Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
01 Sept 2025SOCIETE DE VENTE EN LIGNE DE VETEMENTS, CHAUSSURES ET ACCESSOIRESSOCIETE DE VENTE EN LIGNE DE VETEMENTS, CHAUSSURES ET ACCESSOIRES was fined EUR 150,000,000 by CNIL. The case concerns a regulatory breach that resulted in an administrative sanction.FRCNILGDPR€150,000,000
01 Sept 2025Osnovna škola XAZOP imposed a fine of EUR 2,000 on Osnovna škola X for breaching GDPR rules on personal data processing. The case involved unlawful processing of personal data, indicating a compliance failure under data protection requirements.HRAZOPGDPR€2,000
31 Aug 2025A.A.A.A.A.A. was fined by the AEPD EUR 3,000 for using surveillance cameras in a tourist accommodation without a valid legal basis and without informing the individuals concerned. The authority found a breach of Article 6 of the GDPR.ESAEPDGDPR€3,000
31 Aug 2025RISING SUN CAR RENTAL S.L.RISING SUN CAR RENTAL S.L. was fined by the AEPD 6,000 EUR for using surveillance cameras that recorded images and sound without explicit consent or proper justification. The authority also found that the mandatory camera information signs were not displayed.ESAEPDGDPR€6,000
31 Aug 2025DELAFRUIT, S.L.DELAFRUIT, S.L. was fined by the AEPD in the amount of 6,000 EUR for installing cameras in a break area without proper notice to affected individuals. The authority treated this as a breach of data protection rules.ESAEPDGDPR€6,000
29 Aug 2025EXTRA MADRID, S.L.EXTRA MADRID, S.L. sent personalized postal advertising without the recipient’s consent. The AEPD found this to be a breach of Article 6 GDPR and imposed a fine of 1,000 EUR.ESAEPDGDPR€1,000
29 Aug 2025FIATC MUTUA DE SEGUROS Y REASEGUROSFIATC Mutua de Seguros y Reaseguros was fined €40,000 by the AEPD after unauthorized access to its systems. The incident may have exposed personal data, including DNI/CIF, and the authority found inadequate security measures and a breach of Article 5(1)(f) GDPR.ESAEPDGDPR€40,000
28 Aug 2025Home Improvement Marketing LtdHome Improvement Marketing Ltd was investigated by the ICO as part of a wider review of complaint trends in the energy and home improvements sector. After a search warrant and extensive investigation, the ICO found that between 31 May 2023 and 31 August 2023 the company initiated 2,449,380 automated marketing calls to subscribers without prior consent, contrary to PECR. The conduct generated 274 complaints to the TPS and ICO reporting tools.GBICOePrivacy€347,000
28 Aug 2025Green Spark Energy LtdThe ICO investigated Green Spark Energy Ltd as part of a wider operation focused on complaint trends in the energy and home improvements sector. It found that between May 2023 and May 2024 the company initiated 9,587,050 automated recorded marketing calls in breach of regulation 19 of PECR, leading to 497 complaints. The recordings used misleading claims to pressure homeowners, and some recipients believed the calls were a scam.GBICOePrivacy€289,000
27 Aug 2025INGPoland’s data protection authority, UODO, fined ING more than PLN 18 million. The authority found that the bank scanned identity documents in situations not required by AML rules, including for non-customers and in cases unrelated to service provision.PLUrząd Ochrony Danych OsobowychGDPR€4,215,000
25 Aug 2025ASSOCIATION DE DEFENSE DE DROITS FONDAMENTAUX (procédure simplifiée)The CNIL imposed an administrative fine of EUR 10,000 on ASSOCIATION DE DEFENSE DE DROITS FONDAMENTAUX and issued an injunction. The case was handled under a simplified procedure.FRCNILGDPR€10,000
21 Aug 2025Anonymisiert (DSB 2025-0.625.944)Dr. Martha N. unlawfully accessed the electronic health records of a former assistant without a legitimate purpose. The authority found this to be a breach of GDPR principles governing personal data processing.ATDSBGDPR€1,000
20 Aug 2025MOBILITY EVOLUTION S.A.MOBILITY EVOLUTION S.A. was fined EUR 15,000 by the AEPD for failing to properly process data deletion requests submitted through its application. The authority found that the company’s handling of these requests breached Article 25 GDPR on data protection by design and by default.ESAEPDGDPR€15,000
18 Aug 2025SC Elite Conta SRLThe National Supervisory Authority for Personal Data Processing completed an investigation in July 2025 at SC Elite Conta SRL and found a GDPR violation. The company was fined for failing to properly notify a personal data security breach.ROANSPDCPGDPR€3,000
14 Aug 2025ALIQUAM SOFTWARE DEVELOPMENT, S.R.L.UALIQUAM SOFTWARE DEVELOPMENT, S.R.L.U was fined by the AEPD 1,400 EUR for sending unsolicited marketing emails despite requests to stop. The case concerns a breach of the LSSI rules on commercial communications.ESAEPDePrivacy€1,400
13 Aug 2025TELECONTACT LIST S.L.TELECONTACT LIST S.L. was fined by the AEPD €1,000 for failing to respond to a data subject’s requests to exercise the rights of access and erasure. The authority found a breach of GDPR obligations, including Article 17.ESAEPDGDPR€1,000
13 Aug 2025Anonimizirano (IP-RS 0609-97/2024/2)A sole proprietor was fined for failing to respond to a request from the Information Commissioner within the specified 10-day period. The authority treated this as a breach of Article 31 GDPR.SIIP-RSGDPR€500
12 Aug 2025Asociația Casa de Ajutor Reciproc „FLEXICREDIT”In June 2025, ANSPDCP completed an investigation at Asociația Casa de Ajutor Reciproc „FLEXICREDIT” and found violations of GDPR provisions. The entity was fined EUR 3,000.ROANSPDCPGDPR€3,000
11 Aug 2025APARELLS ORTOPEDICS CURTO, S.L.APARELLS ORTOPEDICS CURTO, S.L. did not provide complete personal data and medical records in response to an access request. The AEPD found this to be a breach of data protection rules and imposed a fine of 10,000 EUR.ESAEPDGDPR€10,000
11 Aug 2025FUNDACIÓN PARA EL DESARROLLO DE LA ENFERMERÍA y SINDICATO DE ENFERMERÍA, SATSESATSE and FUDEN were fined by the AEPD EUR 15,000 after a ransomware incident affected personal data. The authority also found that the parties had not properly formalized a joint controllership agreement under the GDPR.ESAEPDGDPR€15,000