Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
15 Oct 2024Quick Tax Claims LimitedThe ICO found that Quick Tax Claims Limited sent 7,863,547 unlawful text messages over one month, generating 66,793 complaints. In 93% of complaints, recipients said there was no opt-out option, and the company had bought personal data from suppliers without valid consent.GBICOGDPR€143,000
01 Jan 2024DIGI SPAIN TELECOM, S.L.DIGI SPAIN TELECOM, S.L. was fined by the AEPD 120,000 EUR for a data protection breach involving unauthorized SIM card duplication. The incident enabled fraudulent activity, and the authority found that the company had not implemented sufficient preventive measures.ESAEPDGDPR€120,000
31 Mar 2021Anonymizováno (ÚOOÚ UOOU-04077/20-13)The entity was fined for processing personal data from public registers without a legal basis and for failing to respond to a data subject's erasure request. The case highlights deficiencies in lawful processing and in handling data subject rights.CZUOOUGDPR€4,590
21 Mar 2024Regione LazioThe Garante fined Regione Lazio EUR 120,000 for inadequate security measures that led to attempted unauthorized access to user accounts. The authority found a breach of GDPR requirements on data protection and processing security.ITGaranteGDPR€120,000
15 Dec 2022Assiteca S.p.A.Assiteca S.p.A. was fined EUR 120,000 by the Garante for violations related to the processing of personal data for marketing purposes. The authority also found inadequate responses to data subject requests. The case highlights the need for proper handling of individual rights and GDPR-compliant marketing practices.ITGaranteGDPR€120,000
04 Oct 2025OVH HISPANO, S.L.U.OVH HISPANO, S.L.U. was fined by the AEPD 120,000 EUR for a data protection breach. Confidential emails and documents of third parties were improperly shared due to inadequate data protection measures.ESAEPDGDPR€120,000
16 Jan 2020VODAFONE ESPAÑA SAUVODAFONE ESPAÑA SAU was fined 120,000 EUR by the AEPD for unlawful processing of personal data. The case involved threatening to include a minor's data in a credit file over an alleged unpaid debt.ESAEPDGDPR€120,000
18 Dec 2025Pioneer Hi-Bred Italia Sementi s.r.l.Pioneer Hi-Bred Italia Sementi s.r.l. was fined by the Garante 120,000 EUR for installing telematic devices in company vehicles to monitor employees' driving behavior. The authority found that the processing lacked proper data protection safeguards and privacy information.ITGaranteGDPR€120,000
20 Dec 2019Anonymizováno (ÚOOÚ UOOU-00136/19-31)The company was fined for disseminating commercial communications without a legal basis and without proper labeling. The authority found a breach of Czech rules on information society services.CZUOOUePrivacy€4,716
30 Nov 2023Dane anonimowe (L. Sp. z o.o. z siedzibą we W.)UODO imposed an administrative fine of PLN 117,900 on L. Sp. z o.o. for failing to implement appropriate technical and organizational measures proportionate to the risk of data processing. The authority found deficiencies in ensuring system availability, resilience, and the ability to quickly restore access to personal data after a physical or technical incident.PLUODOGDPR€27,110
21 Mar 2013Giant s.r.l.Giant s.r.l. was fined 114,000 EUR by the Garante for the unauthorized registration of numerous phone cards to third parties without their knowledge. The authority found this conduct to be in breach of data protection rules.ITGaranteGDPR€114,000
24 Jul 2014Easy Call srlEasy Call srl was fined EUR 112,000 by the Garante for making unsolicited promotional calls. The company contacted individuals listed in the opposition register, breaching data protection rules.ITGaranteGDPR€112,000
14 Jun 2018Faiella Nicola s.r.l.Faiella Nicola s.r.l. was fined EUR 112,000 by the Garante for improper processing of personal data using geolocation and video surveillance systems. The authority found that the company did not comply with data protection requirements when deploying these tools.ITGaranteGDPR€112,000
13 Nov 2023Rompetrol Downstream SRLRompetrol Downstream SRL was fined EUR 110,000 by ANSPDCP for failing to ensure the security of personal data. The authority found a breach of Article 32 GDPR, which requires appropriate technical and organizational measures.ROANSPDCPGDPR€110,000
09 Dec 2021Limerick City and County CouncilThe Irish DPC imposed a fine of EUR 110,000 on Limerick City and County Council in inquiry 03/SIU/2018. The penalty has been collected.IEDPCGDPR€110,000
11 Apr 2013Zeno VincoZeno Vinco was fined by the Garante for registering SIM cards to 36 individuals without their knowledge. The case involved a breach of data protection rules.ITGaranteGDPR€108,000
29 Dec 2023SOCIETE PERMETTANT D'EFFECTUER DES PAIEMENTS EN LIGNEA fine of EUR 105,000 was imposed by the CNIL. The case concerns a breach of personal data protection rules.FRCNILGDPR€105,000
11 Dec 2025ZMLUK LimitedZMLUK Limited received an MPN from the ICO for sending unsolicited emails promoting energy-saving products. The case concerns a breach of electronic marketing rules and should be reviewed for compliance with applicable consent requirements.GBICOGDPR€119,000
18 Oct 2023Dane anonimowe (J. Towarzystwo Ubezpieczeń S.A. z siedzibą w N.)UODO imposed an administrative fine of PLN 103,752 on J. Towarzystwo Ubezpieczeń S.A. The authority found that the company failed to notify the supervisory authority of a personal data breach without undue delay.PLUODOGDPR€23,362
18 Apr 2013Itel s.r.l. UnipersonaleItel s.r.l. Unipersonale was fined EUR 102,000 by the Garante for improper processing of personal data. The case involved registering phone cards to third parties without their knowledge, in breach of privacy rules.ITGaranteGDPR€102,000