Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
31 Jul 2024CURENERGÍA COMERCIALIZADOR DE ÚLTIMO RECURSO, S.A.U.Curenergía was fined by the AEPD for processing personal data without a proper legal basis. The company used former customer data without full consent in connection with a new contract.ESAEPDGDPR€100,000
01 Dec 2022Regione LazioThe Garante fined Regione Lazio EUR 100,000 for unlawfully collecting metadata from employees' emails without a proper legal basis. The authority found that the processing did not meet the legal requirements for monitoring employee communications.ITGaranteGDPR€100,000
08 Jun 2021DKN.5131.10.2020StatusnieprawomocnaTytuThe President of UODO imposed a fine of PLN 100,000 for failing to notify data breaches within the required deadline. The case concerns the obligation to report personal data breaches to the supervisory authority on time.PLUODOGDPR€22,372
12 May 2022CivilstyrelsenThe Danish DPA reported Civilstyrelsen to the police and recommended a fine for failing to implement appropriate security measures and for not reporting a data breach. The case ended with a fine notice of 100,000 DKK.DKDatatilsynetGDPR€13,439
09 Mar 2021VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined EUR 100,000 by the AEPD for failing to permanently delete personal data after a request. As a result, the complainant continued to receive SMS messages.ESAEPDGDPR€100,000
10 Jul 2025Banco Bilbao Vizcaya Argentaria SABanco Bilbao Vizcaya Argentaria SA was fined by the Italian authority Garante in the amount of €100,000. The case concerned an inadequate response to a data access request linked to a fraud incident, which breached Article 15 of the GDPR.ITGaranteGDPR€100,000
16 Jun 2021Vejle KommuneVejle Kommune was fined by Datatilsynet for failing to implement appropriate security measures, which led to the unintended disclosure of personal data, including children's addresses. The authority also found no assessment of whether such disclosures were necessary.DKDatatilsynetGDPR€13,447
17 Dec 2025HAN University of Applied SciencesThe Autoriteit Persoonsgegevens announced on 17 December 2025 that it had imposed a fine on HAN University of Applied Sciences. According to the notice, the university was hacked in September 2021, resulting in a data breach, and HAN will not object to the decision.NLAutoriteit PersoonsgegevensGDPR€100,000
19 Feb 2026Hrvatska agencija za nekretnineAZOP imposed an administrative fine of EUR 100,000 on a Croatian real estate agency for GDPR breaches. The authority found unlawful retention of personal data of 11,887 clients after the processing purpose had expired, processing without a legal basis, and inadequate technical and organizational measures.HRAZOPGDPR€100,000
11 Feb 2021Krajową Szkołę Sądownictwa i Prokuratury z siedzibą w Z.,UODO imposed a PLN 100,000 administrative fine on the National School of Judiciary and Public Prosecution. The authority found that the entity failed to implement appropriate technical and organizational measures to ensure the ongoing confidentiality of processing services and breached GDPR Article 28(3).PLUODOGDPR€22,235
14 May 2026Energia Sostenibile S.r.l.Energia Sostenibile S.r.l. was fined EUR 100,000 by the Garante for making unsolicited calls to numbers listed in the Public Opposition Register. The authority also found that the company did not adequately respond to data subjects’ requests to exercise their rights.ITGaranteGDPR€100,000
01 Jan 2023VODAFONE ESPAÑA, S.A.U.The AEPD fined VODAFONE ESPAÑA, S.A.U. 100,000 EUR for allowing a third party to impersonate a customer. This led to a mobile line portability request and the purchase of a mobile device without the customer’s consent.ESAEPDGDPR€100,000
12 Jun 2023Piraeus Bank S.A.Piraeus Bank S.A. was fined by the HDPA EUR 100,000 for processing personal data without a legal basis. The breach affected a large number of data subjects, which increases its compliance significance.GRHDPAGDPR€100,000
12 Jun 2025Krajowa Szkoła Sądownictwa i Prokuratury (KSSiP)The President of the Polish data protection authority imposed a PLN 100,000 fine on the National School of Judiciary and Public Prosecution for breaching data protection rules during a data migration. The Supreme Administrative Court upheld the decision, making the sanction final.PLUrząd Ochrony Danych OsobowychGDPR€23,425
02 Jan 2023Dulnevnd fyritøka (Dátueftirlitið)DATFO referred a company to the police for suspected breaches of data protection law. The company collected and stored personal data without a valid legal basis and without providing adequate information to the data subjects. Its website contact mechanism also caused data intended for a specific provider to be collected and retained by the company.FODATFOGDPR€13,446
01 Jan 2023NATURGY IBERIA, S.A.Naturgy Iberia was fined for changing a customer's gas and electricity supplier without authorization. The authority found that this breached Article 6(1) of the GDPR because there was no lawful basis for the processing.ESAEPDGDPR€100,000
22 Jun 2023VODAFONE ESPAÑA, S.A.U.Vodafone España, S.A.U. was fined by the AEPD in the amount of 100,000 EUR for issuing a SIM card duplicate without the customer's consent. The authority treated this as a breach of data protection rules.ESAEPDGDPR€100,000
29 Dec 2023SOCIETE DE CONSEIL EN SYSTEMES ET LOGICIELS INFORMATIQUESThe CNIL imposed a fine of EUR 100,000 on SOCIETE DE CONSEIL EN SYSTEMES ET LOGICIELS INFORMATIQUES. The case concerns a breach of personal data protection rules.FRCNILGDPR€100,000
15 Feb 2024Dr TelemarketingBetween 11 February 2021 and 24 January 2022, 80,240 connected unsolicited marketing calls were made to subscribers registered with the TPS who had not consented to receive them. Two complaints were received, and the calls related to the Irish Lottery. The company stopped engaging with the Commissioner during the investigation and did not provide a satisfactory explanation for the Lotto Express calls.GBICOGDPR€116,000
03 Feb 2026TMAC LtdTMAC Ltd was fined GBP 100,000 by the ICO and served with an enforcement notice for breaches of regulations 21 and 24 of PECR. Between 8 February 2024 and 24 September 2024, the company made 260,332 unsolicited direct marketing calls to numbers listed on the Commissioner’s register. It also failed to provide the required information to call recipients.GBICOePrivacy€115,000