Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
23 Jun 2025Dane anonimowe (U.)UODO imposed a PLN 94,286 administrative fine on an anonymous entity for improperly vetting a processor before entering into a data processing agreement. The authority also found inadequate technical and organizational safeguards, insufficient testing of their effectiveness, and failure to properly involve the data protection officer in privacy matters.PLUODOGDPR€22,053
03 Dec 2020Dane anonimowe (W. Polska Sp. z o.o. z siedzibą w G.)UODO imposed a fine of PLN 1,968,524 on W. Polska Sp. z o.o. for failing to implement appropriate technical and organizational measures. The authority found that the security level did not match the risk associated with processing subscribers’ personal data in IT systems.PLUODOGDPR€440,000
04 Nov 2025McDonald'sThe Polish Data Protection Authority imposed a EUR 4,022,773 fine on McDonald's for insufficient security measures in personal data processing. A separate EUR 43,680 fine was also issued to the service provider involved in the same incident.PLPolish Data Protection AuthorityGDPR€4,022,000
25 Jan 2023Dane anonimowe (S. Sp. z o.o. z siedzibą w R. przy ul.)The President of UODO imposed an administrative fine of PLN 18,279 on the company. The sanction was issued for failing to cooperate with the authority and for not providing information necessary for the performance of its duties.PLUODOGDPR€3,876
31 May 2023Dane anonimowe (P. Sp. z o.o. z siedzibą w W. przy ul.)UODO imposed a PLN 47,160 fine on the anonymous company for failing to implement appropriate technical and organizational measures to secure personal data processing in IT systems. The authority also found a lack of regular testing, measuring, and evaluation of the effectiveness of those measures, as well as failure to report the personal data breach without undue delay. In addition, the company did not notify affected individuals without undue delay despite a high risk to their rights and freedoms.PLUODOGDPR€10,395
01 Jan 2021Município de LisboaThe Portuguese data protection authority fined Município de Lisboa EUR 1,250,000 in 2021. The sanction concerned the unlawful transfer of protesters’ personal data to the Russian Embassy in breach of the GDPR.PTComissão Nacional de Proteção de DadosGDPR€1,250,000
30 Oct 2024Untold SRLIn September 2024, ANSPDCP completed an investigation at Untold SRL and found violations of GDPR provisions. As a result, the company was fined EUR 10,000.ROANSPDCPGDPR€10,000
22 Aug 2024Sancțiuni pentru încălcarea RGPDThe ANSPDCP fined the company EUR 3,000 for violating Article 2 of the GDPR. The case concerned non-compliance with data protection requirements.ROANSPDCPGDPR€3,000
22 Aug 2024Kaufland România SCSKaufland România SCS was fined EUR 3,000 by ANSPDCP for a data security breach. The case concerns an incident involving personal data protection that resulted in an administrative sanction.ROANSPDCPGDPR€3,000
14 May 2021persoană fizicăA natural person was fined EUR 200 by ANSPDCP for violating GDPR requirements. The case concerned breaches related to the processing of personal data.ROANSPDCPGDPR€200
28 Apr 2025Xiting ROM SRLIn April 2025, ANSPDCP completed an investigation at Xiting ROM SRL and found violations of GDPR provisions. As a result, a fine of EUR 1,000 was imposed.ROANSPDCPGDPR€1,000
07 Dec 2023Hora Credit IFN SAThe authority fined Hora Credit IFN SA for sending documents containing another client's personal data to the complainant's email address. The incident indicates a breach of confidentiality and proper personal data processing requirements.ROANSPDCPGDPR€2,000
26 Nov 2021Valoris Center S.R.L.Valoris Center S.R.L. was fined by ANSPDCP EUR 2,000 for a personal data processing security breach. The incident was caused by a call center employee.ROANSPDCPGDPR€2,000
31 Jan 2026SC Tensa Art Design SAThe Romanian data protection authority fined SC Tensa Art Design SA, operator of the Lensa brand, EUR 20,000 under the GDPR. The sanction followed the company’s failure to respond to the authority’s investigative request concerning cookie tracking and behavioral advertising on its website.ROAutoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter PersonalGDPR€20,000
30 May 2024Corint Logistic SRLCorint Logistic SRL was fined EUR 1,000 by ANSPDCP for GDPR violations. The case concerned non-compliance with personal data protection requirements.ROANSPDCPGDPR€1,000
12 Apr 2024Centrul Medical dr. Furtună DanThe National Supervisory Authority for Personal Data Processing imposed a fine on Centrul Medical dr. Furtună Dan for breaching Article 6 of the GDPR. The infringement concerned the absence of a proper legal basis for personal data processing.ROANSPDCPGDPR€1,500
21 May 2025Data Diggers Market Research SRLData Diggers Market Research SRL was fined EUR 2,000 by ANSPDCP for another violation related to the processing of personal data. The case indicates non-compliance with data protection requirements and calls for a review of processing procedures.ROANSPDCPGDPR€2,000
20 Mar 2025ONE UNITED PROPERTIES S.AIn February 2025, ANSPDCP completed an investigation at ONE UNITED PROPERTIES S.A. The authority found GDPR violations and imposed a fine of 1,000 EUR.ROANSPDCPGDPR€1,000
20 Jan 2025Vodafone Romania S.A.Vodafone Romania S.A. was fined EUR 15,000 by ANSPDCP for violations of GDPR provisions. The case concerns non-compliance with personal data protection requirements.ROANSPDCPGDPR€15,000
01 Feb 2022SC Grupex 2000 SRLSC Grupex 2000 SRL was fined by ANSPDCP for unlawfully processing the personal data of institutionalized patients. The data appeared in filmed material available on the company's website.ROANSPDCPGDPR€1,000