Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
20 Jun 2024Fastweb S.p.A.Fastweb S.p.A. was fined by the Garante EUR 1,000,000 for carrying out telemarketing activities without obtaining proper consent from the contacted individuals. The authority found a breach of fairness and transparency principles in the processing of personal data.ITGaranteGDPR€1,000,000
12 Jan 2023ORANGEORANGE was fined EUR 1,000,000 by the AEPD for breaching data protection principles. The authority found failures to implement privacy by design and privacy by default in connection with SIM swapping incidents.ESAEPDGDPR€1,000,000
30 Sept 2020Követeléskezelő cég által végzett adatkezelés jogszerűségeThe authority imposed a fine for violating the data subject’s right to erasure because outdated address data was not deleted. It also found that personal data was processed without a proper legal basis.HUNAIHGDPR€2,740
23 Sept 2021TELEFÓNICA MÓVILES ESPAÑA, S.A.U.TELEFÓNICA MÓVILES ESPAÑA, S.A.U. was fined by the AEPD EUR 1,000,000 for failing to adequately prevent unauthorized SIM card duplication. The breach enabled access to confidential information and caused financial losses for customers.ESAEPDGDPR€1,000,000
26 Jun 2019Törléshez való jog megsértése, jogalap nélküli adatkezelés, célhoz kötöttség és adattakarékosság elvének megsértéseThe controller did not comply with the data subject’s request to delete personal data, including phone numbers. The authority found unlawful processing and a breach of the principles of purpose limitation and data minimization.HUNAIHGDPR€3,090
09 Jul 2020Második ítélet a NAIH/2020/974 sz. ügyben (Fővárosi Törvényszék 105.K.701.565/2022/2)The controller collected personal data for contact purposes without a lawful basis and did not provide adequate information about the processing. The conduct breached multiple GDPR provisions, and the authority imposed a fine of HUF 1,000,000.HUNAIHGDPR€2,820
09 Jul 2020Ítélet a NAIH/2020/974 sz. ügyben (Kúria Kfv. II.37.001/2021/6)The controller processed personal data without a legal basis for a political campaign. It also failed to provide adequate information about the processing, resulting in breaches of several GDPR provisions.HUNAIHGDPR€2,820
24 Aug 2023Kamerás adatkezelés szálláshelyenThe entity was fined for failing to provide easily accessible and transparent information about data processing through a camera system. The authority found a breach of GDPR Articles 12 and 13.HUNAIHGDPR€2,600
03 Feb 2025IBERMUTUA, MUTUA COLABORADORA CON LA SEGURIDAD SOCIAL NUM.274IBERMUTUA was fined EUR 1,000,000 by the AEPD for a data breach. Due to a computer error, personal data, including health information, was mistakenly sent to various companies.ESAEPDGDPR€1,000,000
30 Jan 2024Könnycsepp Nélkül a Beteg Gyermekekért AlapítványThe NAIH imposed a 1,000,000 HUF fine on the foundation for GDPR breaches related to personal data processing during phone calls. The authority found that data subjects were not adequately informed and that the processing lacked a valid legal basis.HUNAIHGDPR€2,580
11 Dec 2025Mobius Solutions LtdThe French CNIL imposed a 1 million EUR fine on Mobius Solutions Ltd for personal data processing violations. The case involved unlawful retention and reuse of data from more than 46 million users after the contract ended, as well as failure to maintain a processing activities register.FRCNILGDPR€1,000,000
18 Dec 2013Google Inc.Google Inc. was fined EUR 1 million by the Italian Data Protection Authority, Garante. The authority found that individuals were not adequately informed during data collection by Google cars for the Street View service.ITGaranteGDPR€1,000,000
07 Jul 2023Személyes adatok forrása és adatgyűjtés távhőszolgáltatás nyújtásáhozThe supervisory authority found a GDPR breach because the controller did not inform data subjects about the source of their personal data. It also failed to demonstrate accountability and compliance with data protection principles.HUNAIHGDPR€2,580
31 Jul 2024Hangrögzítés telefonos ügyfélszolgálatonThe authority imposed a fine for breaching the GDPR principles of transparency and accountability. The entity did not adequately inform callers that customer service phone calls were being recorded.HUNAIHGDPR€2,530
22 Jun 2023Autostrade per l’Italia S.p.A.Autostrade per l’Italia S.p.A. was fined by the Garante EUR 1,000,000 for violations linked to an application that processed users’ personal data. The app was used to handle refunds of highway ticket costs for delays caused by construction works.ITGaranteGDPR€1,000,000
09 Jul 2020dr. Hadházy Ákos ÁnyosThe controller processed personal data without a legal basis and did not provide adequate information about the processing linked to a petition concerning accession to the European Public Prosecutor's Office. The case indicates breaches of core transparency and lawfulness obligations.HUNAIHGDPR€2,820
22 Jun 2022Gyldendal A/SGyldendal A/S was fined 1,000,000 DKK by Datatilsynet for retaining data of 685,000 book club members longer than necessary. The authority found a breach of data retention principles.DKDatatilsynetGDPR€134,000
04 Jan 2021Innovasjon NorgeThe Norwegian DPA notified Innovasjon Norge of a planned NOK 1,000,000 fine for conducting four credit assessments of an individual and his sole proprietorship without a legal basis. The case indicates a breach of the lawfulness principle for personal data processing.NODatatilsynetGDPR€95,750
15 Oct 2019Munkavállaló munkaeszközeinek ellenőrzéseThe controller unlawfully processed the complainant's personal data by reviewing and monitoring their email account without prior notice. This breached the principle of fair processing.HUNAIHGDPR€3,010
28 Feb 2019Kecskemét Megyei Jogú Város Polgármesteri HivatalaKecskemét City Hall transferred personal data from a public interest report to a third party without a legal basis, resulting in unauthorized access. NAIH imposed a fine of 1,000,000 HUF.HUNAIHGDPR€3,160