Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
13 Feb 2025Thomas FeroDr Thomas Fero was fined by the Garante EUR 10,000 for sending patients electoral campaign emails without their consent. The authority found this to be a breach of GDPR rules on personal data processing.ITGaranteGDPR€10,000
13 Feb 2025Claudio BattagliaDr. Claudio Battaglia, an oncologist, was fined for using patient data for electoral propaganda without consent. The case indicates a breach of GDPR principles on lawfulness and purpose limitation.ITGaranteGDPR€10,000
13 Feb 2025MDE – Movimento Diritti Europei s.r.l.s.MDE – Movimento Diritti Europei s.r.l.s. was fined 15,000 EUR by the Garante. The authority found that the company failed to provide shareholders with the information required under GDPR Article 14 and instead referred them to a website that did not contain sufficient details.ITGaranteGDPR€15,000
13 Feb 2025ADVFAST s.r.l.s.ADVFAST s.r.l.s. was fined by the Garante for failing to respond to information requests concerning repeated unsolicited telemarketing calls. The case indicates a failure to cooperate with the supervisory authority.ITGaranteGDPR€2,000
13 Feb 2025Azienda ULSS n. 02573090236The public health company was fined for making a disciplinary proceeding document visible to unauthorized employees. The authority found breaches of GDPR Articles 5 and 6 and Article 2-ter of the Italian Privacy Code.ITGaranteGDPR€4,000
13 Feb 2025D.e.c. soc. coop.The Garante imposed a EUR 20,000 fine on D.e.c. soc. coop. for failing to deactivate an ex-employee's email account after the employment ended. The authority found this conduct breached GDPR principles of fair and transparent processing of personal data.ITGaranteGDPR€20,000
11 Feb 2025Primary Health Care of the Capital AreaThe Icelandic Supervisory Authority imposed an administrative fine on Primary Health Care of the Capital Area for unlawful processing related to the integration of medical record systems. The decision was finalized on 11 February 2025, and the fine amounted to 5,000,000 ISK.ISIcelandic Data Protection AuthorityGDPR€34,100
11 Feb 2025A követeléskezelő társaságNAIH imposed a HUF 10 million fine on a debt collection company for continuing to process personal data after a court declared the debt time-barred. The company ignored the data subject’s deletion request and kept the case active in its system.HUNemzeti Adatvédelmi és Információszabadság HatóságGDPR€24,800
11 Feb 2025AD735 DATA MEDIA ADVERTISING, S.L.AD735 DATA MEDIA ADVERTISING, S.L. was fined by the AEPD 10,000 EUR for sending unsolicited email messages and failing to properly handle unsubscribe requests. The conduct breached Article 21 of the LSSI.ESAEPDePrivacy€10,000
10 Feb 2025PPC Energie Muntenia SAPPC Energie Muntenia SA was fined EUR 1,000 by ANSPDCP for violating GDPR provisions. The case concerned non-compliance with personal data protection requirements.ROANSPDCPGDPR€1,000
10 Feb 2025PPC Energie Muntenia SAThe operator was fined by ANSPDCP in the amount of EUR 2,000 for violating GDPR provisions. The case concerns non-compliance with personal data protection requirements.ROANSPDCPGDPR€2,000
07 Feb 2025ESTUDIO ALCAZAR DEL GENIL 2022, S.L.ESTUDIO ALCAZAR DEL GENIL 2022, S.L. was fined EUR 10,000 by the AEPD for collecting and storing personal data taken from mailboxes without consent or notice to the data subjects. The authority found breaches of the lawful basis and transparency requirements under GDPR Articles 6(1) and 14.ESAEPDGDPR€10,000
06 Feb 2025ALPHA BANK ANONYMI ETAIREIAAlpha Bank was fined by the HDPA for failing to implement adequate security measures. This led to unauthorized access to the personal data of 6,176 employees after a system administrator role was not revoked following an internal transfer.GRHDPAGDPR€3,000
06 Feb 2025Omniasig Vienna Insurance Group S.A.A fine of 3,000 EUR was imposed for unauthorized access to personal data of a significant number of data subjects over a defined period. The case concerns a data security breach requiring appropriate access controls and protective measures.ROANSPDCPGDPR€3,000
05 Feb 2025FARMEC SAThe National Supervisory Authority for Personal Data Processing completed an investigation in December 2024 at FARMEC SA and found a GDPR violation. As a result, the company was fined EUR 5,000.ROANSPDCPGDPR€5,000
05 Feb 2025FacharztThis case concerns a confirmed fine by the Austrian Federal Administrative Court (BVwG) against Facharzt for disclosing health data in an online review. The conduct indicates a breach of personal data protection rules involving medical information.ATBundesverwaltungsgericht (BVwG)GDPR€4,500,000
05 Feb 2025RESIDENTIAL QUALITY ENJOY, S.L.The company was fined EUR 2,000 by the AEPD for requesting and processing personal data, including minors' IDs, without proper consent or information. The authority found this to be a breach of data protection principles and transparency obligations.ESAEPDGDPR€2,000
04 Feb 2025Bonnier NewsThe Swedish Authority for Privacy Protection (IMY) imposed an administrative fine of SEK 13 million on Bonnier News for unlawful personal data processing. The Administrative Court in Stockholm reviewed the case and confirmed that the company lacked a lawful basis and that the sanction was proportionate.SEIntegritetsskyddsmyndighetenGDPR€1,138,000
04 Feb 2025V&M Contab&Management SRLANSPDCP imposed a fine of EUR 2,000 on V&M Contab&Management SRL for GDPR violations. The case concerned non-compliance with personal data protection requirements.ROANSPDCPGDPR€2,000
04 Feb 2025V&M Contab&Management SRLANSPDCP imposed a fine of EUR 8,000 on V&M Contab&Management SRL for GDPR violations. The case concerns non-compliance with personal data protection requirements, creating regulatory risk for the controller.ROANSPDCPGDPR€8,000