Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
28 Jan 2022IBERCAJA BANCO, S.A.IBERCAJA BANCO, S.A. was fined by the AEPD EUR 100,000 for unlawfully processing personal data linked to a family inheritance matter. The breach included opening a bank account for a minor without consent and disclosing personal data to third parties without authorization.ESAEPDGDPR€100,000
06 May 2019ENDESA ENERGÍA XXI, S.L.U.ENDESA ENERGÍA XXI, S.L.U. was fined by the AEPD 100,000 EUR for a data protection breach. An agent mistakenly altered a contract, replacing the complainant’s data with that of a third party.ESAEPDGDPR€100,000
17 Mar 2025Ministra CyfryzacjiUODO imposed an administrative fine of 100,000 PLN on the Minister of Digital Affairs. The breach concerned Article 6(1) and Article 5(1)(a) of Regulation 2016/679.PLUODOGDPR€23,887
18 Jul 2023Tiscali Italia S.p.A.Tiscali Italia S.p.A. was fined EUR 100,000 by the Garante for sending promotional SMS messages to existing customers without their consent. The authority also found inadequate data retention policies and insufficient transparency in the privacy notices.ITGaranteGDPR€100,000
09 Feb 2012Banca popolare Sant'Angelo S.C.P.A.The bank was fined for deploying a biometric data collection system without proper notification and without complying with data protection principles. The authority found that the processing did not meet privacy compliance requirements.ITGaranteGDPR€100,000
29 Apr 2025Energia Verde S.p.A.Energia Verde S.p.A. was fined EUR 100,000 by the Garante for making unsolicited promotional calls without a legal basis. The authority also found that the company did not adequately respond to data subjects' requests, indicating failures in data protection compliance.ITGaranteGDPR€100,000
20 Dec 2023Ministra ZdrowiaThe President of the Personal Data Protection Office imposed an administrative fine of 100,000 PLN on Ministra Zdrowia. The authority found unlawful processing of personal data, including special-category data without a legal basis, and a failure to implement technical and organizational measures appropriate to the processing risk. The affected individual was also not provided with the information required under Article 33(3)(c) and (d) of the GDPR.PLUODOGDPR€23,035
16 Jan 2024Skean Homes LtdSkean Homes Ltd was fined by the ICO after it was found to have instigated 614,342 unsolicited direct marketing calls between 2 March 2022 and 31 May 2022. The calls promoted energy grants for resin driveways and generated 31 complaints through the ICO and TPS reporting tools. The ICO found breaches of regulations 21 and 24 of PECR.GBICOePrivacy€116,000
31 May 2024MEDIOS DE PREVENCIÓN EXTERNOS, S.L.MEDIOS DE PREVENCIÓN EXTERNOS, S.L. was fined by the AEPD for leaving medical documentation of police and civil guard agents in a public place. The authority found this to be a breach of data protection rules.ESAEPDGDPR€100,000
24 Aug 2020Głównego Geodetę KrajuUODO imposed a fine of PLN 100,000 on the Chief Surveyor of Poland. The authority found a breach of the lawfulness principle in personal data processing due to the intentional disclosure, without a legal basis, of land and mortgage register numbers obtained from the land and building records.PLUODOGDPR€22,735
01 Jan 2025STRATESYS TECHNOLOGY SOLUTIONS, S.L.STRATESYS TECHNOLOGY SOLUTIONS, S.L. was fined EUR 100,000 by the AEPD for breaching Article 5(1)(f) of the GDPR. The case concerned a failure to protect the integrity and confidentiality of personal data.ESAEPDGDPR€100,000
18 Sept 2025SOCIETE EXPLOITANT UN GRAND MAGASINCNIL imposed an administrative fine of EUR 100,000 on SOCIETE EXPLOITANT UN GRAND MAGASIN. The case concerns a breach of rules supervised by CNIL.FRCNILGDPR€100,000
11 Dec 2018Anonymizováno (ÚOOÚ UOOU-00313/19-23)The supervisory authority found that the entity failed to implement adequate technical and organizational measures to secure personal data processing and did not properly inform data subjects. Personal data of loan applicants were retained longer than necessary, in breach of the GDPR.CZUOOUGDPR€3,869
11 Apr 2013PLD srlPLD srl was fined €100,000 by the Italian Garante. The company registered numerous phone cards to unaware third parties without providing the required data protection information.ITGaranteGDPR€100,000
13 May 2021Artemisia s.p.a.Artemisia s.p.a. was fined EUR 100,000 by the Garante for GDPR breaches in data processing. The violations concerned consent, information notices, and the handling of health data.ITGaranteGDPR€100,000
08 Aug 2023VODAFONE ESPAÑA, S.A.U.The AEPD fined VODAFONE ESPAÑA, S.A.U. 100,000 EUR for processing personal data without proper authorization. The case involved unsolicited marketing calls and messages sent to a complainant who had no commercial relationship with the company.ESAEPDGDPR€100,000
10 Jul 2020VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD EUR 100,000 for repeatedly sending a former customer electronic notices about invoice availability. The authority found that the processing lacked a valid legal basis under GDPR Article 6.1.ESAEPDGDPR€100,000
11 Apr 2024Olimpia S.r.l.Olimpia S.r.l. was fined for making unsolicited promotional calls without prior consent and for using numbers listed in the Public Opposition Register. The conduct breached GDPR requirements on data protection and security measures.ITGaranteGDPR€100,000
15 Sept 2022Regione LazioThe Garante imposed a 100,000 EUR fine on Regione Lazio for improper processing of health data in the SIPSOweb system. The authority found that sensitive health information was processed without a proper legal basis and with incorrect role designation.ITGaranteGDPR€100,000
14 Feb 2022COMERCIALIZADORA REGULADA, GAS & POWER, S.A.The company sent a customer's electricity supply contract containing personal data to an incorrect address. This breached data protection principles and led to a fine by the AEPD.ESAEPDGDPR€100,000