Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
20 Mar 2026Domeniul Public și Privat SADomeniul Public și Privat SA was fined 2,000 EUR by ANSPDCP for GDPR violations. The case concerned non-compliance with personal data protection requirements.ROANSPDCPGDPR€2,000
20 Mar 2026Domeniul Public și Privat SADomeniul Public și Privat SA was fined EUR 1,000 for breaching Article 15 of the GDPR. The case concerned improper handling of data subject access rights.ROANSPDCPGDPR€1,000
20 Mar 2026Jogalap nélküli hozzáférés az EESZT rendszeréhez és hozzáférési kérelem nemteljesítéseThe supervisory authority imposed a fine for processing personal data without a lawful basis, including health data. It also found failure to comply with an access request, which breaches GDPR obligations.HUNAIHGDPR€1,275
19 Mar 2026HafnarfjarðarbærHafnarfjarðarbær was fined for using Google Workspace for Education in schools without full compliance with data protection rules. The authority cited unclear processing purposes and delayed data protection impact assessments.ISPersónuverndGDPR€19,516
19 Mar 2026GarðabærGarðabær was fined for multiple data protection violations in its use of Google Workspace for Education without ensuring GDPR compliance. The case concerned the processing of children's personal data, which required additional safeguards and a proper legal basis.ISPersónuverndGDPR€17,425
19 Mar 2026KópavogsbærKópavogsbær was fined by Persónuvernd for using Google Workspace for Education in schools without full compliance with data protection rules. The authority cited, among other issues, the absence of a data protection impact assessment and unclear processing purposes.ISPersónuverndGDPR€20,910
19 Mar 2026ReykjavíkurborgReykjavíkurborg was fined by Persónuvernd for using Google Workspace for Education in schools without meeting GDPR requirements. The case concerned the processing of children's personal data, which required heightened compliance and safeguards.ISPersónuverndGDPR€13,940
16 Mar 2026Restaurant Partner PolskaThe Polish Data Protection Authority imposed an administrative fine of PLN 5,898,064 on Restaurant Partner Polska, the operator of Glovo in Poland. The authority found that the company unlawfully collected and processed scans and photos of users’ identity documents, in breach of GDPR requirements.PLUrząd Ochrony Danych OsobowychGDPR€1,381,000
12 Mar 2026Enel Energia S.p.A.Enel Energia S.p.A. was fined by the Italian data protection authority, Garante, for making unwanted telemarketing calls without a proper legal basis. The authority found that the company’s conduct breached data protection principles.ITGaranteGDPR€563,000
12 Mar 2026Bakeca s.r.l.Bakeca s.r.l. was fined €5,000 by the Italian data protection authority, Garante. The case concerned the publication of online ads without the required consent, which breached data protection rules.ITGaranteGDPR€5,000
12 Mar 2026Comune di SutriComune di Sutri was fined EUR 2,000 by the Garante for publishing personal data on its institutional website. The case concerns a breach of data protection rules in the public online disclosure of information.ITGaranteGDPR€2,000
12 Mar 2026ITAS MutuaITAS Mutua was fined EUR 50,000 by the Garante for failing to adequately respond to a former employee’s request for access to personal data. The authority found a breach of GDPR Article 15.ITGaranteGDPR€50,000
12 Mar 2026Almas SalonThe Garante imposed an EUR 800 fine on Almas Salon for operating a video surveillance system without proper compliance with data protection rules. The case concerns a breach of GDPR Article 5, indicating failure to meet core data processing principles.ITGaranteGDPR€800
12 Mar 2026INPS – Istituto nazionale previdenza socialeThe Italian Data Protection Authority fined INPS EUR 40,000 for improperly displaying personal data of individuals residing in a care facility during an ISEE precompilation request. The authority found a breach of data protection principles.ITGaranteGDPR€40,000
12 Mar 2026Artemide S.r.l.s.Artemide S.r.l.s., the owner of MeridioNews.it, was fined 10,000 EUR by the Garante. The authority found that the company failed to properly handle a request to delete and de-index articles concerning judicial matters, thereby infringing data protection rights.ITGaranteGDPR€10,000
12 Mar 2026Domiziana GiorgianniThe Garante imposed a EUR 2,000 fine on Domiziana Giorgianni for failing to implement adequate technical and organizational measures to support data subject rights. The authority also found that requests were not handled without undue delay.ITGaranteGDPR€2,000
12 Mar 2026Liceo Scientifico MorgagniLiceo Scientifico Morgagni was fined by the Garante for violations related to the processing of sensitive data. The authority cited inadequate security measures in the protection of those data.ITGaranteGDPR€2,000
12 Mar 2026La7 S.p.A.La7 S.p.A. was fined 40,000 EUR by the Garante for broadcasting personal data, including phone numbers and names, during a news segment. The authority found a breach of GDPR Article 5 on data processing principles.ITGaranteGDPR€40,000
12 Mar 2026SOCIÉTÉ EXERÇANT UNE ACTIVITÉ DE VENTE À DISTANCE SUR CATALOGUE SPECIALISÉE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 5,000 on Société exerçant une activité de vente à distance sur catalogue spécialisée. The case was handled under a simplified procedure.FRCNILGDPR€5,000
12 Mar 2026Hanako s.r.l.Hanako s.r.l. was fined by the Garante EUR 2,000 for operating a video surveillance system without ensuring GDPR compliance. The authority cited inadequate security measures and failure to provide sufficient information to employees.ITGaranteGDPR€2,000