Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
30 Apr 2025Anonymisé (CNPD decision-03-fr-2025)The company did not maintain a complete record of processing activities as required by Article 30 GDPR. CNPD imposed an administrative fine of €11,964.LUCNPDGDPR€11,964
30 Apr 2025BITDEFENDER SRLIn April 2025, the Romanian authority ANSPDCP completed an investigation into BITDEFENDER SRL and found a GDPR violation. The company was fined EUR 10,000.ROANSPDCPGDPR€10,000
29 Apr 2025Comune di San Francesco al CampoThe Garante imposed a fine of 1,200 EUR on Comune di San Francesco al Campo for violations related to the publication of personal data on its institutional website. The data were subsequently removed.ITGaranteGDPR€1,200
29 Apr 2025Comune di BolognaThe Garante imposed a fine of 40,000 EUR on Comune di Bologna for breaches of data protection principles. The case concerned non-compliance with requirements on lawfulness, fairness, transparency, and data minimization.ITGaranteGDPR€40,000
29 Apr 2025Energia Verde S.p.A.Energia Verde S.p.A. was fined EUR 100,000 by the Garante for making unsolicited promotional calls without a legal basis. The authority also found that the company did not adequately respond to data subjects' requests, indicating failures in data protection compliance.ITGaranteGDPR€100,000
29 Apr 2025Ordine degli Psicologi della Regione LombardiaThe Garante fined the Ordine degli Psicologi della Regione Lombardia EUR 30,000 for a data breach. The incident exposed personal and sensitive data of about 15,000 individuals, including information covered by professional secrecy and special categories of data.ITGaranteGDPR€30,000
29 Apr 2025Versilmagra Immobiliare di Robertelli Davide & C. S.a.s.Versilmagra Immobiliare was fined EUR 2,000 by the Garante. The authority found that the company sent unsolicited communications via WhatsApp without proper consent and did not facilitate the exercise of data subject rights.ITGaranteGDPR€2,000
29 Apr 2025Cooperativa Sociale QuadrifoglioThe Garante imposed a fine of EUR 20,000 on Cooperativa Sociale Quadrifoglio for violations related to data processing. The case concerned non-compliance with personal data protection requirements.ITGaranteGDPR€20,000
29 Apr 2025Energia Pulita S.r.l.Energia Pulita S.r.l. was fined by the Garante for improper handling of personal data in telemarketing activities. The authority also noted failure to cooperate with the supervisory authority and incorrect identification of roles in data processing.ITGaranteGDPR€10,000
29 Apr 2025Regione Emilia RomagnaThe Garante fined Regione Emilia Romagna EUR 15,000 for violations related to the processing of personal data for official statistical purposes. The authority found incorrect application of data protection principles and measures.ITGaranteGDPR€15,000
29 Apr 2025Comune di NoliComune di Noli was fined EUR 2,000 by the Garante for failing to ensure lawful, fair, and transparent processing of personal data. The authority also found a breach of data minimization because unauthorized access to unredacted images was possible through an online portal.ITGaranteGDPR€2,000
29 Apr 2025Tirrenia Hospital S.r.l.Tirrenia Hospital S.r.l. was fined by the Garante EUR 2,000 for breaching the data processing principles set out in GDPR Article 5. The case concerned processing in the healthcare sector, where a particularly high level of compliance is required.ITGaranteGDPR€2,000
29 Apr 2025Regione LombardiaThe Garante fined Regione Lombardia 50,000 EUR for violations related to the processing of personal data. The authority cited inadequate technical and organizational measures to protect data, as well as improper handling of employee metadata and internet navigation logs.ITGaranteGDPR€50,000
29 Apr 2025Ordine professionale degli psicologi della LombardiaOn 2025-04-29, the Italian Data Protection Authority fined the Ordine professionale degli psicologi della Lombardia EUR 30,000. The sanction concerned breaches of Articles 5(1)(f) and 32 GDPR following a data breach and the failure to implement adequate security measures.ITGarante per la protezione dei dati personaliGDPR€30,000
28 Apr 2025Xiting ROM SRLIn April 2025, ANSPDCP completed an investigation at Xiting ROM SRL and found violations of GDPR provisions. As a result, a fine of EUR 1,000 was imposed.ROANSPDCPGDPR€1,000
25 Apr 2025SC Travel Planner SRLSC Travel Planner SRL was fined EUR 5,000 by ANSPDCP for breaching Article 15 of the GDPR. The case concerned the improper handling of a data subject access request.ROANSPDCPGDPR€5,000
25 Apr 2025SC Travel Planner SRLSC Travel Planner SRL was fined EUR 1,000 by ANSPDCP for breaching Article 33 of the GDPR. The case concerned failure to notify a personal data breach to the supervisory authority.ROANSPDCPGDPR€1,000
24 Apr 2025Darian Bishop trading as ECO4UBetween 9 January 2023 and 9 October 2023, 194,110 unsolicited direct marketing calls were made to subscribers registered with the TPS who had not indicated consent to receive such calls. The conduct generated 21 complaints to the Commissioner and the TPS, leading to an ICO fine.GBICOGDPR€58,480
24 Apr 2025Dante International SAIn April 2025, ANSPDCP completed an investigation into Dante International SA and found violations of GDPR provisions. As a result, a fine of 10,000 EUR was imposed.ROANSPDCPGDPR€10,000
23 Apr 2025MetaThe European Commission fined Meta EUR 200 million for breaching the Digital Markets Act. The sanction concerns Meta’s “consent or pay” model used for Facebook and Instagram users in Europe.IEEuropean CommissionDMA€200,000,000