Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
06 Jun 2024FCA Bank S.p.A.FCA Bank S.p.A. was fined EUR 1,000,000 by the Italian supervisory authority Garante for data protection violations. The case concerned the use of blacklists in car rental services, raising compliance concerns about personal data processing.ITGaranteGDPR€1,000,000
07 Apr 2021Jogellenes adatkezelés, adattakarékosság és megfelelő tájékoztatási kötelezettség megsértéseThe authority found that the controller unlawfully processed personal data related to debt collection. It held that the principles of data minimization and transparency were breached, together with the duty to provide proper information to data subjects.HUNAIHGDPR€2,780
09 Jul 2020Ítélet a NAIH/2020/974 sz. ügyben (Alkotmánybíróság 3110/2022. (III. 23.) AB határozata)The controller processed personal data for contact purposes without a lawful basis and did not provide adequate information about the processing. The authority imposed a fine of HUF 1,000,000 for breaches of GDPR principles.HUNAIHGDPR€2,820
08 Mar 2022Harpa tónlistar- og ráðstefnuhús ohf.Harpa tónlistar- og ráðstefnuhús ohf. was fined by Persónuvernd for collecting personal identification numbers and birth dates without necessity. The authority found breaches of GDPR principles of lawfulness, fairness, transparency, and data minimization.ISPersónuverndGDPR€6,850
29 Jul 2024IBERINFORMIBERINFORM was fined by the AEPD €1,000,000 for processing personal data of self-employed individuals without a proper legal basis. The authority also found that the data were used beyond professional relationships, including for marketing and online exposure.ESAEPDGDPR€1,000,000
14 Jun 2019Facebook Ireland Ltd e Facebook Italy s.r.l.Facebook Ireland Ltd and Facebook Italy s.r.l. were fined EUR 1,000,000 by the Garante for violations involving the unauthorized sharing of user data with the application “Thisisyourdigitallife”. The case affected approximately 214,020 users.ITGaranteGDPR€1,000,000
24 Nov 2022Areti S.p.A.Areti S.p.A. was fined EUR 1,000,000 by the Garante for incorrectly labeling a customer as a “defaulting client” based on inaccurate and outdated data. The issue may have affected up to 16,743 other individuals, indicating a broader data processing failure.ITGaranteGDPR€1,000,000
04 Sept 2025Követeléskezeléssel összefüggő jogalap nélküli adatkezelés, tiltakozási joggal kapcsolatos kérelem nem teljesítése és elszámoltathatóság elvének sérelmeThe supervisory authority fined the controller for unlawfully processing the complainant’s phone number in connection with debt collection. It found breaches of lawfulness, data minimization, accountability, and failure to properly handle the data subject’s objection.HUNAIHGDPR€2,540
29 Apr 2026IBERDROLA CLIENTES, S.A.U.IBERDROLA CLIENTES, S.A.U. was fined EUR 1,000,000 by the AEPD for failing to implement adequate technical and organizational security measures. The authority found that the company did not properly verify customer identity, which constitutes a breach of Article 32 GDPR.ESAEPDGDPR€1,000,000
03 Jun 2019Engedély nélkül végzett követelésvásárlási tevékenységgel összefüggő adatkezelésThe authority found that the controller processed personal data without a valid legal basis and for unlawful purposes in connection with unauthorized debt purchasing activities. A fine of HUF 1,000,000 was imposed.HUNAIHGDPR€3,090
26 Jun 2019Banki adatkezelés és érintetti joggyakorlásThe controller was fined for processing personal data without a legal basis and for failing to provide adequate information about the right to object. The authority found breaches of core transparency and lawfulness obligations.HUNAIHGDPR€3,090
11 Dec 2025SOCIETE AYANT POUR ACTIVITE LE DEVELOPPEMENT D'OUTILS MARKETINGCNIL imposed an administrative fine of 1,000,000 EUR on SOCIETE AYANT POUR ACTIVITE LE DEVELOPPEMENT D'OUTILS MARKETING. The case concerns a confirmed breach of rules under CNIL supervision.FRCNILGDPR€1,000,000
22 Apr 2021Magyar ÁllamkincstárThe Hungarian National Authority for Data Protection and Freedom of Information (NAIH) fined Magyar Államkincstár HUF 1,000,000. The authority found a breach of GDPR lawfulness and data minimization principles because personal data were transferred without a proper legal basis.HUNAIHGDPR€2,750
24 Jul 2025CURENERGÍACURENERGÍA was fined by the AEPD EUR 1,000,000 for a data protection breach involving improper handling of personal data due to human error. The issue was corrected after notification.ESAEPDGDPR€1,000,000
09 Jul 2020Ítélet a NAIH/2020/974 sz. ügyben (Kúria végzése Kpk.III.39.352/2022/3)The controller processed personal data without a legal basis and did not provide adequate information about the processing. The authority found violations of several GDPR provisions and imposed a fine.HUNAIHGDPR€2,820
20 Apr 2021Elszámoltathatóság elvének megsértéseThe entity was fined by the NAIH for breaching the accountability principle and failing to implement appropriate technical and organizational measures to ensure GDPR compliance. The violations concerned data processing activities related to its websites.HUNAIHGDPR€2,770
27 Feb 2023Adatkezelési tájékoztatás átláthatóságaThe entity did not provide data subjects with transparent and accurate information about the purposes and legal bases of processing. This breached GDPR Articles 6, 12, and 13, and the authority imposed a fine of HUF 1,000,000.HUNAIHGDPR€2,630
07 Apr 2022Törlési jog a Központi Hitelinformációs Rendszerben tárolt mulasztási adatokkal összefüggésbenThe controller was fined for unlawful data processing and for failing to properly handle a data subject request. The authority found breaches of GDPR Articles 6, 12, and 17 in connection with default data stored in the Central Credit Information System.HUNAIHGDPR€2,640
26 Mar 2020Ügyfélszám téves rögzítésével összefüggő jogellenes adatkezelés és célhoz kötöttség elvének megsértéseThe controller unlawfully processed personal data related to a loan agreement, breaching the GDPR purpose limitation principle. NAIH imposed a fine of HUF 1,000,000.HUNAIHGDPR€2,820
20 Jan 2023Egészségi állapotra vonatkozó dokumentumok kiadásának megtagadásaThe controller did not comply with the data subject's access request and failed to provide adequate information about data processing. The conduct breached several GDPR provisions, and the authority imposed a fine of HUF 1,000,000.HUNAIHGDPR€2,530