Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
20 Oct 2011Betfair Italia srlBetfair Italia srl was fined EUR 40,000 by the Garante for violations related to the omission of information on how data subjects can exercise their rights, as well as other data protection obligations. The case concerned incomplete compliance with information requirements toward users.ITGaranteGDPR€40,000
12 Dec 2023B*** GmbHB*** GmbH was fined by the DSB EUR 5,900 for failing to timely report a data breach to the supervisory authority and for not providing sufficient information required under GDPR. The company also did not cooperate with the authority’s further requests for information.ATDSBGDPR€5,900
07 Oct 2024B*** GmbHB*** GmbH was fined EUR 600 by the Austrian Data Protection Authority (DSB). The penalty concerned a failure to cooperate in a data breach procedure, which breached Article 31 GDPR.ATDSBGDPR€600
16 Sept 2025Bharat Singh ChandBharat Singh Chand, a self-employed lead generator, sent or instigated the sending of 966,449 direct marketing SMS messages between 3 December 2023 and 3 July 2024. The activity breached regulations 22 and 23 of PECR and generated 19,138 complaints to the 7726 spam reporting service. He was fined £200,000 and issued with an enforcement notice.GBICOePrivacy€231,000
11 May 2017Bianalisi s.p.a.Bianalisi s.p.a. was fined by the Italian data protection authority, Garante, for failing to update its notification concerning the processing of genetic data. The obligation arose under the Italian Privacy Code and was intended to ensure proper disclosure of sensitive data processing.ITGaranteGDPR€20,000
20 Jan 2021BICLAMEDIA, S.L.BICLAMEDIA, S.L. was fined 1,500 EUR by the AEPD for sending commercial emails without the recipient’s consent. The conduct breached Article 21 of the LSSI governing electronic marketing communications.ESAEPDePrivacy€1,500
23 Jul 2015Bike Service s.n.c.Bike Service s.n.c. was fined by the Garante 2,400 EUR for failing to inform data subjects about the processing of personal data through a video surveillance system. The breach concerned the absence of required notices for individuals subject to the monitoring.ITGaranteGDPR€2,400
05 Jul 2023BILBAO AD INFINITUM, S.L.BILBAO AD INFINITUM, S.L. was fined by the AEPD EUR 500 for installing surveillance cameras directed at a public square without prior administrative authorization. The authority found that this conduct breached GDPR requirements on lawful processing.ESAEPDGDPR€500
04 Apr 2019Bill Size s.r.l.Bill Size s.r.l. was fined by the Garante in the amount of EUR 16,000 for registering phone cards to individuals without their consent. The authority found this to be a breach of data protection rules.ITGaranteGDPR€16,000
01 Dec 2017BILUA E-COMMERCE S.L (CARETHY y BIUKY)BILUA E-COMMERCE S.L. was fined by the AEPD EUR 7,000 for sending unsolicited commercial emails. The messages were sent despite the recipient's request to unsubscribe, which breached Article 21.1 of the LSSI.ESAEPDePrivacy€7,000
02 Apr 2025BINBOX GLOBAL SERVICES S.R.L.In March 2025, Romania’s data protection authority ANSPDCP completed an investigation into BINBOX GLOBAL SERVICES S.R.L. The authority found a GDPR violation and imposed a fine of EUR 3,000.ROANSPDCPGDPR€3,000
16 Feb 2011Bioacqua s.r.l.Bioacqua s.r.l. was fined EUR 9,000 by the Garante for using phone numbers for commercial communications without explicit consent and without providing the required information notice. The conduct breached Article 13 of the Italian Data Protection Code.ITGaranteGDPR€9,000
19 Jul 2012Biodiversity S.p.A.Biodiversity S.p.A. was fined by the Garante for failing to timely notify personal data processing activities related to molecular diagnostics. The obligation arose under the Italian Privacy Code.ITGaranteGDPR€10,000
16 Jan 2014Bios Marx s.r.l.Bios Marx s.r.l. was fined by the Italian Garante in the amount of EUR 16,000 for providing an inadequate privacy notice during a medical initiative. The authority also found that personal data were shared with third parties without obtaining specific consent.ITGaranteGDPR€16,000
09 Dec 2010Bios s.p.a.Bios s.p.a. was fined by the Italian Garante for failing to provide adequate and timely information about the processing of personal data through a video surveillance system. The conduct breached Article 13 of the Italian Data Protection Code.ITGaranteGDPR€6,000
17 Jul 2019Bírák érdek-képviseleti egyesületi tagságra vonatkozó adatának jogellenes kezeléseBudapest Környéki Törvényszék unlawfully processed personal data by listing and sharing association membership information without a proper purpose or legal basis. The authority found a breach of the GDPR principles of purpose limitation and lawful processing.HUNAIHGDPR€9,180
10 Apr 2023BIROU GAS, S.L.BIROU GAS, S.L. was fined EUR 60,000 by the AEPD for breaching Article 58(1) of the GDPR. The company did not respond to information requests from the supervisory authority.ESAEPDGDPR€60,000
08 Oct 2015Birrificio Torino srlBirrificio Torino srl was fined EUR 2,400 by the Garante for providing inadequate information in the data collection form on its website. The authority found a breach of Article 13 of the Italian Data Protection Code.ITGaranteGDPR€2,400
24 Jun 2025BirthlinkThe UK Information Commissioner’s Office (ICO) fined Scottish charity Birthlink GBP 18,000. The case involved the destruction of about 4,800 personal records, up to 10% of which may have been irreplaceable.GBICOGDPR€21,109
01 Feb 2026Biržų ligoninėVDAI imposed a EUR 6,000 fine on Biržų ligoninė for improper processing of personal data. The case concerns a breach of data protection requirements and indicates non-compliance with GDPR obligations.LTVDAIGDPR€6,000