Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-24%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
04 Sept 2025Owner of the studentenkotenThe Belgian Data Protection Authority (GBA) imposed a total fine of EUR 9,700 on the owner of a student house. The case concerned the unlawful use of surveillance cameras inside and around the property to monitor students.BEGegevensbeschermingsautoriteit (GBA)GDPR€9,700
04 Sept 2025A*** GmbHA*** GmbH did not report a personal data breach to the Austrian Data Protection Authority within the 72-hour deadline required by Article 33 GDPR. As a result, a fine of EUR 870 was imposed.ATDSBGDPR€870
04 Sept 2025GoogleThe French data protection authority CNIL fined Google for setting advertising cookies without valid user consent. Google was ordered to bring its practices into compliance within a set deadline, with daily penalties possible for non-compliance.FRCNILGDPR€379,000,000
04 Sept 2025SOCIETE EXERCANT UNE ACTIVITE DE GRANDE DISTRIBUTIONThe CNIL imposed an administrative fine of EUR 75,000 on SOCIETE EXERCANT UNE ACTIVITE DE GRANDE DISTRIBUTION and issued an injunction. The case concerns a breach of rules supervised by the CNIL.FRCNILGDPR€75,000
04 Sept 2025Követeléskezeléssel összefüggő jogalap nélküli adatkezelés, tiltakozási joggal kapcsolatos kérelem nem teljesítése és elszámoltathatóság elvének sérelmeThe supervisory authority fined the controller for unlawfully processing the complainant’s phone number in connection with debt collection. It found breaches of lawfulness, data minimization, accountability, and failure to properly handle the data subject’s objection.HUNAIHGDPR€2,540
04 Sept 2025SOCIETE DEVELOPPANT ET COMMERCIALISANT UN LOGICIEL D'AIDE AU RECRUTEMENT (procédure simplifiée)CNIL imposed an administrative fine of EUR 7,000 on SOCIETE DEVELOPPANT ET COMMERCIALISANT UN LOGICIEL D'AIDE AU RECRUTEMENT. The case was handled under a simplified procedure.FRCNILGDPR€7,000
04 Sept 2025SOCIETE COLLECTANT DES DONNEES DE PROSPECTS A PARTIR DE PLUSIEURS SOURCES, NOTAMMENT DES FORMULAIRES DE PARTICIPATION A DES JEUX CONCOURS EN LIGNE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 17,000 on SOCIETE COLLECTANT DES DONNEES DE PROSPECTS A PARTIR DE PLUSIEURS SOURCES, NOTAMMENT DES FORMULAIRES DE PARTICIPATION A DES JEUX CONCOURS EN LIGNE under the simplified procedure. The case concerned the processing of prospect data collected from multiple sources, including online contest entry forms.FRCNILGDPR€17,000
05 Sept 2025AUDIO ÓPTICA EUROPA, S.L.AUDIO ÓPTICA EUROPA, S.L. was fined by the AEPD EUR 1,500 for using a minor’s image without valid consent. The authority found this conduct to be in breach of Article 6 of the GDPR.ESAEPDGDPR€1,500
08 Sept 2025SIA "ZZ Dats"DVI imposed a fine of 300,000 EUR on SIA "ZZ Dats". The decision has been appealed.LVDVIGDPR€300,000
09 Sept 2025EVELB TÉCNICAS Y SISTEMAS, S.LEVELB TÉCNICAS Y SISTEMAS, S.L was fined by the AEPD 5,000 EUR for breaching Article 5(1)(f) GDPR. The case concerned inadequate data security measures that caused a temporary loss of data availability.ESAEPDGDPR€5,000
09 Sept 2025Unita Turism Holding S.A.In August 2025, the National Supervisory Authority for Personal Data Processing completed an investigation at Unita Turism Holding S.A. and found violations of GDPR provisions. As a result, the operator was fined EUR 5,000.ROANSPDCPGDPR€5,000
10 Sept 2025S-PankkiThe sanctions board of the Office of the Data Protection Ombudsman imposed a EUR 1.8 million fine on S-Pankki for failing to ensure information security in its online banking authentication service. The case concerned a software vulnerability in S-mobiili that allowed logins using another customer’s credentials and resulted in a personal data security breach.FIOffice of the Data Protection OmbudsmanGDPR€1,800,000
11 Sept 2025ISV Group SrlsISV Group Srls was fined €15,000 by the Garante for sending unsolicited promotional emails without consent. The authority also found that the company failed to properly control its partner Ismax, which carried out unlawful data processing activities.ITGaranteGDPR€15,000
11 Sept 2025Ministero dell’Interno - Dipartimento dei Vigili del Fuoco, del Soccorso Pubblico e della Difesa CivileThe Ministry of the Interior – Department of Firefighters was fined EUR 12,000 by the Garante. The case concerned personal data processing in breach of GDPR Articles 5, 6 and 9, as well as Articles 2-ter and 2-sexies of the Italian Privacy Code.ITGaranteGDPR€12,000
11 Sept 2025MY s.r.l.MY s.r.l. was fined by the Garante for operating video surveillance without proper alignment with data protection requirements. The case concerned breaches related to the processing of personal data through the camera system.ITGaranteGDPR€6,000
11 Sept 2025ASSOCIATION GERANT UN LYCEE ET UN INTERNAT POUR LES JEUNES EN SITUATION DE DECROCHAGE SCOLAIRE (procédure simplifiée)CNIL imposed an administrative fine of 7,000 EUR on ASSOCIATION GERANT UN LYCEE ET UN INTERNAT POUR LES JEUNES EN SITUATION DE DECROCHAGE SCOLAIRE and issued an injunction. The case was handled under a simplified procedure.FRCNILGDPR€7,000
11 Sept 2025Lenjeria Magică SRLLenjeria Magică SRL was fined by ANSPDCP in the amount of 15,000 RON for violating the national ePrivacy law. The breach concerned articles a)-l), n), o) and q).ROANSPDCPePrivacy€2,958
11 Sept 2025J&D di ZAMBRANO AGUIRRE Ruth JohannaThe Garante imposed a fine of 8,000 EUR on J&D di ZAMBRANO AGUIRRE Ruth Johanna for violations related to the use of a video surveillance system. The authority found that the system was not fully compliant with GDPR requirements.ITGaranteGDPR€8,000
11 Sept 2025Provvedimento dell'11 settembre 2025 [10184252]A public entity was fined by the Garante EUR 500 for installing a video surveillance system in a public parking area without providing adequate information to data subjects. The authority found a breach of GDPR transparency and information obligations.ITGaranteGDPR€500
11 Sept 2025SOCIETE DE VENTE A DISTANCE SUR CATALOGUE SPECIALISE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 5,000 on SOCIETE DE VENTE A DISTANCE SUR CATALOGUE SPECIALISE under a simplified procedure. The case concerns an administrative decision by the French supervisory authority.FRCNILGDPR€5,000