Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-24%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
29 Jan 2026ÉTABLISSEMENT PUBLIC EXERÇANT UNE ACTIVITÉ DE TRANSPORT URBAIN (procédure simplifiée)The CNIL imposed an administrative fine of EUR 20,000 on ÉTABLISSEMENT PUBLIC EXERÇANT UNE ACTIVITÉ DE TRANSPORT URBAIN. The case was handled under a simplified procedure.FRCNILGDPR€20,000
29 Jan 2026Istituto tecnico industriale statale “Stanislao Cannizzaro” di CataniaIstituto tecnico industriale statale “Stanislao Cannizzaro” di Catania was fined by the Garante €10,000 for breaches of data protection principles. The authority found that personal data were processed in a manner that was not lawful, fair, or transparent.ITGaranteGDPR€10,000
29 Jan 2026Provincia della Congregazione dei Fratelli delle Suore CristianeThe entity was fined for failing to ensure sufficient transparency in data processing and for not carrying out a data protection impact assessment for workplace surveillance systems. The authority found breaches of the GDPR and the national privacy code.ITGaranteGDPR€12,000
30 Jan 2026un operator persoană fizicăAn individual operator was fined 3,000 EUR for GDPR violations. The case concerned non-compliant processing of personal data and was handled by ANSPDCP.ROANSPDCPGDPR€3,000
30 Jan 2026un operator persoană fizicăAn individual operator was fined 1,000 EUR by ANSPDCP for GDPR violations. The case concerned non-compliance with personal data protection requirements.ROANSPDCPGDPR€1,000
30 Jan 2026un operator persoană fizicăA 1,000 EUR fine was imposed on an individual operator for GDPR violations. The case concerned non-compliance with personal data protection requirements.ROANSPDCPGDPR€1,000
30 Jan 2026Magyar Agrár- és Élettudományi EgyetemThe Hungarian University of Agriculture and Life Sciences was fined by the NAIH for negligent GDPR violations in its dormitory admissions data processing. The authority cited a lack of proper legal basis, insufficient prior information, and failure to apply data minimization.HUNAIHGDPR€3,945
30 Jan 2026deținătorul site-ului evita-teparii.roANSPDCP imposed total fines of 51,000 lei, about 10,000 euro, on the operator, a natural person who runs the site evita-teparii.ro. The case involved multiple GDPR breaches, including the unlawful publication of identity, contact, sensitive, and alleged criminal data without a legal basis.ROANSPDCPGDPR€10,007
30 Jan 2026un operator persoană fizicăA fine of 5,000 EUR was imposed on an individual controller by ANSPDCP for GDPR violations. The case concerned non-compliance with personal data protection requirements.ROANSPDCPGDPR€5,000
31 Jan 2026SC Tensa Art Design SAThe Romanian data protection authority fined SC Tensa Art Design SA, operator of the Lensa brand, EUR 20,000 under the GDPR. The sanction followed the company’s failure to respond to the authority’s investigative request concerning cookie tracking and behavioral advertising on its website.ROAutoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter PersonalGDPR€20,000
01 Feb 2026Biržų ligoninėVDAI imposed a EUR 6,000 fine on Biržų ligoninė for improper processing of personal data. The case concerns a breach of data protection requirements and indicates non-compliance with GDPR obligations.LTVDAIGDPR€6,000
03 Feb 2026Partidul Alianța pentru Unirea Românilor (AUR)The National Supervisory Authority for Personal Data Processing imposed a fine on the political party AUR for GDPR violations. The case concerned non-compliance with personal data protection requirements.ROANSPDCPGDPR€1,000
03 Feb 2026TMAC LtdTMAC Ltd was fined GBP 100,000 by the ICO and served with an enforcement notice for breaches of regulations 21 and 24 of PECR. Between 8 February 2024 and 24 September 2024, the company made 260,332 unsolicited direct marketing calls to numbers listed on the Commissioner’s register. It also failed to provide the required information to call recipients.GBICOePrivacy€115,000
04 Feb 2026GENPACT ROMANIA SRLThe National Supervisory Authority for Personal Data Processing completed an investigation into GENPACT ROMANIA SRL and found a GDPR violation. The company was fined EUR 10,000 due to the severity of the circumstances.ROANSPDCPGDPR€10,000
04 Feb 2026E-RETAIL ADVERTISING, S.L.E-RETAIL ADVERTISING, S.L. was fined by the AEPD in the amount of 5,000 EUR for installing non-exempt cookies on its website without prior user consent. The case concerns non-compliance with cookie consent requirements and user privacy obligations.ESAEPDePrivacy€5,000
04 Feb 2026MediaLab.AI, Inc.The ICO imposed a 247,590 GBP penalty on MediaLab.AI, Inc. for breaches of Articles 5(1)(a), 6, 8 and 35 UK GDPR. The company operated Imgur in the UK and allowed children under 13 to access the platform without a reliable way to verify age or obtain the required parental consent. It also failed to carry out a DPIA before high-risk processing involving children under 18.GBICOGDPR€287,000
05 Feb 2026Óbudai EgyetemÓbudai Egyetem was fined by the NAIH 1,500,000 HUF for breaching the principles of transparency and data minimization. The authority also found no lawful basis for processing and that the conditions for processing special categories of data were not met.HUNAIHGDPR€3,945
05 Feb 2026Tensa Art Design S.AThe National Supervisory Authority for Personal Data Processing completed an investigation in January 2026 at Tensa Art Design S.A. It found violations of GDPR provisions and imposed a fine of EUR 20,000.ROANSPDCPGDPR€20,000
05 Feb 2026Dane anonimowe (pana H. G., prowadzącego działalność gospodarczą pod firmą H.)The President of the Polish DPA (UODO) imposed a fine of PLN 16,804 on an anonymous sole proprietor. The sanction resulted from failure to cooperate with the authority and from not providing access to personal data and information necessary for the performance of its duties.PLUODOGDPR€3,982
05 Feb 2026AVOCAT (procédure simplifiée)The CNIL imposed a fine of EUR 1,000 on AVOCAT (procédure simplifiée) in connection with the liquidation of astreinte. The case concerns enforcement of a prior obligation and the amount due for failure to comply on time.FRCNILGDPR€1,000