Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
01 Apr 2025BitdefenderBitdefender received a GDPR fine of EUR 10,000 from the Romanian data protection authority. The sanction followed an investigation completed in April 2025 after a data breach notification, with the authority citing inadequate technical and organizational security measures.ROAutoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal€10,000
01 Apr 2025EL LEÓN DE EL ESPAÑOL PUBLICACIONES, S.A.The AEPD fined EL LEÓN DE EL ESPAÑOL PUBLICACIONES, S.A. 20,000 EUR for publishing unnecessary personal data in a news article. A video in the article revealed the identity of a minor, which was considered disproportionate and unnecessary for the informational purpose.ESAEPDGDPR€20,000
01 Apr 2025Anonymised (IDPC 0476_001)The IDPC imposed a EUR 20,000 fine on Anonymised (IDPC 0476_001) for breaches of several GDPR provisions. The case concerned lawfulness, fairness and transparency, purpose limitation, information duties, the right to rectification, and the appointment of a data protection officer.MTIDPCGDPR€20,000
31 Mar 2025BAR EL ANDÉN M. ROJO, S.L.The entity was fined for recording audio and video in the establishment without proper informational signage. The authority considered this a breach of data protection requirements.ESAEPDGDPR€1,000
30 Mar 2025MODEL REYNA, C.B.MODEL REYNA, C.B. was fined by the AEPD EUR 3,000 for failing to provide access to personal data and related information. The authority found a breach of Article 58.1 of the GDPR.ESAEPDGDPR€3,000
27 Mar 2025NOVATES ALIMENTACIÓN MADRID, S.L.NOVATES ALIMENTACIÓN MADRID, S.L. was fined by the AEPD for a personal data protection breach involving the improper handling of video surveillance footage. The footage was shared via WhatsApp without adequate security measures, increasing the risk of unauthorized access.ESAEPDGDPR€20,000
27 Mar 2025Azienda sanitaria territoriale di MacerataAzienda sanitaria territoriale di Macerata was fined 5,000 EUR by the Garante for failing to comply with data access requests and for breaches of data protection rules. The case concerned the processing of health data and inadequate security measures.ITGaranteGDPR€5,000
27 Mar 2025Comune di PolinoComune di Polino was fined by the Garante for breaches of transparency and information obligations in data processing under GDPR Articles 6, 12, 13, and 14. The case concerned insufficient information provided to data subjects about how their personal data was processed.ITGaranteGDPR€2,500
27 Mar 2025Comune di MilazzoThe Garante fined the Comune di Milazzo €3,600 for failing to provide adequate data protection information on its website. The authority found a breach of GDPR principles of lawfulness, fairness, and transparency.ITGaranteGDPR€3,600
27 Mar 2025AFK Letters Co LtdBetween January and September 2023, AFK Letters Co Ltd made 95,277 spam calls, leading to multiple complaints to the ICO and TPS. The company did not provide evidence that the called numbers had consented to receiving calls. The ICO imposed a £90,000 fine.GBICOGDPR€108,000
27 Mar 2025Provvedimento del 27 marzo 2025 [10140216]The Garante fined Powerfit, Soleo, and Zero Due Villa for sending promotional SMS messages without the recipients’ consent. The messages also did not provide an opt-out mechanism, which breached GDPR requirements.ITGaranteGDPR€6,000
27 Mar 2025Corriere del Giorno 1947 Media Group Soc. Coop. ArlThe Garante imposed a fine of 6,000 EUR on Corriere del Giorno 1947 Media Group Soc. Coop. Arl for violations related to the right to be forgotten. The authority found that certain articles were no longer relevant and were not in the public interest.ITGaranteGDPR€6,000
27 Mar 2025Comune di Palma di MontechiaroThe Municipality of Comune di Palma di Montechiaro was fined EUR 3,000 by the Italian data protection authority, Garante. The sanction concerned the failure to communicate the contact details of its Data Protection Officer to the authority, as required by Article 37 GDPR.ITGaranteGDPR€3,000
27 Mar 2025SOCIETE DE CONSEILS POUR LES AFFAIRES ET AUTRES CONSEILS DE GESTION (procédure simplifiée)The CNIL imposed an administrative fine of EUR 6,000 on SOCIETE DE CONSEILS POUR LES AFFAIRES ET AUTRES CONSEILS DE GESTION. The case was handled under a simplified procedure.FRCNILGDPR€6,000
27 Mar 2025Istituto di Istruzione Superiore “P. 96012510796The Garante imposed a fine on an educational institution for breaches of GDPR Articles 5, 6, and 9 in connection with data processing activities. The case concerned deficiencies in the lawful basis and principles of processing, including special-category data.ITGaranteGDPR€4,000
26 Mar 2025Advanced Computer Software Group LimitedThe UK Information Commissioner's Office fined Advanced Computer Software Group Limited, Advanced Health and Care Limited, and Aston Midco Limited a total of £3,076,320. The penalty related to serious UK GDPR Article 32(1) security failings linked to a ransomware attack and data breach affecting healthcare services.GBInformation Commissioner's OfficeGDPR€3,678,000
26 Mar 2025Advanced Computer Software Group LimitedThe UK Information Commissioner’s Office (ICO) fined Advanced Computer Software Group Limited £3,070,000 for security failings. The issues put the personal information of 79,404 people at risk. The case highlights inadequate safeguards over processed personal data.GBICOGDPR€3,671,000
25 Mar 2025NTT DATA ROMÂNIA S.A.NTT DATA ROMÂNIA S.A. was fined by ANSPDCP in the amount of EUR 25,000 for GDPR violations. The case concerned non-compliance with personal data protection requirements.ROANSPDCPGDPR€25,000
25 Mar 2025B.B.B.B.B.B. was fined EUR 1,000 by the AEPD for lacking an adequate data processing protocol. The authority also found that individuals were not properly informed about the processing of their personal data, in breach of GDPR Articles 5(1)(c) and 13.ESAEPDGDPR€1,000
25 Mar 2025Star Delta Electrical ServicesThe Jersey Data Protection Authority fined Jon Peacock t/a Star-Delta Electrical Services £4,000. The case arose from a client complaint concerning the handling of personal data by the sole trader. The penalty was issued under the Data Protection (Jersey) Law 2018.JEJOICGDPR€4,787