Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-24%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
14 Jan 2026ZalandoUOKiK imposed a fine on Zalando for misleading consumers by improperly presenting promotional prices and hiding the required lowest price from the previous 30 days. According to the report, the combined sanctions against Zalando and Temu were about PLN 37 million, with Zalando accounting for PLN 31,488,674.PLUrząd Ochrony Konkurencji i KonsumentówOther€7,465,000
15 Jan 2026Allay Claims Ltd The ICO issued an MPN and EN to Allay Claims Ltd after a large volume of unsolicited SMS messages promoting PPI tax refund services. The case indicates a breach of direct marketing and electronic communications rules.GBICOGDPR€138,000
15 Jan 2026CANDIDATS AUX ÉLECTIONS LÉGISLATIVES (procédure simplifiée)CNIL imposed an administrative fine of 2,000 EUR on CANDIDATS AUX ÉLECTIONS LÉGISLATIVES (procédure simplifiée) and issued an injunction. The case concerns a breach of rules supervised by CNIL.FRCNILGDPR€2,000
16 Jan 2026BAR GIOIA di XXThe Garante imposed a fine of EUR 600 on BAR GIOIA for the non-compliant installation of a video surveillance system. The case concerned breaches of data protection rules and the requirements for lawful processing.ITGaranteGDPR€600
16 Jan 2026Provvedimento del 16 gennaio 2026 [10213836]The Garante imposed a fine of EUR 500 on an anonymized data controller for a minor breach of data protection rules in the health sector. The authority also ordered publication of the decision on its website.ITGaranteGDPR€500
16 Jan 2026Liceo Classico e Scientifico Alessandro VoltaLiceo Classico e Scientifico Alessandro Volta was fined 2,000 EUR by the Garante for publishing personal data on its institutional website without a proper legal basis. The authority found breaches of lawfulness, fairness, and transparency principles.ITGaranteGDPR€2,000
16 Jan 2026Born S.r.l.Born S.r.l. was fined by the Garante 15,000 EUR for making unsolicited promotional calls to numbers listed in the Public Register of Oppositions. The conduct breached data protection rules governing telephone marketing and the right to object.ITGaranteGDPR€15,000
16 Jan 2026Macelleria La Costata s.r.l.s.The Garante fined Macelleria La Costata s.r.l.s. EUR 1,500 for the non-compliant installation of a video surveillance system. The authority found a breach of GDPR Article 5, which sets out the core principles for personal data processing.ITGaranteGDPR€1,500
16 Jan 2026Associazione Turistica Pro Loco di CittarealeThe association unlawfully disclosed the personal data of 23 members by publishing it in a public notice and online. The authority found breaches of lawfulness, fairness, transparency, and data minimization.ITGaranteGDPR€600
16 Jan 2026Azienda Ospedaliera S. Pio di BeneventoAzienda Ospedaliera S. Pio di Benevento was fined by the Garante EUR 6,000 for violations related to the processing of personal data. The case concerned special categories of data and disclosure to third parties.ITGaranteGDPR€6,000
16 Jan 2026Πυροσβεστικό ΣώμαThe Hellenic Data Protection Authority imposed a €10,000 fine on the Fire Service for unlawfully processing an employee’s special-category health data. The authority found breaches of GDPR lawfulness and data minimization principles and noted that the data were accessible through an internal electronic application.GRΑρχή Προστασίας Δεδομένων Προσωπικού ΧαρακτήραGDPR€10,000
20 Jan 2026Timegrip ASTimegrip AS was fined 250,000 NOK for failing to provide employees access to their own timekeeping data after the bankruptcy of a retail chain. The authority treated the company as the data controller and found a breach of the GDPR right of access.NODatatilsynetGDPR€21,340
22 Jan 2026ÉTABLISSEMENT PUBLIC ADMINISTRATIFCNIL imposed an administrative fine of EUR 5,000,000 on ÉTABLISSEMENT PUBLIC ADMINISTRATIF and issued an injunction. The case concerns a confirmed breach of rules supervised by CNIL.FRCNILGDPR€5,000,000
24 Jan 2026IBERANUNCIOS SLIBERANUNCIOS SL was fined by the AEPD EUR 15,000 for a data protection breach. The incident allowed unauthorized access to personal data, breaching the confidentiality principle under GDPR.ESAEPDGDPR€15,000
24 Jan 2026CENTRO MÉDICO REY FERNANDO, S.L.P.The entity charged a fee for providing a patient with their medical history, which breached the right of access under GDPR Article 12. The AEPD imposed a fine of 1,000 EUR.ESAEPDGDPR€1,000
26 Jan 2026SportAdmin i Skandinavien ABSportAdmin i Skandinavien AB was fined by IMY 6,000,000 SEK for failing to implement appropriate technical and organizational measures to ensure an adequate level of security for personal data. The deficiency resulted in a data breach.SEIMYGDPR€564,000
29 Jan 2026Università Telematica e-CampusThe Garante fined Università Telematica e-Campus EUR 50,000 for violations related to biometric data processing. The authority also found that the university failed to carry out a proper Data Protection Impact Assessment (DPIA).ITGaranteGDPR€50,000
29 Jan 2026Ministero della CulturaMinistero della Cultura was fined EUR 12,000 by the Garante for using surveillance footage for disciplinary purposes without ensuring proper transparency toward visitors and employees. The authority found breaches of the GDPR and national data protection rules.ITGaranteGDPR€12,000
29 Jan 2026dott. Paolo MontemurroDott. Paolo Montemurro was fined 5,000 EUR by the Garante for posting photographs of a patient's surgical procedure on Instagram without consent. The authority found this breached GDPR principles of lawfulness, fairness, and transparency.ITGaranteGDPR€5,000
29 Jan 2026ASSOCIATION RELIGIEUSE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 10,000 on ASSOCIATION RELIGIEUSE (procédure simplifiée) and issued an injunction. The case concerned a confirmed breach of rules supervised by the CNIL.FRCNILGDPR€10,000