Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
31 May 2018Mingardi Medical Center s.r.l.Mingardi Medical Center s.r.l. was fined by the Garante in the amount of EUR 86,000 for making unsolicited promotional calls. The conduct breached data protection rules governing telemarketing activities.ITGaranteGDPR€86,000
31 May 2018IDEASORRISO S.R.L.IDEASORRISO S.R.L. was fined by the Garante EUR 86,000 for making unsolicited promotional calls without the recipients’ consent. The case concerned data protection rules applicable to telemarketing activities.ITGaranteGDPR€86,000
05 Jan 2021Dane anonimowe (Panią M. Z. prowadzącą działalność gospodarczą pod firmą K.)The President of UODO imposed a fine of PLN 85,588 on an individual conducting business under the name K. The authority found that an order contained in an administrative decision on personal data protection had not been complied with.PLUODOGDPR€18,822
01 Nov 2025Właścicielka lecznicy stomatologicznejThe owner of a dental clinic was fined 85,588 PLN by UODO for failing to notify affected patients in time after a personal data breach. The WSA and then the NSA upheld the penalty, finding that the required notices were sent too late.PLPresident of the Personal Data Protection Office (UODO)GDPR€20,110
09 Dec 2020DKN.5131.5.2020StatusprawomocnaTytuA monetary penalty was imposed for failing to report a personal data breach to the President of UODO and for failing to notify the affected individuals. The case concerns non-compliance with breach notification obligations after a data security incident.PLUODOGDPR€19,344
02 Sept 2024Prokuraturę KrajowąUODO imposed an administrative fine of 85,000 PLN on the National Prosecutor's Office for breaches of Article 6(1), Article 9(1), Article 33(1), and Article 34(1) and (2) of the GDPR. The authority also ordered notification of the affected data subjects.PLUODOGDPR€19,883
12 Aug 2020TuslaThe Irish DPC fined Tusla EUR 85,000 in inquiry IN-18-11-4. The fine has been collected.IEDPCGDPR€85,000
17 Apr 2026The European House - Ambrosetti S.p.A.The European House - Ambrosetti S.p.A. was fined by Garante 85,000 EUR for a data breach. The incident involved unauthorized access and exfiltration of personal and authentication data affecting an unspecified number of individuals.ITGaranteGDPR€85,000
21 May 2026The European House – Ambrosetti spaThe Italian data protection authority fined The European House – Ambrosetti spa EUR 85,000 for security shortcomings following a data breach affecting 61,670 people. The company notified affected individuals too late, only after intervention by the authority.ITGarante per la protezione dei dati personaliGDPR€85,000
13 May 2021Comune di BolzanoThe Municipality of Bolzano was fined 84,000 EUR by the Garante for improper handling of employee internet navigation data. The authority found that personal data were systematically collected without adequate safeguards and in breach of data protection principles.ITGaranteGDPR€84,000
29 Jan 2015Comunicando di Rizzotto Fabio & C. s.a.s.Comunicando di Rizzotto Fabio & C. s.a.s. was fined €80,000 by the Garante for activating 88 phone cards in the names of 16 individuals without their knowledge. The authority found this to be a breach of data protection rules.ITGaranteGDPR€80,000
12 Feb 2024MEYDIS, S.L.MEYDIS, S.L. was fined EUR 80,000 by the AEPD for failing to provide required information during an investigation. The authority found a breach of Article 58.1 of the GDPR.ESAEPDGDPR€80,000
10 Jul 2025Poste Vita S.p.a.Poste Vita S.p.a. was fined EUR 80,000 by the Garante for unlawfully disclosing personal data relating to life insurance policies to an unauthorized third party. The data were then used in judicial proceedings.ITGaranteGDPR€80,000
17 Dec 2019ORANGE ESPAGNE, S.A.U.ORANGE ESPAGNE, S.A.U. was fined EUR 80,000 by the AEPD for using personal data to fraudulently contract phone lines without consent. The authority found a breach of Article 6(1) GDPR.ESAEPDGDPR€80,000
07 Nov 2025MAJOREL SP SOLUTIONS, S.A.MAJOREL SP SOLUTIONS, S.A. was fined by the AEPD 80,000 EUR for processing personal data without a lawful basis. The authority found a breach of Article 6(1)(b) GDPR.ESAEPDGDPR€80,000
16 May 2023Ice Telecommunications LtdIce Telecommunications Ltd made 72,682 unsolicited marketing calls to businesses registered with the CTPS or TPS between 13 September 2021 and 31 January 2022. The ICO imposed a fine of £80,000 for breaching direct marketing rules.GBICOGDPR€92,016
04 Aug 2025Azienda Ospedaliero-UniversitariaThe Italian data protection authority fined Azienda Ospedaliero-Universitaria EUR 80,000 for improperly configuring its health dossier. It found that staff could access patients’ clinical histories without proper profiling, alerts, or access logging, and that patients were not adequately informed or able to consent or object.ITGarante per la protezione dei dati personaliGDPR€80,000
23 Jan 2020Runwhip s.r.l.Runwhip s.r.l. was fined €80,000 by the Italian supervisory authority, Garante. The sanction concerned failure to respond to information requests, which was treated as a breach of GDPR Article 5.ITGaranteGDPR€80,000
23 Apr 2015Compagnia dei Telefoni s.r.l.Compagnia dei Telefoni s.r.l. was fined by the Garante 80,000 EUR for conducting telemarketing through automated calls without prior informed consent. The company also made promotional calls while concealing the caller's identity.ITGaranteGDPR€80,000
17 Sept 2020Azienda Ospedaliera di Rilievo Nazionale “Antonio Cardarelli"The Garante imposed an EUR 80,000 fine on Azienda Ospedaliera di Rilievo Nazionale “Antonio Cardarelli” for a data breach involving sensitive health data. The incident occurred during a platform maintenance period, indicating insufficient safeguards around processing.ITGaranteGDPR€80,000