Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
07 Mar 2024Pinnacle Life LimitedBetween 5 May 2021 and 5 May 2022, the company made 47,998 connected unsolicited direct marketing calls to subscribers registered with the TPS who had not consented to receive such calls. Four complaints were submitted, and the ICO imposed a fine of 80,000 GBP.GBICOGDPR€93,624
11 Jan 2023Commify Italia S.r.l.Commify Italia S.r.l. was fined by the Garante 80,000 EUR for violations related to the processing of personal data through its Skebby platform. The case involved inadequate data protection measures and unauthorized access that led to phishing attacks.ITGaranteGDPR€80,000
19 Mar 2019Enel Energia s.p.a.Enel Energia s.p.a. was fined by the Garante EUR 80,000 for failing to implement adequate security measures. This allowed unauthorized access and massive data downloads by a third-party company using credentials of former employees.ITGaranteGDPR€80,000
17 May 2021VODAFONE ESPAÑA, S.A.U.Vodafone España, S.A.U. was fined by the AEPD 80,000 EUR for processing personal data without proper consent. The case involved linking phone lines to incorrect data and enrolling a customer in services without authorization.ESAEPDGDPR€80,000
02 Oct 2025EMAGISTER SERVICIOS DE FORMACIÓN, S.L.EMAGISTER SERVICIOS DE FORMACIÓN, S.L. was fined EUR 80,000 by the AEPD for a data security incident involving unauthorized processes on its web servers. The authority found a breach of data protection principles.ESAEPDGDPR€80,000
13 Jan 2022ADVANS BROKERS CORREDURIA DE SEGUROS S.L.ADVANS BROKERS CORREDURIA DE SEGUROS S.L. was fined by the AEPD EUR 80,000 for a data breach affecting 55,000 individuals, including minors. The authority found that the incident was reported to the AEPD with delay.ESAEPDGDPR€80,000
11 Mar 2021Planet Group spaPlanet Group spa was fined EUR 80,000 by the Garante. The authority found that the company made unsolicited promotional calls without a proper legal basis, breaching GDPR rules on data processing and privacy by design.ITGaranteGDPR€80,000
15 May 2025SOCIETE REALISANT DES OPERATIONS DE PROSPECTION COMMERCIALE PAR VOIE ELECTRONIQUE POUR LE COMPTE D'ANNONCEURS, AVEC UNE ACTIVITE DE COURTIER EN DONNEESThe CNIL imposed an administrative fine of EUR 80,000 on a company engaged in electronic commercial prospecting and data brokering. The decision concerns a breach of rules supervised by the CNIL.FRCNILGDPR€80,000
01 Jan 2024COMERCIALIZADORA REGULADA, GAS & POWER, S.A.The company was fined EUR 80,000 by the AEPD for processing a gas contract without the complainant's consent. It used personal data without authorization, which constitutes a breach of data protection law.ESAEPDGDPR€80,000
14 Dec 2017Yahoo Italia s.r.l.Yahoo Italia s.r.l. was fined EUR 80,000 by the Garante for violations related to the processing of personal data concerning the geolocation of users connecting to its website. The case concerned irregularities in how these data were collected and processed.ITGaranteGDPR€80,000
17 Jul 2024Selectra S.p.A.Selectra S.p.A. was fined EUR 80,000 by the Garante for unlawfully accessing and retaining a former employee's email account after the end of the collaboration. The authority found that the company's conduct breached data protection rules.ITGaranteGDPR€80,000
02 Apr 2015Regione CalabriaRegione Calabria was fined EUR 80,000 by the Garante for failing to designate data processing officers and for only partially implementing IT security measures. The authority also noted a failure to respond to information requests, which required further investigation.ITGaranteGDPR€80,000
13 May 2021Agenzia di Tutela della Salute della Città metropolitana di MilanoAgenzia di Tutela della Salute della Città metropolitana di Milano was fined by the Garante 80,000 EUR for violations linked to data processing during an emergency. The authority found inadequate data protection measures and a failure to provide required information to data subjects.ITGaranteGDPR€80,000
30 Oct 2013Compagnia Assicuratrice Linear s.p.a.Compagnia Assicuratrice Linear s.p.a. was fined by the Garante 80,000 EUR for collecting personal data without specific consent for purposes beyond registration services. The authority found this to be a breach of the Italian Data Protection Code.ITGaranteGDPR€80,000
03 Oct 2013Telecom Italia s.p.a.Telecom Italia s.p.a. was fined 80,000 EUR by the Garante for making unsolicited promotional calls to a customer. The calls were made after the customer had withdrawn consent for such communications, which breached data protection rules.ITGaranteGDPR€80,000
27 Sept 2018Anonymizováno (ÚOOÚ UOOU-05291/17-44)The entity was fined for repeatedly sending commercial communications to specified electronic addresses without consent and without proper labeling. The authority found a breach of Czech rules on information society services.CZUOOUePrivacy€3,111
10 Oct 2024WerepairUK LtdWerepairUK Ltd made 42,688 marketing calls to individuals in breach of regulation 21 of PECR. The ICO fined the company 80,000 GBP and issued an enforcement notice.GBICOePrivacy€95,592
07 Mar 2025SENDING TRANSPORTE Y COMUNICACIÓN, S.A.SENDING TRANSPORTE Y COMUNICACIÓN, S.A. was fined EUR 80,000 by the AEPD for breaching GDPR Articles 28(2) and 28(4). The company subcontracted data processing without the required authorization.ESAEPDGDPR€80,000
12 Mar 2024DKN.5131.28.2023StatusprawomocnaTytuUODO imposed an administrative fine of PLN 78,575.4 for failing to report a personal data breach without undue delay. The incident was not notified to the supervisory authority within 72 hours of becoming aware of the breach.PLUODOGDPR€18,331
30 Jul 2015Roberto NaccaratoRoberto Naccarato was fined by the Garante for processing the personal data of 12 individuals without providing proper information or obtaining consent. The authority found this to be a breach of Italian data protection law.ITGaranteGDPR€76,800