Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-24%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
03 Dec 2025FUNDACIÓN TRILEMAFUNDACIÓN TRILEMA was fined 3,000 EUR by the AEPD for publishing a minor’s image on social media without parental consent. The authority found this to be a breach of data protection rules.ESAEPDGDPR€3,000
04 Dec 2025DIARIO DE PRENSA DIGITAL, S.L.DIARIO DE PRENSA DIGITAL, S.L. was fined by the AEPD 5,000 EUR for placing tracking and advertising cookies on its website without prior user consent. The authority found this to be a breach of Article 22.2 of the LSSI.ESAEPDePrivacy€5,000
04 Dec 2025PARTI POLITIQUE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 5,000 on PARTI POLITIQUE under a simplified procedure and issued an injunction. The case concerns a breach of rules supervised by the CNIL.FRCNILGDPR€5,000
04 Dec 2025Istituto Comprensivo Centro di Casalecchio di RenoThe Garante fined Istituto Comprensivo Centro di Casalecchio di Reno EUR 2,000 for publishing personal data online without a proper legal basis. The authority found breaches of data minimization and transparency principles.ITGaranteGDPR€2,000
04 Dec 2025Comune di TuscaniaThe Garante fined Comune di Tuscania 12,000 EUR for failing to provide timely and complete responses to information requests. It also found breaches of lawfulness, fairness, and transparency, as well as inadequate data protection impact assessments for video surveillance.ITGaranteGDPR€12,000
04 Dec 2025Liceo scientifico e linguistico statale “Principe Umberto di Savoia”Liceo scientifico e linguistico statale “Principe Umberto di Savoia” was fined EUR 1,000 by the Garante for breaching the principles of lawfulness, fairness, and transparency in data processing. The authority also found that the school failed to provide adequate information to data subjects.ITGaranteGDPR€1,000
04 Dec 2025Istituto Comprensivo di Roverbella (Mantova)Istituto Comprensivo di Roverbella was fined EUR 1,000 by the Garante for breaches of data protection rules. The authority cited non-compliance with the principles of lawfulness, fairness, and transparency in data processing.ITGaranteGDPR€1,000
04 Dec 2025SOCIETE EXERCANT UNE ACTIVITE D'HOTELLERIE ET D'HEBERGEMENT (procédure simplifiée)The CNIL imposed an administrative fine of EUR 10,000 on SOCIETE EXERCANT UNE ACTIVITE D'HOTELLERIE ET D'HEBERGEMENT. The case was handled under a simplified procedure.FRCNILGDPR€10,000
05 Dec 2025XThe European Commission imposed a EUR 120 million fine on X for breaching transparency requirements under the Digital Services Act. The penalty covered deceptive verification design, an inadequate ad repository, and restricted access for researchers.EUEuropean CommissionDSA€120,000,000
08 Dec 2025SOCIETE EXERCANT UNE ACTIVITE DE COMMERCE DE DETAIL (procédure simplifiée)The CNIL imposed an administrative fine of EUR 20,000 on SOCIETE EXERCANT UNE ACTIVITE DE COMMERCE DE DETAIL. The case was handled under a simplified procedure.FRCNILGDPR€20,000
08 Dec 2025Dane anonimowe (S.)The UODO imposed an administrative fine of PLN 14,816 on Anonymous data (S.). The penalty was issued for failing to provide access to all personal data and information necessary for the President of the UODO to perform his duties.PLUODOGDPR€3,502
08 Dec 2025Compania de Apă Oltenia S.A.The company was fined EUR 1,000 by ANSPDCP after an employee disclosed personal data on a social network. The case was initiated following a complaint from the data subject.ROANSPDCPGDPR€1,000
08 Dec 2025Anonimizirano (IP-RS 0609-112/2025/7)A legal entity was fined 4,800 EUR by IP-RS for failing to provide concise, transparent, and understandable information to individuals when collecting personal data through online forms. The authority found this to be a breach of Article 13 GDPR.SIIP-RSGDPR€4,800
10 Dec 2025Crowd Entertainment LimitedThe National Supervisory Authority for Personal Data Processing completed an investigation in November 2025 at Crowd Entertainment Limited and found violations of GDPR provisions. As a result, an administrative fine of EUR 15,000 was imposed.ROANSPDCPGDPR€15,000
10 Dec 2025University of LimerickThe Irish DPC fined University of Limerick 98,000 EUR in inquiry IN-19-7-1. The record notes the status as not confirmed.IEDPCGDPR€98,000
11 Dec 2025CANDIDAT AUX ELECTIONS LEGISLATIVES DE 2024 (procédure simplifiée)The CNIL imposed an administrative fine of EUR 5,500 on CANDIDAT AUX ELECTIONS LEGISLATIVES DE 2024. The case was handled under a simplified procedure.FRCNILGDPR€5,500
11 Dec 2025ETABLISSEMENT PUBLIC EXERCANT UNE ACTIVITE DE GESTION LOCATIVE DE LOGEMENTS (procédure simplifiée)The CNIL imposed an administrative fine of EUR 20,000 on ETABLISSEMENT PUBLIC EXERCANT UNE ACTIVITE DE GESTION LOCATIVE DE LOGEMENTS and issued an injunction. The case concerns a regulatory breach in the area of data protection.FRCNILGDPR€20,000
11 Dec 2025SOCIETE DE COURTAGE EN TRAVAUX, CONSULTING EN BATIMENT ET TRAVAUX PUBLICS, ACHAT ET REVENTE DE MATERIEL, TRANSACTION IMMOBILIERE ET MAITRISE D'ŒUVRE (procédure simplifiée)The CNIL imposed a liquidation of astreinte in the amount of EUR 3,000 on the company. The decision relates to failure to comply with a prior obligation arising from supervisory proceedings.FRCNILGDPR€3,000
11 Dec 2025Mobius Solutions LtdThe French CNIL imposed a 1 million EUR fine on Mobius Solutions Ltd for personal data processing violations. The case involved unlawful retention and reuse of data from more than 46 million users after the contract ended, as well as failure to maintain a processing activities register.FRCNILGDPR€1,000,000
11 Dec 2025CANDIDAT AUX ELECTIONS LEGISLATIVES DE 2024 (procédure simplifiée)CNIL imposed an administrative fine of EUR 5,000 on CANDIDAT AUX ELECTIONS LEGISLATIVES DE 2024. The case was handled under a simplified procedure.FRCNILGDPR€5,000