Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.5m
YoY volume
-24%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
12 Mar 2026Domiziana GiorgianniThe Garante imposed a EUR 2,000 fine on Domiziana Giorgianni for failing to implement adequate technical and organizational measures to support data subject rights. The authority also found that requests were not handled without undue delay.ITGaranteGDPR€2,000
12 Mar 2026Liceo Scientifico MorgagniLiceo Scientifico Morgagni was fined by the Garante for violations related to the processing of sensitive data. The authority cited inadequate security measures in the protection of those data.ITGaranteGDPR€2,000
12 Mar 2026La7 S.p.A.La7 S.p.A. was fined 40,000 EUR by the Garante for broadcasting personal data, including phone numbers and names, during a news segment. The authority found a breach of GDPR Article 5 on data processing principles.ITGaranteGDPR€40,000
12 Mar 2026SOCIÉTÉ EXERÇANT UNE ACTIVITÉ DE VENTE À DISTANCE SUR CATALOGUE SPECIALISÉE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 5,000 on Société exerçant une activité de vente à distance sur catalogue spécialisée. The case was handled under a simplified procedure.FRCNILGDPR€5,000
12 Mar 2026Hanako s.r.l.Hanako s.r.l. was fined by the Garante EUR 2,000 for operating a video surveillance system without ensuring GDPR compliance. The authority cited inadequate security measures and failure to provide sufficient information to employees.ITGaranteGDPR€2,000
16 Mar 2026Restaurant Partner PolskaThe Polish Data Protection Authority imposed an administrative fine of PLN 5,898,064 on Restaurant Partner Polska, the operator of Glovo in Poland. The authority found that the company unlawfully collected and processed scans and photos of users’ identity documents, in breach of GDPR requirements.PLUrząd Ochrony Danych OsobowychGDPR€1,381,000
19 Mar 2026HafnarfjarðarbærHafnarfjarðarbær was fined for using Google Workspace for Education in schools without full compliance with data protection rules. The authority cited unclear processing purposes and delayed data protection impact assessments.ISPersónuverndGDPR€19,516
19 Mar 2026GarðabærGarðabær was fined for multiple data protection violations in its use of Google Workspace for Education without ensuring GDPR compliance. The case concerned the processing of children's personal data, which required additional safeguards and a proper legal basis.ISPersónuverndGDPR€17,425
19 Mar 2026KópavogsbærKópavogsbær was fined by Persónuvernd for using Google Workspace for Education in schools without full compliance with data protection rules. The authority cited, among other issues, the absence of a data protection impact assessment and unclear processing purposes.ISPersónuverndGDPR€20,910
19 Mar 2026ReykjavíkurborgReykjavíkurborg was fined by Persónuvernd for using Google Workspace for Education in schools without meeting GDPR requirements. The case concerned the processing of children's personal data, which required heightened compliance and safeguards.ISPersónuverndGDPR€13,940
20 Mar 2026Domeniul Public și Privat SADomeniul Public și Privat SA was fined 2,000 EUR by ANSPDCP for GDPR violations. The case concerned non-compliance with personal data protection requirements.ROANSPDCPGDPR€2,000
20 Mar 2026Domeniul Public și Privat SADomeniul Public și Privat SA was fined EUR 1,000 for breaching Article 15 of the GDPR. The case concerned improper handling of data subject access rights.ROANSPDCPGDPR€1,000
20 Mar 2026Jogalap nélküli hozzáférés az EESZT rendszeréhez és hozzáférési kérelem nemteljesítéseThe supervisory authority imposed a fine for processing personal data without a lawful basis, including health data. It also found failure to comply with an access request, which breaches GDPR obligations.HUNAIHGDPR€1,275
23 Mar 2026ING Bank NV Amsterdam – Sucursala București S.A.The fine was imposed for failing to implement adequate technical and organizational measures to ensure the confidentiality of personal data. As a result, an unauthorized third party received a bank account statement.ROANSPDCPGDPR€4,000
24 Mar 2026SIA "Fitsypro"SIA "Fitsypro" was fined EUR 1,500 by the DVI. The decision has entered into force.LVDVIGDPR€1,500
26 Mar 2026Esselunga S.p.A.Esselunga S.p.A. was fined EUR 5,000 by the Italian supervisory authority, Garante. The case concerned a failure to respond to a data access request under Article 15 GDPR, including access to employee attendance records.ITGaranteGDPR€5,000
26 Mar 2026Euro Bangla MinimarketThe Garante fined Euro Bangla Minimarket EUR 1,000 for improper use of a video surveillance system. Images from six cameras were visible to everyone on a monitor in the store, which breached GDPR requirements.ITGaranteGDPR€1,000
26 Mar 2026SOCIÉTÉ EXERÇANT UNE ACTIVITÉ D'ARTS DU SPECTACLE VIVANT (procédure simplifiée)CNIL imposed a fine of 850 EUR on SOCIÉTÉ EXERÇANT UNE ACTIVITÉ D'ARTS DU SPECTACLE VIVANT in connection with the liquidation of astreinte. The case concerns compliance with a prior obligation under a simplified procedure.FRCNILGDPR€850
26 Mar 2026Provvedimento del 26 marzo 2026 [10246060]The entity was fined for operating a video surveillance system without providing adequate informational signage. The authority found this to be a breach of GDPR Article 13 on the duty to inform data subjects.ITGaranteGDPR€2,000
26 Mar 2026Copacabana s.r.l.Copacabana s.r.l. was fined EUR 2,000 by the Garante for installing a video surveillance system without the required informational signage and necessary authorization. The authority cited a breach of GDPR Article 13.ITGaranteGDPR€2,000