Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-24%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
23 Oct 2025Dane anonimowe (Komornika Sądowego przy Sądzie Rejonowym w S. B. F. Kancelaria)The President of UODO imposed an administrative fine on the bailiff’s office for failing to report a personal data breach within the required 72 hours. The authority also found that the affected individual was not notified without undue delay after the data was disclosed to an unauthorized recipient.PLUODOGDPR€1,819
23 Oct 2025Emera SrlEmera Srl was fined by the Garante EUR 6,000 for sending unsolicited promotional SMS messages despite the recipient's repeated requests for data deletion. The authority also found inadequate data retention and organizational procedures to ensure respect for data subject rights.ITGaranteGDPR€6,000
23 Oct 2025Provvedimento del 23 ottobre 2025 [10210718]The Garante imposed a EUR 10,000 fine on an individual tobacco shop owner for suspicious financial transactions involving the misuse of a third party’s identification data with a prepaid card. The case concerns unauthorized use of personal data in the context of payment operations.ITGaranteGDPR€10,000
25 Oct 2025MAR DEGUSTACIÓN, S.LMAR DEGUSTACIÓN, S.L was fined by the AEPD 1,000 EUR for installing a video surveillance system without proper consent and for failing to inform affected individuals. The authority cited breaches of GDPR Articles 5(1)(c) and 13.ESAEPDGDPR€1,000
25 Oct 2025TELECONTACT LIST S.L.TELECONTACT LIST S.L. was fined 1,000 EUR by the AEPD for failing to respond to a data subject’s request for access to and deletion of personal data. The authority found a breach of Article 15 of the GDPR.ESAEPDGDPR€1,000
27 Oct 2025Anonymisiert (DSB 2025-0.811.087)The controller unlawfully processed personal data through video surveillance, including public sidewalk areas, contrary to data minimization principles. Images were also published online without a legal basis.ATDSBGDPR€1,500
28 Oct 2025Aktia PankkiThe sanction panel of the Finnish Data Protection Ombudsman’s Office imposed an EUR 865,000 fine on Aktia Pankki for deficiencies in information security in its strong electronic identification service. The incident caused some users to see other customers’ data in services requiring strong authentication.FITietosuojavaltuutetun toimistoGDPR€865,000
28 Oct 2025SIA ZZ DatsThe Latvian Data State Inspectorate found that SIA ZZ Dats failed to meet GDPR Article 32 requirements for appropriate technical and organizational measures. The case involved a major personal data leak affecting nearly all Latvian municipalities, and the authority imposed an administrative fine of EUR 300,000. The company has appealed the decision.LVDatu valsts inspekcijaGDPR€300,000
01 Nov 2025LastPass UK LtdIn November 2025, the Information Commissioner’s Office imposed a monetary penalty of about £1.2 million on LastPass UK Ltd. The sanction concerned security and governance failures that led to a breach affecting around 1.6 million UK users, despite the use of strong encryption.GBInformation Commissioner's OfficeGDPR€1,361,000
01 Nov 2025Właścicielka lecznicy stomatologicznejThe owner of a dental clinic was fined 85,588 PLN by UODO for failing to notify affected patients in time after a personal data breach. The WSA and then the NSA upheld the penalty, finding that the required notices were sent too late.PLPresident of the Personal Data Protection Office (UODO)GDPR€20,110
03 Nov 2025Fiziskas personaA fine of EUR 250 was imposed by DVI. The decision has entered into force.LVDVIGDPR€250
04 Nov 2025COLLECTIVITE TERRITORIALE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 4,000 on COLLECTIVITE TERRITORIALE under a simplified procedure. The decision concerns a breach of data protection rules.FRCNILGDPR€4,000
04 Nov 2025THERE’S AN AI FOR THAT S.R.LTHERE’S AN AI FOR THAT S.R.L. was fined 30,000 RON by ANSPDCP. The sanction concerns a breach of the national ePrivacy law.ROANSPDCPePrivacy€5,898
04 Nov 2025Fiziska personaA fine of EUR 150 was imposed by the DVI on an individual in Latvia. The decision is final and has entered into force.LVDVIGDPR€150
04 Nov 2025SOCIETE EXERCANT UNE ACTIVITE DE CONSEIL ET AIDE A LA GESTION AUPRES DE CLUBS DE SPORTS SUBAQUATIQUES (procédure simplifiée)CNIL imposed an administrative fine of 4,000 EUR on SOCIETE EXERCANT UNE ACTIVITE DE CONSEIL ET AIDE A LA GESTION AUPRES DE CLUBS DE SPORTS SUBAQUATIQUES under a simplified procedure. The decision concerns a regulatory breach handled in administrative proceedings.FRCNILGDPR€4,000
04 Nov 2025McDonald'sThe Polish Data Protection Authority imposed a EUR 4,022,773 fine on McDonald's for insufficient security measures in personal data processing. A separate EUR 43,680 fine was also issued to the service provider involved in the same incident.PLPolish Data Protection AuthorityGDPR€4,022,000
05 Nov 2025COFIDIS S.A., SUCURSAL EN ESPAÑACOFIDIS S.A., Sucursal en España was fined €5,000 by the AEPD for mixing a complainant’s personal data with unrelated information and sending a third party’s debt statement. The case concerns a breach of the data accuracy principle.ESAEPDGDPR€5,000
05 Nov 2025RAMÓN GRAU, S.L.RAMÓN GRAU, S.L. was fined by the AEPD for installing a video surveillance system that recorded audio without informing employees. The authority found breaches of GDPR Articles 6(1) and 13 due to the lack of a valid legal basis and required transparency information.ESAEPDGDPR€30,000
05 Nov 2025CABINET D'AVOCATS (procédure simplifiée)The CNIL imposed an administrative fine of EUR 5,000 on CABINET D'AVOCATS (procédure simplifiée). The case was handled under a simplified administrative procedure by the French data protection authority.FRCNILGDPR€5,000
06 Nov 2025Lead Pronto LtdLead Pronto Ltd received an MPN and an EN from the ICO for sending unsolicited SMS messages promoting Government funded boiler grants. The case indicates a breach of direct marketing rules and consent requirements.GBICOGDPR€34,065