teljesítéseThe authority imposed a fine for a negligent GDPR breach involving the processing of personal data without a legal basis in connection with debt collection. It also found that deletion requests from the data subject were not fulfilled.HUNAIHGDPR€25,100
25 Jul 2025Anonimizirano (IP-RS 0609-34/2025/8)The legal entity did not establish a valid contract with a data processor. This breaches Article 28 GDPR, which requires processing by a processor to be governed by a contract.SIIP-RSGDPR€5,610