Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-23.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
29 May 2026Unicredit Bank SAUnicredit Bank SA was fined EUR 2,000 by ANSPDCP. The authority found that the bank failed to notify a personal data breach within the required 72-hour deadline.ROANSPDCPGDPR€2,000
01 May 2025SC Piramida Trade Invest SRLThe Romanian DPA ANSPDCP imposed a total fine of EUR 3,000 on SC Piramida Trade Invest SRL for unlawful audio-video monitoring of employees and inadequate staff information. It also found that the company failed to respond to access, erasure, and objection requests within the legal deadline; a separate email-forwarding issue resulted only in a warning.ROAutoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter PersonalGDPR€3,000
16 May 2025ACCOUNTING & AUDIT CONSULTING SRLACCOUNTING & AUDIT CONSULTING SRL was fined by ANSPDCP €5,000 for GDPR violations. The investigation was completed in April 2025, and the decision was issued on 16 May 2025.ROANSPDCPGDPR€5,000
06 Mar 2024Sectorul 1 al Municipiului BucureștiSectorul 1 of Bucharest was fined 159,000 RON by ANSPDCP for failing to comply with a remediation measure. The authority had required the requested information to be provided within 10 days, but the obligation was not met.ROANSPDCPGDPR€31,988
30 Jan 2026deținătorul site-ului evita-teparii.roANSPDCP imposed total fines of 51,000 lei, about 10,000 euro, on the operator, a natural person who runs the site evita-teparii.ro. The case involved multiple GDPR breaches, including the unlawful publication of identity, contact, sensitive, and alleged criminal data without a legal basis.ROANSPDCPGDPR€10,007
13 Oct 2025Vellea Home SRLIn September 2025, the National Supervisory Authority for Personal Data Processing completed an investigation at Vellea Home SRL and found violations of GDPR provisions. The operator was fined EUR 5,000.ROANSPDCPGDPR€5,000
18 May 2022Kredyt Inkaso Investments RO S.A.The company unlawfully processed personal data by disclosing it excessively, including health data. The authority found a breach of personal data processing principles.ROANSPDCPGDPR€5,000
27 Jun 2025YDAIL CONSTRUCT SRLANSPDCP completed an investigation at YDAIL CONSTRUCT SRL in June 2025 and found a violation of applicable legal provisions. As a result, the company was fined 20,000 RON.ROANSPDCPGDPR€3,936
17 Feb 2025Meedea Construct Prest SRLThe company was fined for violating the principles and lawfulness of personal data processing, specifically Articles 6 and 9 of the GDPR. A corrective measure was also imposed to ensure GDPR compliance in data collection and processing and to reduce the risk of unauthorized access and disclosure.ROANSPDCPGDPR€2,000
09 Aug 2022CDI Transport Intern și Internațional SRLThe company was fined for failing to provide requested information within the legal deadline. The authority treated this as a breach of GDPR requirements.ROANSPDCPGDPR€7,000
24 Nov 2022Medicover S.R.L.Medicover S.R.L. was fined EUR 1,000 by ANSPDCP for a data security breach. An email sent to a customer included additional contract documents belonging to other clients, resulting in disclosure of third-party personal data.ROANSPDCPGDPR€1,000
27 Jan 2025Orange România SAOrange România SA was fined EUR 20,000 by ANSPDCP for GDPR violations. The case concerns non-compliance with personal data protection requirements, creating regulatory risk for organizations processing data in Romania.ROANSPDCPGDPR€20,000
27 Mar 2023persoană fizicăAn individual was fined EUR 450 by ANSPDCP for violating GDPR provisions. The case concerned non-compliance with obligations under personal data protection rules.ROANSPDCPGDPR€450
01 Apr 2024Your Consulting SRLANSPDCP imposed a fine on Your Consulting SRL for GDPR violations related to insufficient technical and organizational security measures. The security gap allowed unauthorized access to personal data through one of the company’s applications.ROANSPDCPGDPR€3,000
27 Oct 2023Asociația de Proprietari bloc A1The homeowners association was fined by ANSPDCP for failing to implement measures ordered by the authority and for unlawfully disclosing owners’ names on maintenance lists without consent. The case concerns breaches of personal data protection rules and non-compliance with supervisory instructions.ROANSPDCPGDPR€501
09 May 2024IRIDEX GROUP SALUBRIZARE SRLIRIDEX GROUP SALUBRIZARE SRL was fined by ANSPDCP 2,000 EUR for sending a collective email to clients with recipients' email addresses visible. The incident resulted in unauthorized disclosure of personal data.ROANSPDCPGDPR€2,000
05 Mar 2024EURO MINI STORAGE ROMANIA SRLEURO MINI STORAGE ROMANIA SRL was fined by ANSPDCP EUR 5,000 for a data security breach caused by a cyber attack. The incident led to unauthorized access to personal data and affected data availability for several weeks.ROANSPDCPGDPR€5,000
01 Jun 2025Călin GeorgescuCălin Georgescu was sanctioned by Romania’s data protection authority after an investigation into his website. Two fines totaling about EUR 10,000 were imposed for installing cookies without consent and collecting personal data without proper notice.ROAutoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter PersonalGDPR€10,000
03 Nov 2023OTP BANK ROMANIA SAThe National Supervisory Authority for Personal Data Processing imposed a fine of EUR 3,000 on OTP BANK ROMANIA SA for GDPR violations. The case concerned non-compliance with personal data protection requirements.ROANSPDCPGDPR€3,000
09 Sept 2025Unita Turism Holding S.A.In August 2025, the National Supervisory Authority for Personal Data Processing completed an investigation at Unita Turism Holding S.A. and found violations of GDPR provisions. As a result, the operator was fined EUR 5,000.ROANSPDCPGDPR€5,000