Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
14 Apr 2023Green Network S.p.a.Green Network S.p.a. was fined by the Garante for illegal telemarketing practices in the energy sector. The authority found a breach of data protection principles.ITGaranteGDPR€237,000
12 May 2021xy d.o.o.The company xy d.o.o. was fined by AZOP for failing to implement appropriate technical security measures. This resulted in unauthorized processing of personal data of 28,085 data subjects, indicating a data protection compliance failure.HRAZOPGDPR€30,553
05 Apr 2018I Tel s.r.l.I Tel s.r.l. was fined EUR 230,000 by the Italian data protection authority, Garante. The case concerned the registration of phone cards to 23 individuals without their consent, in breach of data protection rules.ITGaranteGDPR€230,000
21 Feb 2013Elettrodomestici Parise sncElettrodomestici Parise snc was fined 222,000 EUR by the Italian Garante. The company improperly registered numerous phone cards to unaware third parties and then sold them to phone centers, breaching data protection rules.ITGaranteGDPR€222,000
01 Jan 2025Εθνική Τράπεζα της Ελλάδος Α.Ε.The data protection authority imposed a EUR 220,000 fine on Εθνική Τράπεζα της Ελλάδος Α.Ε. for a GDPR violation. The case concerned deficiencies in personal data protection and compliance with GDPR requirements.GRΑρχή Προστασίας Δεδομένων Προσωπικού ΧαρακτήραGDPR€220,000
01 Jan 2024GESTERNOVA, S.A.GESTERNOVA, S.A. was fined by the AEPD in the amount of 220,000 EUR for processing personal data without a valid legal basis. The authority also found that the company failed to provide the required information to the data subject, in breach of GDPR Articles 6(1), 13, and 14.ESAEPDGDPR€220,000
26 Apr 2023CARTONAJES BAÑERES, S.A.CARTONAJES BAÑERES, S.A. was fined by the AEPD 220,000 EUR for processing biometric data without the required data protection impact assessment. The authority also found a failure to comply with data subjects’ access rights.ESAEPDGDPR€220,000
16 Oct 2019Dane anonimowe (S. Sp. z o.o. z siedzibą w P., karę pieniężną w kwocie 201 559,50 PLN)UODO imposed a fine of PLN 201,559.50 on S. Sp. z o.o. for failing to implement appropriate technical and organizational measures. The authority also found that personal data were processed without a lawful basis, which led to the sanction.PLUODOGDPR€46,923
21 Sept 2023F12 Management LtdF12 Management Ltd made 1,346,019 marketing calls to individuals in breach of regulation 21 of PECR. The ICO imposed a £200,000 fine and issued an enforcement notice.GBICOePrivacy€230,000
15 Feb 2023It's OK LimitedBetween 1 July 2019 and 1 June 2020, It's OK Limited made 1,752,149 unsolicited direct marketing calls to subscribers who had been registered with the TPS for at least 28 days. The company had no evidence that the recipients had not objected to receiving such calls, breaching regulation 21 of PECR.GBICOePrivacy€225,000
08 Jun 2020Volt munkavállaló munkavégzési célú elektronikus leveleihez való hozzáféréseThe controller unlawfully denied access to the complainant's archived personal emails from 2018. It also failed to provide transparent information about the actions taken in response to the data subject's request.HUNAIHGDPR€582
01 Jan 2024DIGI SPAIN TELECOM, S.L.DIGI SPAIN TELECOM, S.L. was fined by the AEPD 200,000 EUR for issuing a duplicate SIM card to a third party without the original user's consent. The incident led to unauthorized access to personal and banking data.ESAEPDGDPR€200,000
28 Aug 2024SOCIETE SPECIALISEE DANS LA GESTION DES FLUX DE DONNEES DE SANTEThe CNIL imposed an administrative fine of EUR 200,000 on SOCIETE SPECIALISEE DANS LA GESTION DES FLUX DE DONNEES DE SANTE. The case concerns a breach of data protection rules supervised by the French authority.FRCNILGDPR€200,000
16 Mar 2023VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD 200,000 EUR for failing to implement adequate security measures. A SIM card duplication enabled unauthorized access to a customer’s personal data and financial accounts.ESAEPDGDPR€200,000
12 Oct 2023Onda Più S.r.l.Onda Più S.r.l. was fined EUR 200,000 by the Garante for activating energy supply contracts without customer consent. The authority also found the use of inaccurate and outdated personal data.ITGaranteGDPR€200,000
21 Jun 2021GSMA LTD.GSMA LTD. was fined by the AEPD for requiring biometric data, including passport details and photos, for facial recognition at the Mobile World Congress without a valid legal basis. The authority found a breach of data protection rules.ESAEPDGDPR€200,000
11 Mar 2025UNIÓN DE CRÉDITO PARA LA FINANC. MOB. E INMOB., CREDIFIMO, E.F.C., SAUCREDIFIMO was fined by the AEPD for unlawfully processing personal data by including an individual's data in a credit file without a lawful basis. The authority found a breach of Article 6 of the GDPR.ESAEPDGDPR€200,000
19 Mar 2024DIGI SPAIN TELECOM, S.L.DIGI SPAIN TELECOM, S.L. was fined by the AEPD for failing to verify the identity of a person who obtained a SIM duplicate. This omission led to unauthorized transactions and was treated as a breach of Article 6(1) GDPR.ESAEPDGDPR€200,000
03 Feb 2021Cyberbook ASCyberbook AS was fined 200,000 NOK by Datatilsynet for unlawfully forwarding a former employee's emails without informing them. The authority found breaches of GDPR requirements on legal basis, information duties, and data deletion.NODatatilsynetGDPR€19,316
03 Apr 2023HM HOSPITALES 1989, S.A.HM HOSPITALES 1989, S.A. was fined EUR 200,000 by the AEPD for insufficient security measures in its hospital information system. The authority found a breach of Article 32 GDPR, which requires appropriate technical and organizational safeguards.ESAEPDGDPR€200,000