Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
27 Nov 2025Verisure Italy s.r.l.Verisure Italy s.r.l. was fined by the Garante EUR 400,000 for breaches of data retention and information obligations in connection with marketing activities. The case concerned customer and former customer data processed without proper consent and notice.ITGaranteGDPR€400,000
21 May 2025Autostrade per l'Italia SpaThe Italian data protection authority fined Autostrade per l'Italia Spa EUR 420,000 for unlawfully processing an employee's personal data. The company used content from her Facebook profile and private Messenger and WhatsApp chats to support disciplinary proceedings and justify her dismissal.ITGarante per la protezione dei dati personaliGDPR€420,000
06 Dec 2011Tiscali Italia SpATiscali Italia SpA was fined €420,000 by the Garante for retaining customer traffic data beyond the legal retention period. The authority also found that Amdocs accessed the data without being properly designated as a data processor or obtaining customer consent.ITGaranteGDPR€420,000
11 Feb 2021Stichting OLVGStichting OLVG was fined by the AP 440,000 EUR for failing to implement two-factor authentication and for not regularly reviewing log files. The authority found that the organization did not maintain appropriate security measures required under Article 32 GDPR.NLAPGDPR€440,000
01 Oct 2024TRIVE CREDIT SPAIN, S.L.TRIVE CREDIT SPAIN, S.L. failed to properly handle a data subject access request, which constitutes a breach of Article 15 GDPR. The AEPD imposed a fine for non-compliance with a prior resolution.ESAEPDGDPR€450,000
07 Jul 2021Uitvoeringsinstituut werknemersverzekeringen (UWV)UWV was fined by the AP for failing to ensure an adequate level of security for personal data. The deficiencies led to multiple breaches involving sensitive information of job seekers.NLAPGDPR€450,000
09 Dec 2020Twitter International CompanyThe Irish DPC imposed a fine of EUR 450,000 on Twitter International Company in inquiry IN-19-1-1. The fine was collected.IEDPCGDPR€450,000
16 Jul 2019Stichting HagaZiekenhuisStichting HagaZiekenhuis was fined by the AP for failing to implement two-factor authentication and for not regularly reviewing log files. The authority found these shortcomings breached Article 32 GDPR on appropriate security measures.NLAPGDPR€460,000
23 Feb 2023Centric Health Ltd. (“Centric”)The Irish DPC imposed a fine of EUR 460,000 on Centric Health Ltd. in inquiry IN-21-2-4. The fine has been collected.IEDPCGDPR€460,000
14 Mar 2022Bank of Ireland Group plcThe Irish DPC fined Bank of Ireland Group plc EUR 463,000 in inquiry IN-19-9-5. The penalty status is recorded as collected.IEDPCGDPR€463,000
31 Mar 2021Booking.com B.V.Booking.com B.V. was fined for failing to report a personal data breach to the Dutch Data Protection Authority within 72 hours of becoming aware of it, as required by GDPR Article 33. The case concerns the controller’s obligation to notify the supervisory authority without undue delay.NLAPGDPR€475,000
06 Jan 2025Anonymisé (CNPD decision-01-fr-2025)The entity failed to comply with the response time requirements for data subject requests, which constitutes a breach of Article 12 GDPR. CNPD imposed a fine of EUR 493,560.LUCNPDGDPR€493,000
01 Jan 2024SANTANDER CONSUMER FINANCE, S.A.Santander Consumer Finance, S.A. was fined by the AEPD 500,000 EUR for a data protection breach. The incident affected personal identification and contact data of 28,120 individuals.ESAEPDGDPR€500,000
22 Mar 2021Tájékoztatási kötelezettség elmulasztása, hozzáférési jog és adatkezelés korlátozásához való jogThe controller did not inform the data subject within the required timeframe about actions taken on their requests. It also delayed access to the requested footage and failed to block the camera recording, resulting in a data protection fine.HUNAIHGDPR€1,365
25 Mar 2021Kamerák üzemeltetése idősek otthonábanThe authority imposed a fine for using video surveillance for unlawful purposes. It also found that the data subjects were not adequately informed and that there was no proper legal basis for processing.HUNAIHGDPR€1,370
27 Apr 2021Diszpécseri munkakört betöltő munkavállalóval folytatott telefonhívás rögzítéseThe decision concerned the unlawful recording and use of phone calls without a proper legal basis and without adequate transparency. The authority found breaches of GDPR accountability, lawful processing, and transparency principles.HUNAIHGDPR€1,380
03 Dec 2025AVATEL TELECOM, S.A.AVATEL TELECOM, S.A. was fined 500,000 EUR by the AEPD for unauthorized duplication of SIM cards and their fraudulent use. The case concerns breaches of data protection principles and controls over access to telecommunications services.ESAEPDGDPR€500,000
31 Jan 2024MARINA SALUD, S.A.MARINA SALUD, S.A. was fined by the AEPD 500,000 EUR for failing to comply with data processing agreement obligations under Article 28 GDPR. The case involved the handling of sensitive health data, which increased the compliance risk.ESAEPDGDPR€500,000
24 Nov 2023Pitagorasz Oktatási Stúdió Kft.Pitagorasz Oktatási Stúdió Kft. was fined by NAIH for processing minors' personal data without a valid legal basis. The authority found breaches of GDPR principles, including accountability, purpose limitation, and transparency.HUNAIHGDPR€1,315
20 Dec 2019Hozzáférési jog terjedelmeThe controller did not inform the data subject about actions taken on their requests within the required timeframe. It also failed to provide access to certain data, which constitutes a GDPR breach.HUNAIHGDPR€1,515