Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
17 Apr 2026Framos Italia s.r.l. in liquidazioneFramos Italia s.r.l. in liquidation was fined EUR 5,000 by the Garante. The authority found that former employees’ email accounts were not deactivated and that information on data processing was not clear and comprehensive.ITGaranteGDPR€5,000
17 Apr 2026Poste Italiane S.p.a. e PostePay S.p.a.Poste Italiane S.p.a. and PostePay S.p.a. were sanctioned for unlawful processing of personal data in their Bancoposta and PostePay apps on Android devices. The apps required users to authorize access to data to detect malicious software, which breached GDPR principles.ITGaranteGDPR€6,624,000
17 Apr 2026Comune di VeneziaThe Municipality of Venice was fined €3,000 by the Garante for failing to ensure the required transparency in data processing. The authority found a breach of the GDPR principles of lawfulness, fairness, and transparency.ITGaranteGDPR€3,000
17 Apr 2026Pak StorePak Store was fined EUR 2,000 by the Garante for using a CCTV camera without the required signage and without the necessary authorization from the Labour Inspectorate. The authority found a breach of the information obligations under GDPR Article 13.ITGaranteGDPR€2,000
17 Apr 2026The European House - Ambrosetti S.p.A.The European House - Ambrosetti S.p.A. was fined by Garante 85,000 EUR for a data breach. The incident involved unauthorized access and exfiltration of personal and authentication data affecting an unspecified number of individuals.ITGaranteGDPR€85,000
17 Apr 2026Comune di CogoletoComune di Cogoleto was fined EUR 4,000 by the Garante for failing to ensure transparency in data processing. The authority also found that no data protection impact assessment had been carried out, breaching the principles of lawfulness, fairness, and transparency.ITGaranteGDPR€4,000
17 Apr 2026Io e te s.r.l.s.Io e te s.r.l.s. was fined EUR 2,000 by the Italian Garante. The case concerned improper use of a surveillance camera that enabled remote viewing through a mobile application without proper authorization.ITGaranteGDPR€2,000
17 Apr 2026Carlo Maria Antonio ParisiThe Garante fined Carlo Maria Antonio Parisi, owner of the online newspaper “giornalistitalia.it”, EUR 2,500. The authority found inadequate technical and organizational measures to support data subject rights and delays in handling requests without undue delay.ITGaranteGDPR€2,500
17 Apr 2026Ausl ModenaAusl Modena was fined by the Garante in the amount of 3,500 EUR for creating duplicate patient records. The case involved processing health data without proper transparency and compliance with data protection rules.ITGaranteGDPR€3,500
17 Apr 2026Comune di Mazara del ValloThe Garante fined Comune di Mazara del Vallo 6,000 EUR for violations related to the online publication of personal data. The case concerned the improper disclosure of personal information through online publication.ITGaranteGDPR€6,000
17 Apr 2026Azienda USL ModenaAzienda USL Modena was fined by the Garante in the amount of 10,000 EUR for a data breach caused by a ransomware attack. The authority found a breach of GDPR data security obligations.ITGaranteGDPR€10,000
17 Apr 2026Provvedimento del 17 aprile 2026 [10254325]The supervisory authority found that a video surveillance system with 25 cameras operated without the required informational signage. The breach concerned GDPR information obligations.ITGaranteGDPR€3,000
17 Apr 2026Associazione Movimento Cinque Stelle SiciliaThe Garante fined Associazione Movimento Cinque Stelle Sicilia 5,000 EUR for failing to adopt adequate technical and organizational measures to facilitate the exercise of data protection rights. The authority also found that requests were not addressed without undue delay.ITGaranteGDPR€5,000
17 Apr 2026Sicra PressThe Garante imposed a 2,000 EUR fine on Sicra Press for using non-anonymized data in articles related to judicial matters. The authority found a breach of data protection rules.ITGaranteGDPR€2,000
17 Apr 2026Istituto “Ancelle della Compagnia della Regina dei Gigli”The Garante fined the school EUR 4,000 for processing students’ personal data without a proper legal basis. The authority found breaches of lawfulness, fairness, and transparency.ITGaranteGDPR€4,000
16 Apr 2026An unnamed energy companyHungary’s data protection authority, NAIH, imposed a HUF 75 million GDPR fine in case NAIH-19-18/2024 on an unnamed energy company. The case concerned data processing for a nationwide LED replacement program and identified serious privacy compliance failures.HUNemzeti Adatvédelmi és Információszabadság HatóságGDPR€205,000
15 Apr 2026Javno komunalno podjetjeThe Slovenian Information Commissioner fined a municipal utility company EUR 6,000 for continuously and indiscriminately collecting employees’ location data via GPS trackers in company vehicles. The authority found no valid legal basis under GDPR Article 6 and also noted inadequate employee notice and a failure to assess legitimate interest separately for each processing purpose.SIInformacijski pooblaščenecGDPR€6,000
13 Apr 2026Dane anonimowe (Pana L. A. prowadzącego działalność gospodarczą pod nazwą: A.)UODO issued a reprimand to the controller, two agents and a sub-agent, and imposed an administrative fine on the sub-agent. The case concerned GDPR breaches related to processing security, verification of processors, and the principles of confidentiality and accountability.PLUODOGDPR€2,385
07 Apr 2026Dane anonimowe (Wspólnotę Mieszkaniową K.)The UODO imposed an administrative fine on K. Housing Community for failing to report a personal data breach without undue delay, and no later than 72 hours after becoming aware of it. The case concerns the obligation to notify the President of the UODO within the statutory deadline.PLUODOGDPR€1,135
03 Apr 2026BLUE PROJECTS S.R.L.In March 2026, the Romanian supervisory authority ANSPDCP completed an investigation into BLUE PROJECTS S.R.L. and found a GDPR violation. The company was fined EUR 2,500.ROANSPDCPGDPR€2,500