Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-24%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
26 Feb 2026Dante Labs S.r.l.Dante Labs S.r.l. was fined EUR 600 by the Garante for failing to provide the results of a genetic test after receiving a customer's DNA sample. Despite multiple attempts by the customer to contact the company, the results were not delivered or explained.ITGaranteGDPR€600
26 Feb 2026Depac Società Cooperativa Sociale a r.l.Depac Società Cooperativa Sociale a r.l. was fined by the Garante EUR 15,000 for unauthorized processing of employees' biometric data. The case concerned the collection and storage of fingerprint data without proper consent or a valid legal basis.ITGaranteGDPR€15,000
26 Feb 2026Ciemme S.r.l.sThe Italian Data Protection Authority fined Ciemme S.r.l.s EUR 1,000 for failing to respond to a data subject request to exercise rights of access, erasure, and objection. The case arose after unsolicited marketing calls.ITGaranteGDPR€1,000
26 Feb 2026Ministero dell’Economia e delle FinanzeThe Ministry of Economy and Finance was fined 12,000 EUR by Garante for inadequate control measures over the data processor. The authority found breaches of GDPR Articles 3, 5 and 6, as well as Article 2-ter of the Italian Privacy Code.ITGaranteGDPR€12,000
26 Feb 2026Flamel S.r.l.Flamel S.r.l. was fined by the Garante 15,000 EUR for carrying out promotional activities without a legal basis. The company used phone numbers not registered with the ROC, affecting the data of more than 500 individuals.ITGaranteGDPR€15,000
26 Feb 2026Dedalus Italia S.p.A.Dedalus Italia S.p.A. was fined EUR 32,000 by the Garante for inadequate security measures that led to a data breach. The company implemented corrective actions promptly, but prior violations were taken into account when setting the penalty.ITGaranteGDPR€32,000
26 Feb 2026Istituto Tecnico Statale L. 80014050357Istituto Tecnico Statale was fined by the Garante for breaches of data protection principles, including lawfulness, fairness, transparency, and data minimization. The school improperly published personal data on its website.ITGaranteGDPR€2,000
27 Feb 2026T., za naruszenie art. 5 ust. 1 lit. f), art. 5 ust. 2 oraz art. 32 ust. 1 i 2 rozporządzenia 2016/679,The Polish DPA (UODO) imposed an administrative fine of PLN 975 on T. for failing to implement appropriate technical and organizational measures and for lacking a proper, accountable data protection policy tailored to its processing activities. The authority also noted deficiencies in transparency notices, processor agreements, access authorizations, and the record of processing activities.PLUODOGDPR€231
02 Mar 2026Nordic Cleaning ApSThe Danish DPA reported Klein2 ApS and Nordic Cleaning ApS to the police for failing to comply with orders to address access requests. Nordic Cleaning ApS accepted a fine notice of 60,000 DKK.DKDatatilsynetGDPR€8,031
05 Mar 2026ASSOCIATION AYANT POUR OBJET DE PROMOUVOIR L'ACCÈS AUX SOINS DENTAIRES DES PERSONNES DÉMUNIES (procédure simplifiée)The CNIL imposed an administrative fine of EUR 6,000 on ASSOCIATION AYANT POUR OBJET DE PROMOUVOIR L'ACCÈS AUX SOINS DENTAIRES DES PERSONNES DÉMUNIES and issued an injunction. The case was handled under a simplified procedure.FRCNILGDPR€6,000
05 Mar 2026Poczta Polska S.A.The President of the Polish Data Protection Authority imposed a fine of PLN 27,124,816 on Poczta Polska S.A. for processing personal data in connection with preparations for the presidential election at the prime minister's order. The Warsaw Regional Administrative Court overturned the decision on 2026-03-05.PLPrezes Urzędu Ochrony Danych OsobowychGDPR€6,348,000
05 Mar 2026ASSOCIATION DE DÉFENSE DE DROITS FONDAMENTAUX(procédure simplifiée)CNIL imposed a EUR 5,100 penalty on ASSOCIATION DE DÉFENSE DE DROITS FONDAMENTAUX in connection with the liquidation of astreinte. The matter concerns enforcement of a prior obligation, with the amount arising from non-compliance.FRCNILGDPR€5,100
05 Mar 2026Altex România S.R.L.The National Supervisory Authority for Personal Data Processing imposed fines totaling EUR 8,000 on Altex România S.R.L. for GDPR violations. The case followed complaints from data subjects.ROANSPDCPGDPR€8,000
12 Mar 2026Enel Energia S.p.A.Enel Energia S.p.A. was fined by the Italian data protection authority, Garante, for making unwanted telemarketing calls without a proper legal basis. The authority found that the company’s conduct breached data protection principles.ITGaranteGDPR€563,000
12 Mar 2026Bakeca s.r.l.Bakeca s.r.l. was fined €5,000 by the Italian data protection authority, Garante. The case concerned the publication of online ads without the required consent, which breached data protection rules.ITGaranteGDPR€5,000
12 Mar 2026Comune di SutriComune di Sutri was fined EUR 2,000 by the Garante for publishing personal data on its institutional website. The case concerns a breach of data protection rules in the public online disclosure of information.ITGaranteGDPR€2,000
12 Mar 2026ITAS MutuaITAS Mutua was fined EUR 50,000 by the Garante for failing to adequately respond to a former employee’s request for access to personal data. The authority found a breach of GDPR Article 15.ITGaranteGDPR€50,000
12 Mar 2026Almas SalonThe Garante imposed an EUR 800 fine on Almas Salon for operating a video surveillance system without proper compliance with data protection rules. The case concerns a breach of GDPR Article 5, indicating failure to meet core data processing principles.ITGaranteGDPR€800
12 Mar 2026INPS – Istituto nazionale previdenza socialeThe Italian Data Protection Authority fined INPS EUR 40,000 for improperly displaying personal data of individuals residing in a care facility during an ISEE precompilation request. The authority found a breach of data protection principles.ITGaranteGDPR€40,000
12 Mar 2026Artemide S.r.l.s.Artemide S.r.l.s., the owner of MeridioNews.it, was fined 10,000 EUR by the Garante. The authority found that the company failed to properly handle a request to delete and de-index articles concerning judicial matters, thereby infringing data protection rights.ITGaranteGDPR€10,000