Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-24%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
29 Dec 2025SOCIETE EDITANT UNE APPLICATION MOBILECNIL imposed an administrative fine of EUR 270,000 on SOCIETE EDITANT UNE APPLICATION MOBILE. The case concerns a breach of personal data protection rules and should be considered in compliance assessments.FRCNILGDPR€270,000
29 Dec 2025SOCIETE EXERCANT UNE ACTIVITE D'EDITION DE JOURNAUX (procédure simplifiée)The CNIL imposed an administrative fine of EUR 7,000 on SOCIETE EXERCANT UNE ACTIVITE D'EDITION DE JOURNAUX and issued an injunction. The case concerns a breach of rules supervised by the CNIL.FRCNILGDPR€7,000
30 Dec 2025SOCIETE DU SECTEUR TERTIAIREThe CNIL imposed an administrative fine of EUR 3,500,000 on SOCIETE DU SECTEUR TERTIAIRE. The case concerns a breach of personal data protection rules.FRCNILGDPR€3,500,000
30 Dec 2025SOCIETE EXERCANT UNE ACTIVITE DE FRET AEROPORTUAIRE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 10,000 on SOCIETE EXERCANT UNE ACTIVITE DE FRET AEROPORTUAIRE. The case was handled under a simplified procedure.FRCNILGDPR€10,000
30 Dec 2025Roumasport S.R.LRoumasport S.R.L was fined EUR 10,000 by ANSPDCP for violating GDPR provisions. The case concerns non-compliant processing of personal data.ROANSPDCPGDPR€10,000
30 Dec 2025SOCIETE AYANT POUR ACTIVITE L'ACQUISITION ET LA GESTION D'HOTELS/RESIDENCES HOTELIERES (procédure simplifiée)The CNIL imposed an administrative fine of 5,000 EUR on the company engaged in the acquisition and management of hotels and hotel residences. The case was handled under a simplified procedure.FRCNILGDPR€5,000
31 Dec 2025UNIVERSITE (procédure simplifiée)CNIL imposed an administrative fine of EUR 20,000 on UNIVERSITE (procédure simplifiée). The case concerned a confirmed breach of rules supervised by CNIL.FRCNILGDPR€20,000
01 Jan 2026Telekommunikationsunternehmen aus NRWThe Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen imposed a total fine of EUR 300,000 on a telecommunications company from North Rhine-Westphalia. The authority found breaches of transparency obligations and data subject rights, including requests for access, deletion, and objection.DELandesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-WestfalenGDPR€300,000
01 Jan 2026CloudflareAGCOM issued an ordinanza ingiunzione against Cloudflare under the Digital Services Act. The fine is 100,000 EUR and relates to a breach of DSA obligations.ITAGCOMDSA€100,000
02 Jan 2026Dane anonimowe (Spółkę)UODO imposed an administrative fine of PLN 978,128 on the company. The authority found that the controller did not ensure the independence of the Data Protection Officer and failed to prevent a conflict of interest arising from the DPO’s other tasks and duties.PLUODOGDPR€232,000
08 Jan 2026OPÉRATEUR DE TÉLÉPHONIE MOBILECNIL imposed an administrative fine of EUR 27 million on OPÉRATEUR DE TÉLÉPHONIE MOBILE and issued an injunction. The case concerns a regulatory breach addressed by the authority’s decision.FRCNILGDPR€27,000,000
08 Jan 2026Amendă pentru încălcarea Legii nr. 506/2004 și a RGPDA fine of EUR 2,000 was imposed for violations of certain provisions of Law No. 506/2004 and the GDPR. The case concerns non-compliant personal data processing and privacy protection obligations.ROANSPDCPGDPR€2,000
08 Jan 2026OPÉRATEUR DE TÉLÉPHONIE FIXECNIL imposed an administrative fine of EUR 15 million on a fixed-line telecom operator and issued an injunction. The case concerns a breach requiring corrective action and compliance with regulatory obligations.FRCNILGDPR€15,000,000
08 Jan 2026MEDIOS DE PREVENCIÓN EXTERNOS SUR, S.L.The company suffered a ransomware attack that caused a breach of the confidentiality and availability of personal data. AEPD found a violation of Article 5(1)(f) GDPR.ESAEPDGDPR€60,000
10 Jan 2026NAROBESA INV, S.L.NAROBESA INV, S.L. was fined 1,000 EUR by the AEPD for unlawfully accessing a job applicant's credit information without consent during recruitment. The conduct breached data protection rules and occurred in the hiring process.ESAEPDGDPR€1,000
10 Jan 2026DÉCIMAS, S.L.DÉCIMAS, S.L. was fined by the AEPD in the amount of EUR 200,000 for a personal data breach. The incident exposed personal data and breached GDPR Article 5(1)(f).ESAEPDGDPR€200,000
10 Jan 2026MULTISPORTS GALICIA, S.L.MULTISPORTS GALICIA, S.L. was fined by the AEPD EUR 6,000 for failing to implement appropriate technical and organizational measures proportionate to the risk. The weakness allowed easy access to personal data of race participants through its website.ESAEPDGDPR€6,000
12 Jan 2026Zalando SEThe President of UOKiK imposed a fine of PLN 30,945,000 on Zalando SE for failing to provide the lowest price from the 30 days before a discount and for misleading discount presentation. The decision concerns consumer protection and is not yet final.PLUOKiKOmnibus€7,351,000
13 Jan 2026Free Mobile and FreeFrance’s CNIL fined Free Mobile and Free a combined EUR 42 million for GDPR breaches linked to a 2024 data breach affecting more than 24 million users. The regulator found inadequate security measures and said Free Mobile unlawfully retained former subscribers’ data.FRCommission nationale de l’informatique et des libertésGDPR€42,000,000
13 Jan 2026PREMIER RESTAURANTS ROMANIA SRLThe National Supervisory Authority for Personal Data Processing imposed a fine on PREMIER RESTAURANTS ROMANIA SRL for GDPR violations. The case concerned non-compliance with personal data protection requirements.ROANSPDCPGDPR€8,000