BULLETIN №081Last updated · 28 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -20.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 18 Jul 2023 | Tiscali Italia S.p.A.Tiscali Italia S.p.A. was fined EUR 100,000 by the Garante for sending promotional SMS messages to existing customers without their consent. The authority also found inadequate data retention policies and insufficient transparency in the privacy notices. | IT | Garante | GDPR | €100,000 | ↗ |
| 06 Dec 2011 | Tiscali Italia SpATiscali Italia SpA was fined €420,000 by the Garante for retaining customer traffic data beyond the legal retention period. The authority also found that Amdocs accessed the data without being properly designated as a data processor or obtaining customer consent. | IT | Garante | GDPR | €420,000 | ↗ |
| 29 Apr 2026 | Tirrenia Hospital SRLTirrenia Hospital SRL was fined EUR 1,000 by the Garante for failing to provide a comprehensible transcription of a deceased patient's medical records. The authority treated this as a breach of data protection rules. | IT | Garante | GDPR | €1,000 | ↗ |
| 29 Apr 2025 | Tirrenia Hospital S.r.l.Tirrenia Hospital S.r.l. was fined by the Garante EUR 2,000 for breaching the data processing principles set out in GDPR Article 5. The case concerned processing in the healthcare sector, where a particularly high level of compliance is required. | IT | Garante | GDPR | €2,000 | ↗ |
| 12 Jun 2015 | Tiresias AETiresias AE was fined for failing to implement measures to control access to personal data files. This failure led to unauthorized access by ICAP. | GR | HDPA | GDPR | €30,000 | ↗ |
| 14 Mar 2023 | Tinmar Energy SATinmar Energy SA was fined EUR 3,000 by ANSPDCP after unauthorized access to its email server. The incident resulted in a personal data breach. | RO | ANSPDCP | GDPR | €3,000 | ↗ |
| 15 Jan 2020 | TIM S.p.A.TIM S.p.A. was fined by the Garante for making unauthorized promotional calls. The authority found that the company failed to ensure adequate consent and accountability measures under data protection rules. | IT | Garante | GDPR | €27,802,000 | ↗ |
| 27 Feb 2020 | Tim S.p.A.The Italian data protection authority imposed a EUR 27.8 million fine on Tim S.p.A. The case concerned privacy violations in marketing and telemarketing activities, including issues with obtaining valid consent. | IT | Garante per la protezione dei dati personali | GDPR | €27,800,000 | ↗ |
| — | Timegrip ASDatatilsynet imposed an administrative fine of NOK 250,000 on Timegrip AS for denying employees access to their personal data relating to time tracking. The authority found that Timegrip effectively acted as the controller and had no valid basis to refuse the access requests. | NO | Datatilsynet | — | €22,435 | ↗ |
| 20 Jan 2026 | Timegrip ASTimegrip AS was fined 250,000 NOK for failing to provide employees access to their own timekeeping data after the bankruptcy of a retail chain. The authority treated the company as the data controller and found a breach of the GDPR right of access. | NO | Datatilsynet | GDPR | €21,340 | ↗ |
| 01 Sept 2023 | TikTok Technology Limited (TTL)The Irish DPC imposed a fine of EUR 345,000,000 on TikTok Technology Limited (TTL) following an inquiry. The matter remains ongoing because the decision is under appeal. | IE | DPC | GDPR | €345,000,000 | ↗ |
| 30 Apr 2025 | TikTok Technology LimitedThe Irish DPC imposed a fine of EUR 530,000,000 on TikTok Technology Limited in inquiry IN-21-9-2. The decision is currently under appeal. | IE | DPC | GDPR | €530,000,000 | ↗ |
| 15 May 2023 | TikTok Information Technologies UK Limited and TikTok Inc (TikTok)The UK ICO imposed a fine of 12,700,000 GBP on TikTok Information Technologies UK Limited and TikTok Inc for multiple breaches of data protection law. The regulator specifically cited unlawful use of children’s personal data. | GB | ICO | GDPR | €14,607,000 | ↗ |
| 22 Jul 2021 | TikTok Inc.TikTok Inc. was fined 750,000 EUR by the Dutch authority AP for providing its privacy policy to users in the Netherlands, including children, only in English. The authority found this breached Article 12 GDPR, which requires information to be provided in a clear and easily accessible form. | NL | AP | GDPR | €750,000 | ↗ |
| 01 Apr 2023 | TikTokTikTok is appealing a UK data-protection fine of GBP 12.7 million imposed by the Information Commissioner's Office. The record states that in April 2023 the platform was found to have breached the UK GDPR by failing to process children's personal data lawfully. | GB | Information Commissioner's Office | GDPR | €14,444,000 | ↗ |
| 02 Oct 2025 | TIGER MEDIA INC.TIGER MEDIA INC. was fined by the AEPD EUR 120,000 for processing personal data without a lawful basis. The authority also found that the company failed to appoint an EU representative, in breach of GDPR Articles 6 and 27. | ES | AEPD | GDPR | €120,000 | ↗ |
| 25 Oct 2017 | TICKETMASTER SPAIN S.A.Ticketmaster Spain S.A. was fined 17,000 EUR by the AEPD for failing to provide adequate information and obtain valid consent for the use of cookies on its website. The authority found that this conduct breached data protection and privacy rules. | ES | AEPD | ePrivacy | €17,000 | ↗ |
| 15 Apr 2021 | Tiberia Assicurazioni s.a.s.Tiberia Assicurazioni s.a.s. was fined by the Garante 1,500 EUR for sending an insurance contract proposal by email without the recipient's consent. The authority found this to be a breach of GDPR Article 6. | IT | Garante | GDPR | €1,500 | ↗ |
| 20 May 2022 | THUNDER HUNTER ENERGY ADVISORS, S.L.THUNDER HUNTER ENERGY ADVISORS, S.L. was fined by the AEPD 1,000 EUR for sending unsolicited commercial emails without prior consent. The authority found this conduct breached Article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €1,000 | ↗ |
| 11 Jul 2019 | Thomas N****The individual secretly recorded video footage of two women in a changing room without their consent. The DSB found this to be a breach of GDPR rules on lawful processing and consent. | AT | DSB | GDPR | €10,000 | ↗ |