Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
15 Sept 2022Bper Banca S.p.A.Bper Banca S.p.A. was fined by the Garante for a delayed and inadequate response to requests for deletion of personal data. The authority found breaches of GDPR Articles 12 and 17.ITGaranteGDPR€10,000
11 Jun 2021BRAbank ASABRAbank ASA was fined NOK 400,000 by Datatilsynet for failing to perform risk assessments and testing before launching a customer portal. The deficiency led to a data breach in which customers could view other customers’ loan information.NODatatilsynetGDPR€39,672
24 Mar 2022Brav s.r.l.Brav s.r.l. was fined by the Garante 10,000 EUR for failing to implement adequate technical and organizational security measures. The issue concerned data processing linked to the management of contraventions by the local police of the Municipality of Genoa.ITGaranteGDPR€10,000
12 Dec 2024Breathe Services LtdBreathe Services Ltd, a debt advice company based in Bolton, was investigated by the ICO following complaints about unsolicited calls to potentially vulnerable individuals. The ICO found that the company spoofed outbound numbers and made 4,376,037 unsolicited direct marketing calls to numbers registered with the Telephone Preference Service, generating multiple complaints.GBICOGDPR€206,000
17 May 2023Breikot Management LtdBreikot Management Ltd was fined EUR 3,000 by the CyDPC for publishing personal data, including names and photos. The authority found a breach of the data minimization principle under the GDPR.CYCyDPCGDPR€3,000
18 May 2017Brennercom s.p.a.Brennercom s.p.a. was fined 10,000 EUR by the Garante for inadequate password security measures. The authority found that the company's practices breached data protection rules.ITGaranteGDPR€10,000
12 Dec 2024BREOGAN AUTOLUX, S.L.BREOGAN AUTOLUX, S.L. was fined EUR 10,000 by the AEPD for sending unsolicited SMS advertisements without prior consent from recipients. The authority also found that the messages did not provide an opt-out mechanism, in breach of the LSSI.ESAEPDePrivacy€10,000
12 Feb 2026Bressanelli Galli Gelpi Porta & C. S.r.l.The company was fined EUR 15,000 by the Garante for sending promotional emails without prior consent from recipients. The authority found this to be a breach of GDPR principles, including Article 5.ITGaranteGDPR€15,000
13 May 2021Brico Rida s.r.l.Brico Rida s.r.l. was fined by the Garante in the amount of 2,000 EUR for operating a video surveillance system without the required information notice to data subjects. The authority found a breach of Article 13 GDPR.ITGaranteGDPR€2,000
12 Jan 2023BRISTOL LOGISTICS SABRISTOL LOGISTICS SA was fined EUR 2,000 by ANSPDCP for violating GDPR provisions. The case concerns non-compliant processing of personal data.ROANSPDCPGDPR€2,000
10 Mar 2022Briza Land S.R.L.The National Supervisory Authority completed an investigation on 24.02.2022 at Briza Land S.R.L. and found a violation of GDPR provisions. As a result, a fine of EUR 2,000 was imposed.ROANSPDCPGDPR€2,000
05 Apr 2018Broker & Broker s.r.l.Broker & Broker s.r.l. was fined EUR 340,000 by the Italian authority Garante. The case concerned the registration of numerous phone cards to third parties without their knowledge or consent, which breached data protection rules.ITGaranteGDPR€340,000
24 Sept 2020BRONSON BAR, S.L.BRONSON BAR, S.L. was fined 2,000 EUR by the AEPD. The company used the reverse side of a contract to create an inventory, which was then publicly displayed, breaching data integrity and confidentiality principles.ESAEPDGDPR€2,000
06 Sept 2012BT Italia s.p.a.BT Italia s.p.a. was fined by the Garante EUR 75,000 for sending unsolicited promotional faxes without recipient consent. The conduct breached data protection and direct marketing rules.ITGaranteGDPR€75,000
05 Jun 2020BUBO MEDIA, S.L.BUBO MEDIA, S.L. was fined by the AEPD in the amount of 1,500 EUR for sending unsolicited SMS messages to individuals without their consent. The conduct breached data protection and electronic communications rules.ESAEPDePrivacy€1,500
21 Mar 2025Bucharest Down Town Hotel SRLThe National Supervisory Authority for Personal Data Processing fined Bucharest Down Town Hotel SRL for GDPR violations following a complaint. The case concerned non-compliant processing of personal data.ROANSPDCPGDPR€1,000
08 Feb 2022Budapest Bank Zrt.Budapest Bank Zrt. was fined by NAIH for improper personal data processing related to the analysis of recorded phone conversations. The authority found violations of several GDPR provisions.HUNAIHGDPR€707,000
24 Mar 2021Budapest Főváros Kormányhivatala XI. kerületi HivatalaBudapest Főváros Kormányhivatala XI. kerületi Hivatala failed to implement adequate security measures for health data related to Covid-19 tests. The office also did not report a high-risk personal data breach to NAIH or notify the affected individuals.HUNAIHGDPR€27,400
25 Apr 2022Budapest Főváros XVIII. kerület Pestszentlőrinc - Pestszentimre ÖnkormányzataThe authority fined the municipality for failing to provide adequate information to data subjects about the collection and use of their personal data. It also found processing of personal and health data without a valid legal basis or proper consent.HUNAIHGDPR€8,010
10 Dec 2020Budapesti Műszaki és Gazdaságtudományi EgyetemThe university processed personal data during the submission and evaluation of social scholarship applications without a valid legal basis. This also included special category data processed without appropriate GDPR grounds.HUNAIHGDPR€22,480