Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-24%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
25 Sept 2025JacksonsThe ODPA fined Jacksons £65,000 after finding that the company unlawfully changed customer marketing preferences. The investigation identified anomalies in customer records and direct marketing communications made against customers’ wishes.GGODPAGDPR€74,302
25 Sept 2025Officine Serena s.r.l.Green.mec. s.r.l. did not respond to a data subject’s request for training certificates and communications related to the termination of employment. The Garante imposed a fine of 1,000 EUR on Officine Serena s.r.l., the incorporating company.ITGaranteGDPR€1,000
25 Sept 2025Vimar S.p.A.Vimar S.p.A. was fined EUR 15,000 by the Garante for failing to provide adequate information to a complainant and for improper account handling. The account was accessible to unauthorized individuals, indicating weaknesses in access control and safeguards.ITGaranteGDPR€15,000
25 Sept 2025RCS MediaGroup S.p.a.RCS MediaGroup S.p.a. was fined by the Italian data protection authority, Garante, in the amount of EUR 100,000. The case concerned the publication of images of a person in a private setting without consent, which infringed privacy rights.ITGaranteGDPR€100,000
25 Sept 2025Provincia Autonoma di TrentoProvincia Autonoma di Trento was fined for processing personal data without a legal basis, lacking transparency, and failing to conduct a data protection impact assessment. The authority found breaches of several GDPR provisions.ITGaranteGDPR€8,000
25 Sept 2025S.C. PRIMONET RO S.R.L.The company was fined for a data security breach that enabled unauthorized transactions on affected cards. The incident caused financial losses to the data subjects.ROANSPDCPGDPR€20,000
25 Sept 2025Comune di Isola del Gran Sasso d’ItaliaThe Garante fined the Comune di Isola del Gran Sasso d’Italia EUR 3,000 for unlawfully publishing personal data on its institutional website, including information related to criminal proceedings. The authority found breaches of lawfulness, fairness, transparency, and data minimization.ITGaranteGDPR€3,000
25 Sept 2025Comune di PazzanoThe Garante imposed a fine of 3,960 EUR on Comune di Pazzano for failing to meet data protection obligations. The case concerned, among other issues, the improper provision of the Data Protection Officer’s contact details and other GDPR requirements.ITGaranteGDPR€3,960
25 Sept 2025La Prima SrlLa Prima Srl was fined EUR 10,000 by the Garante for sending unsolicited emails. The authority also found that the company failed to respond to a data deletion request, in breach of the GDPR.ITGaranteGDPR€10,000
25 Sept 2025E-Power S.r.l.E-Power S.r.l. was fined EUR 35,000 by the Garante for making promotional calls without a valid legal basis. The authority also found that the company failed to respond to data subject rights requests, which breaches GDPR requirements.ITGaranteGDPR€35,000
25 Sept 2025Azienda Ospedaliero Universitaria di FerraraAzienda Ospedaliero Universitaria di Ferrara was fined EUR 20,000 by the Garante for irregularities in the handling of personal data in its health dossier system. The authority found that the organization failed to implement adequate measures to protect data privacy.ITGaranteGDPR€20,000
02 Oct 2025TIGER MEDIA INC.TIGER MEDIA INC. was fined by the AEPD EUR 120,000 for processing personal data without a lawful basis. The authority also found that the company failed to appoint an EU representative, in breach of GDPR Articles 6 and 27.ESAEPDGDPR€120,000
02 Oct 2025EMAGISTER SERVICIOS DE FORMACIÓN, S.L.EMAGISTER SERVICIOS DE FORMACIÓN, S.L. was fined EUR 80,000 by the AEPD for a data security incident involving unauthorized processes on its web servers. The authority found a breach of data protection principles.ESAEPDGDPR€80,000
02 Oct 2025RETSINNAL GROUP, S.L.U.RETSINNAL GROUP, S.L.U. was fined 1,000 EUR by the AEPD for deficiencies in its website privacy policy. The authority found that the company did not provide adequate information about the data controller, in breach of Article 13 GDPR.ESAEPDGDPR€1,000
02 Oct 2025UNIVERSITE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 15,000 on UNIVERSITE (procédure simplifiée). The case concerns a breach of rules supervised by the CNIL.FRCNILGDPR€15,000
03 Oct 2025INTEGRAL DE VIGILANCIA Y CONTROL, S.L.INTEGRAL DE VIGILANCIA Y CONTROL, S.L. was fined by the AEPD 5,000 EUR for sending emails to a personal email address without a proper legal basis. The authority treated this as a breach of data protection rules.ESAEPDGDPR€5,000
04 Oct 2025OVH HISPANO, S.L.U.OVH HISPANO, S.L.U. was fined by the AEPD 120,000 EUR for a data protection breach. Confidential emails and documents of third parties were improperly shared due to inadequate data protection measures.ESAEPDGDPR€120,000
07 Oct 2025Anonymisiert (DSB 2025-0.778.661)An individual unlawfully accessed and processed personal data from a secured hard drive without a legitimate purpose. The authority found this to be a breach of core GDPR principles, including lawfulness and purpose limitation.ATDSBGDPR€2,500
09 Oct 2025SOCIETE EXERCANT UNE ACTIVITE DE VENTE A DISTANCE SUR CATALOGUE GENERAL (procédure simplifiée)The CNIL imposed an administrative fine of EUR 4,000 on SOCIETE EXERCANT UNE ACTIVITE DE VENTE A DISTANCE SUR CATALOGUE GENERAL. The case was handled under a simplified procedure.FRCNILGDPR€4,000
09 Oct 2025Arienti & C. s.r.l. a socio unicoThe Garante fined Arienti & C. s.r.l. a socio unico EUR 8,000 for denying a former employee access to their email account after the employment contract ended. The authority found this breached GDPR Article 15 on the right of access to personal data.ITGaranteGDPR€8,000