Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
23 Oct 2024ASSOCIATION PARTICIPANT AUX ACTIVITES DES ORGANISATIONS POLITIQUES (procédure simplifiée)CNIL imposed a EUR 4,000 penalty on ASSOCIATION PARTICIPANT AUX ACTIVITES DES ORGANISATIONS POLITIQUES under a simplified procedure. The case concerns liquidation of an astreinte, indicating that a prior obligation was not fulfilled on time.FRCNILGDPR€4,000
25 Apr 2024ASSOCIATION PARTICIPANT AUX ACTIVITES DES ORGANISATIONS POLITIQUES (procédure simplifiée)The CNIL imposed an administrative fine of EUR 16,000 on ASSOCIATION PARTICIPANT AUX ACTIVITES DES ORGANISATIONS POLITIQUES. The authority also issued an injunction requiring corrective action.FRCNILGDPR€16,000
27 Dec 2023ASSOCIATION PROMOUVANT DES ACTIONS AU SEIN D'UNE COMMUNE (procédure simplifiée)CNIL imposed a 5,000 EUR fine on ASSOCIATION PROMOUVANT DES ACTIONS AU SEIN D'UNE COMMUNE and issued an injunction. The case concerned a confirmed data protection breach handled under a simplified procedure.FRCNILGDPR€5,000
29 Jan 2026ASSOCIATION RELIGIEUSE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 10,000 on ASSOCIATION RELIGIEUSE (procédure simplifiée) and issued an injunction. The case concerned a confirmed breach of rules supervised by the CNIL.FRCNILGDPR€10,000
20 Oct 2022Associazione Covid-Healer ODVThe Garante fined Associazione Covid-Healer ODV 500 EUR for breaches linked to the processing of health data through its app, which was active for a short period. The authority cited inadequate transparency and deficiencies in the data protection impact assessment.ITGaranteGDPR€500
05 Dec 2013Associazione culturale KoalaAssociazione culturale Koala was fined 30,000 EUR by the Italian Garante. The case concerned the installation of a fingerprint recognition system for user access without providing the required information to the supervisory authority.ITGaranteGDPR€30,000
17 Jul 2025Associazione Il Cavallo Rosa/ChangeTheGame ODVThe Garante fined Associazione Il Cavallo Rosa/ChangeTheGame ODV 10,000 EUR for publishing a minor’s personal data on its Facebook page without anonymization. The authority found a breach of the data subject’s rights under the GDPR.ITGaranteGDPR€10,000
23 May 2024Associazione Medica Chirone s.c.r.l.The Garante fined Associazione Medica Chirone s.c.r.l. 5,000 EUR for improperly accessing and using an employee's vaccination status data. The authority found that the data were not properly anonymized, resulting in a breach of data protection rules.ITGaranteGDPR€5,000
26 Jul 2018Associazione MEVALAUTE ONLUSThe association was fined by the Garante for sending unsolicited PEC communications. The authority found that personal data were processed without consent, in breach of data protection rules.ITGaranteGDPR€26,000
17 Apr 2026Associazione Movimento Cinque Stelle SiciliaThe Garante fined Associazione Movimento Cinque Stelle Sicilia 5,000 EUR for failing to adopt adequate technical and organizational measures to facilitate the exercise of data protection rights. The authority also found that requests were not addressed without undue delay.ITGaranteGDPR€5,000
11 Jan 2023Associazione Nazionale MagistratiAssociazione Nazionale Magistrati was fined by the Garante for improper handling of personal data. An official email address was used instead of a personal one to notify a disciplinary proceeding, which breached confidentiality requirements.ITGaranteGDPR€5,000
06 Oct 2022Associazione Rescue Drones Network ODVAssociazione Rescue Drones Network ODV was fined by the Garante in the amount of 3,000 EUR for failing to comply with data access requests. The authority treated this as a breach of GDPR Article 5.ITGaranteGDPR€3,000
12 Nov 2014Associazione sportiva dilettantistica Sport Fashion (A.S.D. Sport Fashion)The sports association was fined by the Garante 10,000 EUR for processing clients' biometric data without the required information and consent. The authority found this to be a breach of privacy rules.ITGaranteGDPR€10,000
25 Feb 2016Associazione sportivo dilettantistica Feriolo Sporting ClubFeriolo Sporting Club was fined by the Garante 14,400 EUR for failing to provide adequate simplified information about its video surveillance system. The authority also found that recorded images were retained longer than permitted.ITGaranteGDPR€14,400
16 Jan 2026Associazione Turistica Pro Loco di CittarealeThe association unlawfully disclosed the personal data of 23 members by publishing it in a public notice and online. The authority found breaches of lawfulness, fairness, transparency, and data minimization.ITGaranteGDPR€600
19 Jan 2023A startup football clubThe Belgian data protection authority, GBA, imposed an EUR 8,000 fine on a startup football club. The case involved failure to respond to a data subject access request, as well as additional GDPR breaches concerning transparency and processor-contract requirements.BEGegevensbeschermingsautoriteit (GBA)GDPR€8,000
16 Jul 2024A.S. Watson Health & Beauty Continental Europe B.V.A.S. Watson Health & Beauty Continental Europe B.V. was fined 600,000 EUR by the Dutch AP. The authority found that the company processed personal data without a lawful basis because it failed to obtain consent for tracking cookies on kruidvat.nl, breaching GDPR Articles 5 and 6.NLAPGDPR€600,000
16 Jul 2024AS Watson / KruidvatThe Dutch data protection authority, Autoriteit Persoonsgegevens, imposed a fine of EUR 600,000 on AS Watson / Kruidvat. The case concerns a breach of GDPR cookie consent rules.NLAutoriteit PersoonsgegevensGDPR€600,000
02 Nov 2023ASYMECO, S.A.ASYMECO, S.A. was fined EUR 5,000 by the AEPD for sending clients’ personal data to an employee’s private WhatsApp without proper authorization. The authority found this breached GDPR Articles 6(1) and 32.ESAEPDGDPR€5,000
22 Jul 2021Atac s.p.a.Atac s.p.a. was fined by the Garante 400,000 EUR for processing personal data without a specific legal basis and without adequate security measures. The case concerned users of paid parking services in Rome.ITGaranteGDPR€400,000