Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
04 Jun 2025Comune di LatinaThe Garante fined Comune di Latina EUR 4,000 for violations linked to the activation process for the “Dedicata a te” card. Requiring a payment to avoid cancellation of the benefit raised compliance concerns.ITGaranteGDPR€4,000
04 Jun 2025Istituto d’Istruzione Superiore “Carlo e Nello Rosselli”The Garante imposed a EUR 4,000 fine on Istituto d’Istruzione Superiore “Carlo e Nello Rosselli” for failing to appoint a Data Protection Officer and for delaying notification of the DPO’s contact details to the authority. The authority also found that transparency obligations toward data subjects were not met.ITGaranteGDPR€4,000
03 Jun 2025Spotify ABOn 2025-06-03, Kammarrätten ruled that Spotify AB must pay an administrative fine of 58 million SEK. The case concerned insufficient transparency and inadequate information to data subjects under the GDPR, following an investigation by Integritetsskyddsmyndigheten.SEIntegritetsskyddsmyndigheten (IMY)GDPR€5,309,000
03 Jun 2025VodafoneVodafone was fined EUR 45 million by Germany’s federal data protection authority for GDPR-related privacy violations. The case involved weaknesses in authentication and partner oversight that could allow unauthorized access to customer data and eSIM profiles.DEBundesbeauftragte für den Datenschutz und die Informationsfreiheit (BfDI)GDPR€45,000,000
03 Jun 2025Regione LombardiaThe Italian Data Protection Authority, Garante per la protezione dei dati personali, imposed a EUR 50,000 fine on Regione Lombardia. The case concerned unlawful retention of employees' email metadata, excessive retention of web browsing logs, and prolonged storage of helpdesk ticket data.ITGarante per la protezione dei dati personaliGDPR€50,000
03 Jun 2025B*** Parkraumbewirtschaftung Ges.m.b.H.The company was fined by the Austrian Data Protection Authority (DSB) for failing to cooperate during the investigation. It did not respond to multiple requests for statements or to a summons for an oral hearing, which constitutes a breach of Article 31 GDPR.ATDSBGDPR€16,000
03 Jun 2025Dane anonimowe (Gminny Ośrodek Pomocy Społecznej w K.)UODO imposed an administrative fine of 5,000 PLN on Gminny Ośrodek Pomocy Społecznej w K. The authority found insufficient technical and organizational measures to secure personal data processing, as well as a failure to regularly test and assess the effectiveness of those safeguards.PLUODOGDPR€1,168
01 Jun 2025Călin GeorgescuCălin Georgescu was sanctioned by Romania’s data protection authority after an investigation into his website. Two fines totaling about EUR 10,000 were imposed for installing cookies without consent and collecting personal data without proper notice.ROAutoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter PersonalGDPR€10,000
30 May 2025AG-BROKER ASIGURARE S.R.L.AG-BROKER ASIGURARE S.R.L. was fined 5,000 EUR by ANSPDCP. The sanction concerned the failure to notify a personal data security breach.ROANSPDCPGDPR€5,000
29 May 2025IMMUCURA MED, S.L.IMMUCURA MED, S.L. was fined EUR 20,000 by the AEPD for failing to provide access to personal data and the information requested by the data protection authority. The conduct was found to breach Article 58(1) of the GDPR.ESAEPDGDPR€20,000
25 May 2025ENTIDAD DE CONSERVACION TORREMIRONAThe entity was fined by the AEPD for operating a video surveillance system that excessively covered public areas. This infringed the privacy of residents and passersby.ESAEPDGDPR€5,000
23 May 2025OCI CINE, S.L.OCI CINE, S.L. was fined EUR 30,000 by the AEPD after an incident in which a user's personal information was auto-filled with another person's details in its app. The authority found a breach of data accuracy and processing security principles.ESAEPDGDPR€30,000
22 May 2025Dumitru Viorel FocșaThe National Supervisory Authority for Personal Data Processing imposed a fine on Dumitru Viorel Focșa for GDPR violations. The case followed a complaint from a data subject.ROANSPDCPGDPR€1,000
21 May 2025Autostrade per l'Italia SpaThe Italian data protection authority fined Autostrade per l'Italia Spa EUR 420,000 for unlawfully processing an employee's personal data. The company used content from her Facebook profile and private Messenger and WhatsApp chats to support disciplinary proceedings and justify her dismissal.ITGarante per la protezione dei dati personaliGDPR€420,000
21 May 2025Data Diggers Market Research SRLData Diggers Market Research SRL was fined EUR 2,000 by ANSPDCP for another violation related to the processing of personal data. The case indicates non-compliance with data protection requirements and calls for a review of processing procedures.ROANSPDCPGDPR€2,000
21 May 2025Data Diggers Market Research SRLThe company was fined EUR 5,000 by ANSPDCP for failing to provide complete information to complainants exercising their right of access to personal data. The case concerns the obligation to respond fully to access requests.ROANSPDCPGDPR€5,000
21 May 2025SILVANERGIA 2022, S.L.SILVANERGIA 2022, S.L. was fined by the AEPD EUR 5,000 for processing personal data without a legal basis, in breach of Article 6(1) GDPR. The case involved misleading a customer into confirming personal data over the phone.ESAEPDGDPR€5,000
21 May 2025Data Diggers Market Research SRLData Diggers Market Research SRL was fined EUR 5,000 by ANSPDCP. The authority found that the company did not provide complainants with complete information when they exercised their right of access to personal data.ROANSPDCPGDPR€5,000
21 May 2025Menarini Silicon Biosystems SpAThe Garante imposed a 21,000 EUR fine on Menarini Silicon Biosystems SpA for violations related to personal data processing. The case involved inadequate safeguards in the use of algorithms to identify at-risk patients and online reports accessible to other patients.ITGaranteGDPR€21,000
21 May 2025NN ΕλληνικήThe Greek Data Protection Authority imposed a €22,000 fine on NN Ελληνική for refusing to provide recorded telephone calls in response to a data subject access request. The case concerns failure to comply with access rights obligations under data protection law.GRΑρχή Προστασίας Δεδομένων Προσωπικού ΧαρακτήραGDPR€22,000