Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
02 Apr 2026SOCIÉTÉ EXPLOITANT DES BOUTIQUES TOILETTES (procédure simplifiée)CNIL imposed an administrative fine of EUR 7,500 on SOCIÉTÉ EXPLOITANT DES BOUTIQUES TOILETTES under a simplified procedure. The case concerns a breach of rules covered by the authority’s decision.FRCNILGDPR€7,500
30 Mar 2026Energy Prices Direct LimitedThe ICO fined Energy Prices Direct Limited, an energy switching services provider, for breaches of the PECR. The company obtained data from public sources and list providers, but failed to screen it against the TPS/CTPS registers before making marketing calls.GBICOePrivacy€184,000
30 Mar 2026Κέντρο Εκπαίδευσης και Αποκατάστασης Τυφλών (ΚΕΑΤ)The Greek Data Protection Authority fined ΚΕΑΤ EUR 5,000 for an untimely and improper response to an employee’s request for access to CCTV footage. The case involved edited footage, missing material, and inadequate technical and organizational measures to support compliance.GRΑρχή Προστασίας Δεδομένων Προσωπικού ΧαρακτήραGDPR€5,000
26 Mar 2026Esselunga S.p.A.Esselunga S.p.A. was fined EUR 5,000 by the Italian supervisory authority, Garante. The case concerned a failure to respond to a data access request under Article 15 GDPR, including access to employee attendance records.ITGaranteGDPR€5,000
26 Mar 2026Euro Bangla MinimarketThe Garante fined Euro Bangla Minimarket EUR 1,000 for improper use of a video surveillance system. Images from six cameras were visible to everyone on a monitor in the store, which breached GDPR requirements.ITGaranteGDPR€1,000
26 Mar 2026SOCIÉTÉ EXERÇANT UNE ACTIVITÉ D'ARTS DU SPECTACLE VIVANT (procédure simplifiée)CNIL imposed a fine of 850 EUR on SOCIÉTÉ EXERÇANT UNE ACTIVITÉ D'ARTS DU SPECTACLE VIVANT in connection with the liquidation of astreinte. The case concerns compliance with a prior obligation under a simplified procedure.FRCNILGDPR€850
26 Mar 2026Provvedimento del 26 marzo 2026 [10246060]The entity was fined for operating a video surveillance system without providing adequate informational signage. The authority found this to be a breach of GDPR Article 13 on the duty to inform data subjects.ITGaranteGDPR€2,000
26 Mar 2026Copacabana s.r.l.Copacabana s.r.l. was fined EUR 2,000 by the Garante for installing a video surveillance system without the required informational signage and necessary authorization. The authority cited a breach of GDPR Article 13.ITGaranteGDPR€2,000
26 Mar 2026Messina Social CityMessina Social City was fined by the Garante 10,000 EUR for breaching GDPR principles. The case concerned the improper dissemination of personal data, including images of minors, on Facebook without proper legal grounds and contracts.ITGaranteGDPR€10,000
26 Mar 2026Provvedimento del 26 marzo 2026 [10241477]A doctor did not comply with a request to delete data and provided patients with incomplete information, which constituted a breach of GDPR Article 13. The Garante imposed a fine of EUR 2,000.ITGaranteGDPR€2,000
26 Mar 2026Comune di XXThe Garante fined Comune di XX EUR 5,000 for breaches of lawfulness, fairness, transparency, and data minimization. It also found failures to implement data protection by design and by default.ITGaranteGDPR€5,000
26 Mar 2026Eni S.p.A.Eni S.p.A. was fined 96,000 EUR by the Garante for publishing personal data on its website, including dates of birth and addresses, without proper masking. The authority found this breached GDPR principles of lawfulness, fairness, and transparency.ITGaranteGDPR€96,000
26 Mar 2026SOCIÉTÉ AYANT POUR ACTIVITÉ L'HÉBERGEMENT DE TOURISME (procédure simplifiée)CNIL imposed an administrative fine of EUR 3,000 on SOCIÉTÉ AYANT POUR ACTIVITÉ L'HÉBERGEMENT DE TOURISME under a simplified procedure. The case concerns a confirmed breach of rules supervised by CNIL.FRCNILGDPR€3,000
26 Mar 2026PSK AD Network S.r.l.PSK AD Network S.r.l. was fined EUR 5,000 by the Garante. The case concerned the failure to respond to a data subject’s deletion request and the failure to provide information requested by the authority, in breach of Article 157 of the Codice.ITGaranteGDPR€5,000
26 Mar 2026SOCIÉTÉ ORGANISANT DES ÉVÈNEMENTS PAR LA PROMOTION ET LA VENTE DE BILLETS (procédure simplifiée)The CNIL imposed an administrative fine of EUR 15,000 on the company organizing events and selling tickets, and issued an injunction. The case was handled under a simplified procedure.FRCNILGDPR€15,000
26 Mar 2026Ordine degli Avvocati di PiacenzaOrdine degli Avvocati di Piacenza was fined EUR 3,000 by the Garante for improper handling of disciplinary sanctions in its professional register. The authority found that the processing did not comply with data protection requirements.ITGaranteGDPR€3,000
26 Mar 2026Comune di CassinoComune di Cassino was fined for unlawfully publishing personal data online. The case concerns a breach of data protection rules and indicates a need to review procedures for publishing public information.ITGaranteGDPR€2,500
26 Mar 2026Comune di XXThe Garante fined Comune di XX EUR 3,000 for breaches of GDPR Articles 6 and 9 and Article 2-ter of the Italian Privacy Code. The case concerned processing personal data without a proper legal basis.ITGaranteGDPR€3,000
24 Mar 2026SIA "Fitsypro"SIA "Fitsypro" was fined EUR 1,500 by the DVI. The decision has entered into force.LVDVIGDPR€1,500
23 Mar 2026ING Bank NV Amsterdam – Sucursala București S.A.The fine was imposed for failing to implement adequate technical and organizational measures to ensure the confidentiality of personal data. As a result, an unauthorized third party received a bank account statement.ROANSPDCPGDPR€4,000