Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
28 Oct 2021TPER Trasporto Passeggeri Emilia Romagna S.p.A.TPER Trasporto Passeggeri Emilia Romagna S.p.A. was fined by the Garante EUR 30,000 for violations related to the processing of personal data of call center employees. The case involved potential unauthorized monitoring and insufficient data protection measures.ITGaranteGDPR€30,000
01 Jan 2016TOYS CENTRE, S.L.TOYS CENTRE, S.L. continued sending promotional emails to a complainant even after confirming removal from the mailing list. The AEPD fined the company for failing to comply with the requirements for commercial communications.ESAEPDePrivacy€6,200
18 Dec 2024Toyota Bank Polska S.A.The Polish supervisory authority imposed an administrative fine of EUR 132,000 on Toyota Bank Polska S.A. on 18 December 2024. The penalty concerned breaches of GDPR Articles 30, 35, and 38, including DPO independence, profiling documentation, and DPIA obligations.PLPresident of the Personal Data Protection Office (UODO)GDPR€132,000
18 Mar 2023TOTALENERGIES CLIENTES, S.A.TOTALENERGIES CLIENTES, S.A. was fined EUR 200,000 by the AEPD for linking a customer’s personal data to a third party during gas supply service registration. The authority found this breached data protection principles.ESAEPDGDPR€200,000
03 Apr 2014Torre Marina s.r.l.Torre Marina s.r.l. was fined €2,400 by the Italian Garante. The case concerned the collection of personal data through its websites without the required information notice under Article 13 of the Italian Data Protection Code.ITGaranteGDPR€2,400
07 Apr 2022Törlési jog a Központi Hitelinformációs Rendszerben tárolt mulasztási adatokkal összefüggésbenThe controller was fined for unlawful data processing and for failing to properly handle a data subject request. The authority found breaches of GDPR Articles 6, 12, and 17 in connection with default data stored in the Central Credit Information System.HUNAIHGDPR€2,640
26 Jun 2019Törléshez való jog megsértése, jogalap nélküli adatkezelés, célhoz kötöttség és adattakarékosság elvének megsértéseThe controller did not comply with the data subject’s request to delete personal data, including phone numbers. The authority found unlawful processing and a breach of the principles of purpose limitation and data minimization.HUNAIHGDPR€3,090
11 Nov 2019Törléshez való jog megsértése, jogalap nélküli adatkezelés, célhoz kötöttség, adattakarékosság és átláthatóság elvének megsértéseThe supervisory authority found that the controller did not comply with requests to erase personal data and unlawfully processed phone numbers. It also identified breaches of purpose limitation, data minimization, and transparency principles.HUNAIHGDPR€4,485
05 Sept 2013Top Secret S.r.l.Top Secret S.r.l. was fined by the Garante 6,000 EUR for collecting personal data through forms on its website without the required privacy notice. The authority found this to be a breach of the Italian Data Protection Code.ITGaranteGDPR€6,000
12 Sept 2024Top Quality Corporation S.r.l.s.Top Quality Corporation S.r.l.s. was fined by the Garante 5,000 EUR for failing to respond to a data subject’s request to access personal data related to employment. The authority found a breach of GDPR Articles 12 and 15.ITGaranteGDPR€5,000
12 Apr 2018Tonino CeciliaTonino Cecilia, owner of Telefonia Trigoria, was fined by the Italian authority Garante. The penalty concerned activating phone cards for two individuals without their consent, which breached data protection rules.ITGaranteGDPR€20,000
09 Jan 2019TOM TOM SALES BV SUCURSAL EN ESPAÑATOM TOM SALES BV SUCURSAL EN ESPAÑA was fined by the AEPD 2,500 EUR for sending a promotional email to a user after confirming the deletion of their data. The authority found this conduct breached Article 21 of the LSSI.ESAEPDePrivacy€2,500
06 Nov 2019TODOTECNICOS24H S.L.TODOTECNICOS24H S.L. was fined by the AEPD EUR 1,500 for collecting personal data without providing the required information to the data subjects. The authority treated this as a breach of data protection rules.ESAEPDGDPR€1,500
01 Jan 2019TODO POR EL 431, S.L.TODO POR EL 431, S.L. was fined by the AEPD €4,000 for using surveillance cameras oriented toward public spaces without justified cause. The authority found this to be a breach of data protection rules.ESAEPDGDPR€4,000
19 May 2021TNT EXPRESS WORLDWIDE SPAIN, S.L.TNT Express Worldwide Spain, S.L. was fined by the AEPD €10,000 for incorrectly linking a personal delivery service to a corporate account. This resulted in the unauthorized sharing of personal data with the complainant’s employer.ESAEPDGDPR€10,000
05 Dec 2024TMETME was fined EUR 200,000 by the AEPD for changing the ownership of a mobile line without consent and for issuing a duplicate SIM card without a valid legal basis. The authority found that these actions failed to meet the requirements for lawful processing and proper authorization of subscriber account changes.ESAEPDGDPR€200,000
03 Feb 2026TMAC LtdTMAC Ltd was fined GBP 100,000 by the ICO and served with an enforcement notice for breaches of regulations 21 and 24 of PECR. Between 8 February 2024 and 24 September 2024, the company made 260,332 unsolicited direct marketing calls to numbers listed on the Commissioner’s register. It also failed to provide the required information to call recipients.GBICOePrivacy€115,000
27 Apr 2023Tiziana Life Science LimitedTiziana Life Science Limited was fined by the Italian Garante in the amount of EUR 30,000. The case concerned failure to provide information and obtain consent for processing personal and genetic data acquired from the bankrupt company Shar.Dna S.p.A. for scientific research purposes.ITGaranteGDPR€30,000
26 Sept 2023TITAN STRONG, S.L.TITAN STRONG, S.L. was fined EUR 500 by the AEPD for installing surveillance cameras that captured excessive images of public areas without prior authorization. The authority found this to be a breach of data protection rules.ESAEPDGDPR€500
03 May 2022TITANIA COMPAÑÍA EDITORIAL, S.L.TITANIA COMPAÑÍA EDITORIAL, S.L. was fined by the AEPD 50,000 EUR for publishing an audio recording of a victim’s testimony in a high-profile court case. The authority found that the company processed personal data excessively and breached data protection principles.ESAEPDGDPR€50,000