Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
05 Jul 2023Anonymisé (CNPD decision-05-fr-2023)The company did not inform data subjects about the recipients of their personal data. It also failed to implement appropriate technical and organizational measures required under the GDPR, breaching Articles 13 and 24.LUCNPDGDPR€1,500
16 Dec 2025Anonymisé (CNPD decision-04-fr-2025)The company did not maintain a complete and accurate record of processing activities under Article 30 GDPR. CNPD treated this as a breach of documentation obligations and imposed an administrative fine.LUCNPDGDPR€2,784
16 Feb 2022Anonymisé (CNPD decision-04-fr-2022)The CNPD found that the companies failed to meet the Article 13 GDPR information obligation toward data subjects, including employees and third parties. The breach concerned the lack of proper notice about data processing activities.LUCNPDGDPR€3,100
30 Apr 2025Anonymisé (CNPD decision-03-fr-2025)The company did not maintain a complete record of processing activities as required by Article 30 GDPR. CNPD imposed an administrative fine of €11,964.LUCNPDGDPR€11,964
20 Nov 2024Anonymisé (CNPD decision-03-fr-2024)The company was fined for installing surveillance cameras without a legal basis. The authority found breaches of GDPR principles of lawfulness, transparency, and security.LUCNPDGDPR€14,288
02 Feb 2022Anonymisé (CNPD decision-02-fr-2022)The company was fined by the CNPD 6,600 EUR for breaches of GDPR requirements. The authority found deficiencies in data minimization, retention, security of processing, and the information provided to data subjects in connection with video surveillance and geolocation systems.LUCNPDGDPR€6,600
06 Jan 2025Anonymisé (CNPD decision-01-fr-2025)The entity failed to comply with the response time requirements for data subject requests, which constitutes a breach of Article 12 GDPR. CNPD imposed a fine of EUR 493,560.LUCNPDGDPR€493,000
02 Feb 2022Anonymisé (CNPD decision-01-fr-2022)The entity breached GDPR requirements on data minimization, retention limitation, and the duty to inform data subjects, including employees and third parties, about processing activities. CNPD imposed a fine of EUR 10,000.LUCNPDGDPR€10,000
13 Aug 2025Anonimizirano (IP-RS 0609-97/2024/2)A sole proprietor was fined for failing to respond to a request from the Information Commissioner within the specified 10-day period. The authority treated this as a breach of Article 31 GDPR.SIIP-RSGDPR€500
25 Jul 2025Anonimizirano (IP-RS 0609-34/2025/8)The legal entity did not establish a valid contract with a data processor. This breaches Article 28 GDPR, which requires processing by a processor to be governed by a contract.SIIP-RSGDPR€5,610
29 Jul 2025Anonimizirano (IP-RS 0609-18/2025/7)The legal entity was fined by IP-RS for unlawfully processing personal data by redirecting emails without a legal basis. The authority found a breach of the GDPR principle of lawfulness.SIIP-RSGDPR€10,614
01 Dec 2025Anonimizirano (IP-RS 0609-128/2025/6)A legal entity was fined by IP-RS for failing to implement appropriate technical and organizational measures to secure personal data processing. This failure led to unauthorized access to data stored on a company laptop.SIIP-RSGDPR€1,000
21 Nov 2025Anonimizirano (IP-RS 0609-114/2025/9)A legal entity was fined by IP-RS for failing to implement adequate organizational and technical measures to secure personal data processing on a publicly accessible web server. This led to unauthorized access to the personal data of 12 individuals.SIIP-RSGDPR€16,250
08 Dec 2025Anonimizirano (IP-RS 0609-112/2025/7)A legal entity was fined 4,800 EUR by IP-RS for failing to provide concise, transparent, and understandable information to individuals when collecting personal data through online forms. The authority found this to be a breach of Article 13 GDPR.SIIP-RSGDPR€4,800
26 Nov 2025Anonimizirano (IP-RS 0609-104/2025/18)The entity was fined EUR 6,000 for systematically and indiscriminately collecting employees’ location data through GPS devices in company vehicles without a legal basis. The authority found a breach of the lawfulness principle under Article 5 GDPR.SIIP-RSGDPR€6,000
22 Jul 2025Anonimizirano (IP-RS 0609-101/2024/5)A legal entity was fined by IP-RS for a GDPR breach involving the unauthorized disclosure of personal data, including hospital treatment details, via email. The case concerned processing that failed to meet confidentiality and access-control requirements.SIIP-RSGDPR€2,000
23 May 2022ANOIXISThe fine was imposed for sending unsolicited SMS messages for direct marketing without prior consent. The company also failed to provide a valid opt-out address, affecting data subjects’ rights of access and objection.GRHDPAePrivacy€54,000
27 May 2024Anna-Michelle AsimakopoulouAnna-Michelle Asimakopoulou was fined by the HDPA for sending unsolicited political communications by email to individuals who had registered their email addresses for official use with the Greek government. The case concerned the use of those addresses for political outreach, despite being collected for a different purpose.GRHDPAGDPR€5,000
17 Oct 2013Annamaria FazziniAnnamaria Fazzini was fined EUR 2,400 by the Garante for failing to provide the required privacy notice for a video surveillance system at her business. The case concerns non-compliance with the obligation to inform individuals about the processing of their personal data.ITGaranteGDPR€2,400
01 Jul 2020ANMAVAS 61, S.L. (LA CUEVA SEX CLUB)ANMAVAS 61, S.L. did not respond to a data subject’s request for erasure. The AEPD imposed a fine of EUR 2,000 for breaching GDPR obligations.ESAEPDGDPR€2,000