Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
23 Jan 2024CAJA RURAL NTRA MADRE DEL SOL S.C.A.C.CAJA RURAL NTRA MADRE DEL SOL S.C.A.C. was fined by the AEPD for a data breach that enabled unauthorized access to personal data. The authority found a violation of the confidentiality and integrity principles for personal data.ESAEPDGDPR€250,000
16 Oct 2025SOCIETE DE CENTRES D'APPELSCNIL imposed an administrative fine of EUR 250,000 on SOCIETE DE CENTRES D'APPELS. The case concerns a breach of personal data protection rules.FRCNILGDPR€250,000
11 Jul 2022Anonymizováno (ÚOOÚ UOOU-04856/21-13)The entity was fined by the UOOU 250,000 CZK for sending unsolicited commercial communications by email to approximately 266,607 recipients without their consent. This conduct violated Czech rules on certain information society services.CZUOOUePrivacy€10,165
09 Jan 2024Det Kongelige TeaterThe Danish DPA reported Det Kongelige Teater to the police and recommended a fine of 250,000 DKK. The case concerned the absence of deletion rules for customer data used for marketing, affecting about 520,000 individuals.DKDatatilsynetGDPR€33,523
15 Mar 2012Ammiro Partners s.r.l.Ammiro Partners s.r.l. was fined for violations related to the processing of personal data. The authority cited failure to comply with a prior injunction and failure to respond to requests from the Garante.ITGaranteGDPR€250,000
29 Oct 2024Grue kommuneGrue kommune was fined 250,000 NOK by Datatilsynet after personal data was made accessible in its public journal. The authority found breaches of confidentiality requirements and GDPR rules on legal basis and security.NODatatilsynetGDPR€21,113
25 Mar 2019Taxa 4x35The Danish data protection authority recommended a fine for Taxa 4x35 for failing to delete customer data. The company retained personal data from taxi rides without a legitimate purpose, and the court ultimately imposed a fine of DKK 250,000.DKDatatilsynetGDPR€33,493
24 Jan 2024CAJA RURAL DE ASTURIAS, S.C.C.CAJA RURAL DE ASTURIAS was fined by the AEPD EUR 250,000 for breaching the confidentiality and integrity principles of personal data. The incident allowed unauthorized access to personal data, indicating a failure to protect data appropriately.ESAEPDGDPR€250,000
23 Jan 2024CAJA RURAL DE SALAMANCA, S.C.C.CAJA RURAL DE SALAMANCA, S.C.C. was fined by the AEPD 250,000 EUR for failing to ensure the confidentiality and integrity of personal data. The breach resulted in unauthorized access following a data security incident.ESAEPDGDPR€250,000
26 Sept 2024SOCIETE PROPOSANT DES SERVICES A DISTANCE D'ART DIVINATOIRECNIL imposed an administrative fine of EUR 250,000 on SOCIETE PROPOSANT DES SERVICES A DISTANCE D'ART DIVINATOIRE. The case concerns a breach of rules supervised by CNIL.FRCNILGDPR€250,000
28 Aug 2025Green Spark Energy LtdThe ICO investigated Green Spark Energy Ltd as part of a wider operation focused on complaint trends in the energy and home improvements sector. It found that between May 2023 and May 2024 the company initiated 9,587,050 automated recorded marketing calls in breach of regulation 19 of PECR, leading to 497 complaints. The recordings used misleading claims to pressure homeowners, and some recipients believed the calls were a scam.GBICOePrivacy€289,000
08 Sept 2022GROUPEMENT D'INTÉRÊT ÉCONOMIQUE DES GREFFES DE TRIBUNAUX DE COMMERCE DE FRANCECNIL imposed a fine of 250,000 EUR on GROUPEMENT D'INTÉRÊT ÉCONOMIQUE DES GREFFES DE TRIBUNAUX DE COMMERCE DE FRANCE. The record states that the sanction concerns a violation, but no further details are provided.FRCNILGDPR€250,000
04 Feb 2026MediaLab.AI, Inc.The ICO imposed a 247,590 GBP penalty on MediaLab.AI, Inc. for breaches of Articles 5(1)(a), 6, 8 and 35 UK GDPR. The company operated Imgur in the UK and allowed children under 13 to access the platform without a reliable way to verify age or obtain the required parental consent. It also failed to carry out a DPIA before high-risk processing involving children under 18.GBICOGDPR€287,000
20 Oct 2023Outsource Strategies LtdOutsource Strategies Ltd made 1,346,503 unwanted marketing calls between 11 February 2021 and 22 March 2022 to numbers registered with the TPS. The ICO received 74 complaints, including reports of repeated calls despite requests to stop and aggressive caller behaviour.GBICOGDPR€275,000
05 Dec 2024SOCIETE DEVELOPPANT ET COMMERCIALISANT UNE EXTENSION POUR NAVIGATEURThe CNIL imposed an administrative fine of EUR 240,000 on SOCIETE DEVELOPPANT ET COMMERCIALISANT UNE EXTENSION POUR NAVIGATEUR and issued an injunction. The case concerns identified regulatory breaches.FRCNILGDPR€240,000
27 Apr 2023Benetton Group S.r.l.Benetton Group S.r.l. was fined €240,000 by the Italian data protection authority, Garante. The authority found violations in the processing of personal data for marketing and profiling purposes, including the retention of former customers’ data for more than 10 years without proper justification.ITGaranteGDPR€240,000
05 Dec 2024KASPRThe CNIL imposed an administrative fine of €240,000 on KASPR on 5 December 2024. The case concerned data scraping and multiple GDPR breaches, including lack of lawful basis, poor transparency, excessive retention, and failure to respect access rights.FRCNILGDPR€240,000
27 Apr 2023Ama S.p.a.Ama S.p.a. was fined €239,000 by the Garante for the unlawful processing and dissemination of personal health data concerning women who had terminated pregnancies. The identities were displayed on crosses at a cemetery, resulting in an unlawful disclosure of sensitive data.ITGaranteGDPR€239,000
29 Apr 2024Dane anonimowe (A. Sp. k. z siedzibą w T.)UODO imposed a PLN 238,345 administrative fine on A. Sp. k. for failing to implement appropriate technical and organizational measures proportionate to the risk of data processing, including the use of external storage media. The authority also found a lack of regular testing, measurement, and evaluation of the effectiveness of the security measures in place.PLUODOGDPR€55,103
24 Jun 2010Enterprise Group s.r.l.Enterprise Group s.r.l. was fined EUR 238,000 by the Garante. The authority found that the company failed to provide timely information to data subjects and sent unsolicited marketing communications without prior consent.ITGaranteGDPR€238,000