Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
02 Jul 2015Lycamobile s.r.l.Lycamobile s.r.l. was fined EUR 102,000 by the Garante for failing to provide requested information on the retention of telephone and telematic traffic data. The case concerned a breach of data protection rules.ITGaranteGDPR€102,000
02 Jul 2025Hrvatski ured za osiguranjeAZOP imposed a 101,000 euro fine on Hrvatski ured za osiguranje (HUO) after finding that it had not implemented adequate technical and organizational measures to protect personal data. The decision followed an investigation into a major data leak affecting about 1.2 million vehicle owners in Croatia.HRAZOPGDPR€101,000
31 Jan 2024EDITEUR DE SITE WEB PROPOSANT AUX PARTICULIERS DE PUBLIER OU CONSULTER DES ANNONCES IMMOBILIERES ET AUTRES SERVICESCNIL imposed an administrative fine of EUR 100,000 on EDITEUR DE SITE WEB PROPOSANT AUX PARTICULIERS DE PUBLIER OU CONSULTER DES ANNONCES IMMOBILIERES ET AUTRES SERVICES. The case concerns identified breaches of rules supervised by the CNIL.FRCNILGDPR€100,000
16 May 2023UK Direct Business Solutions LimitedUK Direct Business Solutions Limited was fined by the ICO for making 410,369 unsolicited marketing calls to businesses registered with the CTPS or TPS. The calls were made between 1 March 2020 and 31 October 2021 and breached rules on telephone marketing.GBICOGDPR€115,000
17 Aug 2021BANCO BILBAO VIZCAYA ARGENTARIA, S.A.Banco Bilbao Vizcaya Argentaria, S.A. was fined by the AEPD for sending unsolicited SMS messages to the complainant's mobile phone. The company also failed to remove the number from its database after the request, which constituted a data protection breach.ESAEPDGDPR€100,000
17 Apr 2024BANCO BILBAO VIZCAYA ARGENTARIA, S.A.BBVA was fined EUR 100,000 by the AEPD for processing a payment to a new account without the account holder’s explicit consent. The authority found this conduct to be a breach of GDPR Article 6.ESAEPDGDPR€100,000
04 Mar 2020Fotó készítése és közzététele Facebookon hozzájárulás nélkülThe authority found unlawful processing and publication of personal data without a valid legal basis. A fine was imposed and the image had to be deleted from Facebook.HUNAIHGDPR€299
12 Jun 2015ALPHA BANKThe HDPA imposed a fine of EUR 100,000 on ALPHA BANK for the unlawful provision of data from the TIRESIAS databases. The case concerned a breach of rules on the processing and disclosure of personal data.GRHDPAGDPR€100,000
11 Apr 2024Facile.Energy S.r.l.Facile.Energy S.r.l. was fined EUR 100,000 by the Garante for making unsolicited promotional calls without prior consent and activating energy supplies without a request from the customer. The authority found that these practices breached GDPR rules on data protection and security measures.ITGaranteGDPR€100,000
14 May 2021SIA "SS"DVI imposed a fine of EUR 100,000 on SIA "SS". According to the record, the sanction was later annulled.LVDVIGDPR€100,000
05 Oct 2017Regione autonoma Valle d'AostaRegione autonoma Valle d'Aosta was fined by the Garante 100,000 EUR for publishing a regional council resolution on its institutional website that contained an employee’s personal data. The document included professional evaluations and transfer details.ITGaranteGDPR€100,000
25 Jun 2025Vodafone-PanafonVodafone-Panafon was fined by the HDPA for failing to notify a data breach in a timely manner. The authority cited a violation of Article 12 of Law L.3471/2006.GRHDPAePrivacy€100,000
16 Dec 2021Ubi Banca S.p.a., ora Intesa Sanpaolo S.p.a.Ubi Banca S.p.a., now Intesa Sanpaolo S.p.a., was fined EUR 100,000 by the Italian Garante. The breach involved sending a letter with the phrase “credito anomalo Chieti” visible on the envelope, which could disclose the recipient’s financial information to third parties.ITGaranteGDPR€100,000
15 Dec 2022Altroconsumo Edizioni S.r.lAltroconsumo Edizioni S.r.l was fined EUR 100,000 by the Garante for making unsolicited promotional calls without a proper legal basis. The authority also found that the company failed to provide adequate information and to obtain free and specific consent from data subjects.ITGaranteGDPR€100,000
28 Jul 2022Intesa Sanpaolo S.p.a.Intesa Sanpaolo S.p.a. was fined EUR 100,000 by Garante after an employee accessed a customer's financial data without authorization. The data was then used in judicial proceedings. The authority found that the bank had not implemented adequate data protection measures.ITGaranteGDPR€100,000
22 Feb 2024Italiaonline S.p.A.Italiaonline S.p.A. was fined by the Garante 100,000 EUR for conducting direct email marketing campaigns without proper consent. The authority also found inadequate information about data processing activities shared with Google LLC.ITGaranteGDPR€100,000
25 Sept 2025RCS MediaGroup S.p.a.RCS MediaGroup S.p.a. was fined by the Italian data protection authority, Garante, in the amount of EUR 100,000. The case concerned the publication of images of a person in a private setting without consent, which infringed privacy rights.ITGaranteGDPR€100,000
12 Jun 2023Piraeus Bank S.A.Piraeus Bank S.A. was fined by the HDPA in the amount of 100,000 EUR for failing to implement appropriate technical and organizational measures. The authority found that the bank did not ensure data protection by design and by default.GRHDPAGDPR€100,000
02 Jul 2020Głównego Geodetę Kraju z siedzibą w Warszawie przy ul.UODO imposed a fine of PLN 100,000 on the Chief Surveyor of Poland based in Warsaw. The sanction concerned failure to provide access during an inspection to rooms, equipment and tools used for personal data processing, as well as access to personal data and information.PLUODOGDPR€22,351
07 Jul 2021Nordbornholms Byggeforretning ApSNordbornholms Byggeforretning ApS was fined 100,000 DKK by Datatilsynet. The company unlawfully disclosed information about a former employee's criminal activities to customers without a legal basis.DKDatatilsynetGDPR€13,448