Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
13 Nov 2024Illumia S.p.A.Illumia S.p.A. was fined by the Italian data protection authority, Garante, for violations related to the processing of personal data for telemarketing purposes. The authority cited inadequate contractual arrangements with sub-processors and insufficient oversight of commercial partners.ITGaranteGDPR€678,000
17 Jan 2025Dane anonimowe (X. z siedzibą w K.)The UODO imposed administrative fines on X. based in K. for breaches of Article 6(1), Article 9(1), Article 13(1) and (2), Article 25(1), and Article 32(1) and (2) of the GDPR. These breaches also resulted in violations of the principles in Article 5(1)(a) and (f) and Article 5(2) of the GDPR.PLUODOGDPR€161,000
31 May 2019Kamerafelvételek kiadásának elmulasztásaThe controller did not inform the data subject about the actions taken on their requests within the required timeframe. It also failed to provide access to certain data, which constituted a GDPR breach.HUNAIHGDPR€2,156
14 Oct 2020Munkahelyi kamerás megfigyelés célhoz kötöttséggel, adattakarékossággal és az érintettek tájékoztatásával kapcsolatos hiányosságaiThe entity was fined by NAIH in the amount of HUF 700,000 for improperly implementing camera surveillance of employees. The authority also found that employees were not adequately informed about the scope and rules of the video monitoring.HUNAIHGDPR€1,925
30 Apr 2020vingerafdrukken personeelThe Autoriteit Persoonsgegevens imposed a fine for the unlawful processing of employees' biometric data, specifically fingerprints, for time registration purposes. The authority found this to be a breach of Article 9 of the GDPR.NLAPGDPR€725,000
20 Nov 2025SOCIETE AYANT POUR ACTIVITE L'EDITION DE REVUES ET PERIODIQUES ET LA REGIE PUBLICITAIRECNIL imposed an administrative fine of EUR 750,000 on SOCIETE AYANT POUR ACTIVITE L'EDITION DE REVUES ET PERIODIQUES ET LA REGIE PUBLICITAIRE. The case concerns a confirmed breach of rules supervised by the CNIL.FRCNILGDPR€750,000
27 Feb 2023Bank of Ireland 365 (‘BOI’)The Irish DPC fined Bank of Ireland 365 (‘BOI’) €750,000 in inquiry IN-20-7-2. The fine has been collected.IEDPCGDPR€750,000
27 Nov 2025Conde NastThe French data protection authority CNIL fined Conde Nast EUR 750,000 over cookie practices on the Vanity Fair website. The authority found that the company placed cookies without valid consent, did not provide sufficient information about necessary cookies, and made refusal and withdrawal mechanisms ineffective.FRCNILGDPR€750,000
03 Oct 2024Police Service of Northern IrelandThe Police Service of Northern Ireland was fined £750,000 by the ICO for breaches of Articles 5(1)(f), 32(1) and (2) of the UK GDPR between 25 May 2018 and 14 June 2024. The case concerned insufficient protection of personal data and inadequate security of processing. The decision indicates a failure to implement appropriate technical and organisational safeguards.GBICOGDPR€890,000
10 Oct 2024SOCIETE COMMERCIALISANT DES PORTEFEUILLES DE CRYPTOMONNAIEThe CNIL imposed an administrative fine of EUR 750,000 on SOCIETE COMMERCIALISANT DES PORTEFEUILLES DE CRYPTOMONNAIE. The record indicates a regulatory breach, but no further details are provided.FRCNILGDPR€750,000
22 Jul 2021TikTok Inc.TikTok Inc. was fined 750,000 EUR by the Dutch authority AP for providing its privacy policy to users in the Netherlands, including children, only in English. The authority found this breached Article 12 GDPR, which requires information to be provided in a clear and easily accessible form.NLAPGDPR€750,000
13 Apr 2023Arnia società cooperativaThe Garante imposed a fine of 800,000 EUR on Arnia società cooperativa for unauthorized data processing and telemarketing activities. The case concerned a breach of GDPR Article 5.ITGaranteGDPR€800,000
05 Sept 2024SOCIETE SPECIALISEE DANS L’EDITION ET LA VENTE DE LOGICIELS DE GESTION AUX MEDECINSThe CNIL imposed an administrative fine of EUR 800,000 on SOCIETE SPECIALISEE DANS L’EDITION ET LA VENTE DE LOGICIELS DE GESTION AUX MEDECINS. The case concerns a breach of rules supervised by the CNIL.FRCNILGDPR€800,000
18 Apr 2018Anonymizováno (ÚOOÚ UOOU-09774/17-25)The entity was fined for processing personal data of hundreds of thousands of individuals without consent or another legal basis. The authority found this to be a breach of § 5(2) of the Czech Data Protection Act.CZUOOUGDPR€31,616
01 Jan 2021ORANGE ESPAGNE, S.A.U.ORANGE ESPAGNE, S.A.U. was fined 800,000 EUR by the AEPD for failing to adequately protect personal data. The breach enabled identity fraud and unauthorized access to banking information through SIM card duplication.ESAEPDGDPR€800,000
16 May 2018Telecom Italia S.p.A.Telecom Italia S.p.A. was fined by the Garante €800,000 for the unauthorized activation of numerous residential phone lines in a citizen's name. The case involved processing and disclosing personal data without a legal basis, as well as failing to notify data breaches.ITGaranteGDPR€800,000
09 Dec 2020Ítélet a NAIH/2019/3633/10 sz. ügyben (Fővárosi Törvényszék 106.K.700.561/2019/16) - 2020. december 9.The case concerned a HUF 800,000 fine imposed by the NAIH for unlawful camera surveillance. The authority found that the processing breached GDPR principles of lawfulness, fairness, transparency, purpose limitation, and data minimization.HUNAIHGDPR€2,240
10 Nov 2022SOCIETE DEVELOPPANT UN LOGICIEL DE VOIX SUR IP ET UNE MESSAGERIE INSTANTANEECNIL imposed a fine of 800,000 EUR on SOCIETE DEVELOPPANT UN LOGICIEL DE VOIX SUR IP ET UNE MESSAGERIE INSTANTANEE. The decision concerns a breach of rules covered by the authority’s enforcement action.FRCNILGDPR€800,000
09 Jul 2020Iliad Italia S.p.A.Iliad Italia S.p.A. was fined EUR 800,000 by the Garante for irregularities in the processing of customer data. The violations concerned SIM card activation, promotional use of data, inadequate security measures, and improper data retention.ITGaranteGDPR€800,000
22 Jul 2021Roma CapitaleRoma Capitale was fined EUR 800,000 by the Garante for failing to adequately protect the personal data of motorists using parking meters. The authority also found improper data retention practices, increasing the risk to data subjects.ITGaranteGDPR€800,000