Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
11 Jul 2024EOS MatrixAZOP imposed a EUR 5.47 million fine on EOS Matrix for a personal data protection breach following an incident involving the data of 181,641 debtors. The case was described as a GDPR violation and the largest fine in the authority's history.HRAZOPGDPR€5,470,000
12 Jan 2023WhatsApp Ireland Ltd.The Irish DPC fined WhatsApp Ireland Ltd. EUR 5,500,000 in case IN-18-5-6. The decision is currently under appeal.IEDPCGDPR€5,500,000
02 Feb 2017Sigue Global Service LimitedSigue Global Service Limited was fined by the Garante 5,880,000 EUR for breaches of data protection rules and anti-money laundering requirements. The authority cited money transfers carried out without proper consent, techniques used to obscure the true origin of funds, and non-compliance with AML obligations.ITGaranteGDPR€5,880,000
16 Mar 2026Restaurant Partner PolskaThe Polish Data Protection Authority imposed an administrative fine of PLN 5,898,064 on Restaurant Partner Polska, the operator of Glovo in Poland. The authority found that the company unlawfully collected and processed scans and photos of users’ identity documents, in breach of GDPR requirements.PLUrząd Ochrony Danych OsobowychGDPR€1,381,000
19 Feb 2026Dane anonimowe (W.)UODO imposed an administrative fine of PLN 5,898,064 on Dane anonimowe (W.). The authority found that the company processed personal data without a legal basis and in a manner that was excessive and disproportionate to the stated purpose, including by collecting photos or scans of identity cards or passports.PLUODOGDPR€1,397,000
26 Feb 2025SportadminIMY fined Sportadmin SEK 6 million after an IT attack exposed personal data of more than 2.1 million individuals, mostly children. The authority found that the company had not maintained an appropriate security level for the personal data it processed.SEIntegritetsskyddsmyndighetenGDPR€538,000
01 Jan 2022CosmoteThe Greek data protection authority imposed a €6 million fine on Cosmote under decision 4/2022. The sanction concerned inadequate security measures and retaining more data than permitted after a 2020 cyberattack.GRΑρχή Προστασίας Δεδομένων Προσωπικού ΧαρακτήραGDPR€6,000,000
17 Jun 2024FÚTBOL CLUB BARCELONAFútbol Club Barcelona was fined by the AEPD for processing biometric data without explicit consent during a mandatory member census update. The authority found breaches of GDPR Articles 9 and 35, relating to special-category data processing and data protection impact assessment requirements.ESAEPDGDPR€6,000,000
26 Aug 2020Anonymizováno (ÚOOÚ UOOU-03916/19-49)The entity was fined for sending unsolicited commercial communications without a valid legal basis. The conduct violated the Czech law on certain information society services.CZUOOUePrivacy€228,000
26 Jan 2026SportAdmin i Skandinavien ABSportAdmin i Skandinavien AB was fined by IMY 6,000,000 SEK for failing to implement appropriate technical and organizational measures to ensure an adequate level of security for personal data. The deficiency resulted in a data breach.SEIMYGDPR€564,000
01 Dec 2023ENDESA, S.A.The Spanish data protection authority imposed a EUR 6.1 million fine on ENDESA in December 2023. The case involved a security breach that led to the sale of customer personal data through Facebook ads.ESAgencia Española de Protección de DatosGDPR€6,100,000
05 Feb 2026Dane anonimowe (X.)UODO imposed an administrative fine of PLN 6,251,471 on Dane anonimowe (X.) for breaching Article 28(3) GDPR. The company used external transport providers without prior data processing agreements and without implementing adequate organizational measures to ensure data security.PLUODOGDPR€1,481,000
06 Jun 2024Eni Plenitude S.p.A. Società BenefitEni Plenitude S.p.A. was fined by the Garante 6,419,631 EUR for making unsolicited promotional calls without prior consent. The company also used numbers listed in the Public Opposition Register, which constituted a breach of GDPR rules.ITGaranteGDPR€6,419,000
01 Jan 2023PHONE HOUSEPHONE HOUSE was fined by the AEPD for failing to ensure data integrity and confidentiality. The breach resulted in a data incident caused by a cyberattack.ESAEPDGDPR€6,500,000
01 Feb 2019CAIXABANK, S.A.CAIXABANK was fined by the AEPD for introducing new data protection conditions that required consent for sharing data within its group. The authority found the measure disproportionate and lacking a proper legal basis.ESAEPDGDPR€6,500,000
17 Apr 2026Poste Italiane S.p.a. e PostePay S.p.a.Poste Italiane S.p.a. and PostePay S.p.a. were sanctioned for unlawful processing of personal data in their Bancoposta and PostePay apps on Android devices. The apps required users to authorize access to data to detect malicious software, which breached GDPR principles.ITGaranteGDPR€6,624,000
15 May 2026Unnamed Hungarian employerHungary’s data protection authority, NAIH, imposed a HUF 7 million GDPR fine on an unnamed employer. The case involved continuous camera monitoring in employee dining and rest areas, as well as deficiencies in documentation and privacy notices.HUNemzeti Adatvédelmi és Információszabadság HatóságGDPR€19,460
02 Aug 2022Oraculum 2020 Korlátolt Felelősségű TársaságNAIH fined Oraculum 2020 Kft. and SzondaPhone Kft. for unlawful data processing during telephone surveys. The authority found breaches of GDPR principles of lawfulness, transparency, data minimization, and accountability.HUNAIHGDPR€17,640
28 Mar 2022Klarna Bank AB, bristande informationKlarna Bank AB was fined by IMY SEK 7.5 million for failing to provide adequate information on the purposes and legal basis for processing personal data. The authority also found incomplete and misleading information about data recipients and automated decision-making.SEIMYGDPR€719,000
27 Apr 2020Hungária Med-M Kereskedelmi és Szolgáltató Korlátolt Felelősségű TársaságThe company failed to implement adequate security measures, report a data breach, and notify affected individuals in a timely manner. NAIH found violations of GDPR Articles 32, 33, and 34.HUNAIHGDPR€21,150