Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
20 May 2026KRA Consultancy LtdKRA Consultancy Ltd was fined £300,000 by the ICO for sending more than 5.5 million unsolicited direct marketing texts and fake bailiff messages. The conduct breached regulations 22 and 23 of PECR and generated over 60,000 complaints to the 7726 spam reporting service.GBICOePrivacy€346,000
29 Aug 2024EDITEUR DE SITE WEB DANS LE DOMAINE DES TRANSPORTSEDITEUR DE SITE WEB DANS LE DOMAINE DES TRANSPORTS was fined EUR 300,000 by the CNIL. The case concerns a breach of personal data protection rules.FRCNILGDPR€300,000
08 Aug 2022Hangfelvétel készítése szerelési munkák soránThe authority found that the entity breached the GDPR by recording audio during installation work without a proper legal basis. It also failed to meet transparency and data protection principle requirements.HUNAIHGDPR€762
01 Jan 2021PAGE GROUP EUROPEPAGE GROUP EUROPE was fined by the AEPD 300,000 EUR for breaches of GDPR principles on data minimization and transparency. The case concerned the improper handling of a data subject access request submitted through its Dutch website.ESAEPDGDPR€300,000
23 May 2019Ítélet a NAIH/2019/1189/11 sz. ügyben (Fővárosi Törvényszék 105.K.700.364/2019/11)The controller did not provide the requested personal data or information beyond a 2012 lease agreement. This breached the data subject’s access rights under the GDPR.HUNAIHGDPR€918
21 Mar 2024Budapesti Rendőr-főkapitányság XI. kerületi RendőrkapitányságBudapesti Rendőr-főkapitányság XI. kerületi Rendőrkapitányság was fined by NAIH 300,000 HUF for violations related to the closed handling of personal data. The authority found breaches of several provisions of the Hungarian Information Act (Infotv.).HUNAIHGDPR€762
01 Jan 2024TELEFÓNICA MÓVILES ESPAÑA, S.A.TELEFÓNICA MÓVILES ESPAÑA, S.A. was fined by the AEPD for issuing a duplicate SIM card without proper consent or identity verification. The failure enabled identity theft and fraudulent transactions.ESAEPDGDPR€300,000
08 Sept 2021Region MidtjyllandRegion Midtjylland was fined for failing to implement adequate access restrictions to an archive containing sensitive patient records. This allowed unauthorized access by patients and staff at a lifestyle center.DKDatatilsynetGDPR€40,344
09 Mar 2020Személyes adat a természetes személy állandó használatában lévő telefonszámThe controller was fined for unlawfully processing the complainant's phone number. The authority found a breach of the GDPR principles of lawfulness and accuracy in personal data processing.HUNAIHGDPR€891
23 May 2019Telenor Magyarország Zrt.Telenor Magyarország Zrt. was fined by the Hungarian NAIH 300,000 HUF for failing to comply with a data subject access request under the GDPR. The authority also found that the company did not inform the data subject of the right to an effective legal remedy.HUNAIHGDPR€918
15 Dec 2021Anonymizováno (ÚOOÚ UOOU-01071/21-30)The entity was fined by the UOOU for repeatedly sending unsolicited commercial communications to electronic contacts without prior consent. The messages also failed to clearly identify the sender or label the content as commercial.CZUOOUePrivacy€11,871
28 Aug 2025Home Improvement Marketing LtdHome Improvement Marketing Ltd was investigated by the ICO as part of a wider review of complaint trends in the energy and home improvements sector. After a search warrant and extensive investigation, the ICO found that between 31 May 2023 and 31 August 2023 the company initiated 2,449,380 automated marketing calls to subscribers without prior consent, contrary to PECR. The conduct generated 274 complaints to the TPS and ICO reporting tools.GBICOePrivacy€347,000
01 Oct 2024IBERCAJA BANCO, S.A.Ibercaja Banco, S.A. accessed personal data in the BADEXCUG EXPERIAN file 47 times without consent after the contractual relationship ended. The AEPD found this to be a breach of data protection rules and imposed a 300,000 EUR fine.ESAEPDGDPR€300,000
28 Nov 2023Barn- och utbildningsnämnden, Östersunds kommunBarn- och utbildningsnämnden in Östersunds kommun was fined by IMY for failing to conduct a data protection impact assessment before deploying Google Workspace for Education in 24 schools. The authority found this to be a breach of Article 35 GDPR.SEIMYGDPR€26,241
08 May 2014Telextra s.r.l.Telextra s.r.l. was fined by the Garante for processing personal data from electronic communication operators' databases without consent. The authority also found non-compliance with previous orders and data protection requirements.ITGaranteGDPR€300,000
09 Jun 2022Webáruház adatkezelési tájékoztatójaThe authority found a GDPR breach because the website and online store did not provide clear and transparent information about personal data processing. A fine of 300,000 HUF was imposed.HUNAIHGDPRFt 300,000
01 Jan 2026Telekommunikationsunternehmen aus NRWThe Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen imposed a total fine of EUR 300,000 on a telecommunications company from North Rhine-Westphalia. The authority found breaches of transparency obligations and data subject rights, including requests for access, deletion, and objection.DELandesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-WestfalenGDPR€300,000
22 Apr 2022DISPLAY CONNECTORS, S.LDISPLAY CONNECTORS, S.L was fined EUR 300,000 by the AEPD for automatically publishing videos containing personal data without first ensuring the processing was lawful. The authority found this conduct breached data protection rules.ESAEPDGDPR€300,000
14 Mar 2022Tullverket, tjänstemobilerThe Swedish Customs Agency (Tullverket) was fined by IMY 300,000 SEK for failing to implement adequate technical and organizational measures. This led to unauthorized storage of personal data in a cloud service.SEIMYePrivacy€28,473
03 Dec 2021Bűnügyi személyes adatok kezelése magánvádló általThe controller unlawfully transferred the complainant's criminal personal data, breaching the principles of lawful and fair processing and purpose limitation. The authority also found no legal basis for processing under the GDPR.HUNAIHGDPR€825