Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
02 Dec 2020Sahlgrenska Universitets­sjukhusetSahlgrenska University Hospital was fined SEK 3.5 million for failing to perform the required needs and risk analysis before granting access rights in its medical record systems. The authority found this breached GDPR requirements on data security and accountability.SEIMYGDPR€340,000
19 Jan 2023Sąd Rejonowy Szczecin-Centrum z siedzibą w Szczecinie przy ul.The UODO imposed an administrative fine of PLN 30,000 on the Szczecin-Centrum District Court. The authority found that appropriate technical and organizational measures were not implemented to match the risk of processing data using portable storage devices.PLUODOGDPR€6,374
19 Dec 2023Sąd Okręgowy w Krakowie za naruszenie art. 33 ust. 1 i ust. 2 oraz art. 34 ust. 1 i ust. 2 rozporządzenia 2016/679UODO imposed an administrative fine of 10,000 PLN on the Regional Court in Kraków. The case concerns breaches of obligations related to personal data breach notification and informing affected individuals.PLUODOGDPR€2,306
23 Oct 2014S.A.B. Alberghi di Baveno s.p.a.S.A.B. Alberghi di Baveno s.p.a. was fined by the Garante in the amount of €2,400 for processing personal data connected with job applications without providing the required information notice. The case concerned the information duty under Article 13 of the Italian Privacy Code.ITGaranteGDPR€2,400
05 Mar 2020S.Á.Á.S.Á.Á. was fined for a data breach in which a former employee received sensitive patient information. The authority found that technical and organizational measures were inadequate.ISPersónuverndGDPR€21,090
13 Sept 2012Ruzzo Reti S.p.a.Ruzzo Reti S.p.a. was fined EUR 4,000 by the Italian Garante. The authority found that the company failed to designate data processors, meaning it did not adopt the minimum security measures required by the Italian Privacy Code.ITGaranteGDPR€4,000
23 Jan 2020Runwhip s.r.l.Runwhip s.r.l. was fined €80,000 by the Italian supervisory authority, Garante. The sanction concerned failure to respond to information requests, which was treated as a breach of GDPR Article 5.ITGaranteGDPR€80,000
12 Nov 2014Ruggiero FerdinandoRuggiero Ferdinando was fined EUR 10,000 by the Garante. The sanction concerned failing to provide a complete response to a request for information during a privacy investigation.ITGaranteGDPR€10,000
06 Feb 2020R.T.I. - Reti Televisive Italiane s.p.a.R.T.I. - Reti Televisive Italiane s.p.a. was fined EUR 20,000 by the Garante for broadcasting a segment on “Le Iene”. The segment made the complainant identifiable through her voice and personal information, breaching data protection rules.ITGaranteGDPR€20,000
09 May 2025ROUMASPORT SRLIn April 2025, Romania’s data protection authority ANSPDCP completed an investigation at ROUMASPORT SRL. The authority found GDPR violations and imposed a fine of 5,000 EUR.ROANSPDCPGDPR€5,000
30 Dec 2025Roumasport S.R.LRoumasport S.R.L was fined EUR 10,000 by ANSPDCP for violating GDPR provisions. The case concerns non-compliant processing of personal data.ROANSPDCPGDPR€10,000
25 May 2022Roularta Media GroupRoularta Media Group was fined EUR 50,000 by the APD for using cookies on its media websites without obtaining valid user consent. The authority found this practice breached GDPR and ePrivacy Directive requirements.BEAPDePrivacy€50,000
25 May 2022RoulartaThe Belgian data protection authority, APD, sanctioned Roularta in decision 85/2022 of 25 May 2022. The case concerned the placement of non-essential cookies on its press websites without prior user consent. The fine was EUR 50,000.BEAutorité de protection des donnéesGDPR€50,000
04 Feb 2013ROTULACION Y DISEÑO ALBACETE S.L.The entity was fined for sending unsolicited commercial emails and for failing to provide the required data protection information on its website. The case concerns breaches of information duties and rules on marketing communications.ESAEPDePrivacy€1,200
14 Dec 2017Rotondi AndreaAndrea Rotondi was fined for the improper handling of banking documents that were found by a private citizen. Banca Nazionale del Lavoro was held jointly liable for the violation.ITGaranteGDPR€4,000
24 Apr 2024Rossi Carta S.r.l. UnipersonaleRossi Carta S.r.l. Unipersonale was fined by the Garante 30,000 EUR for sending unsolicited promotional emails and failing to respond to a data subject rights request. The authority also noted the use of an outdated content management system on the company website, which created potential security risks for personal data.ITGaranteGDPR€30,000
22 May 2013Romulus PopescuRomulus Popescu was fined EUR 16,000 by the Garante. The sanction concerned sending unsolicited promotional communications to a minor without proper consent.ITGaranteGDPR€16,000
13 Nov 2023Rompetrol Downstream SRLRompetrol Downstream SRL was fined EUR 110,000 by ANSPDCP for failing to ensure the security of personal data. The authority found a breach of Article 32 GDPR, which requires appropriate technical and organizational measures.ROANSPDCPGDPR€110,000
13 May 2025Romoffice Construct Holding Ag SRLThe company was fined by ANSPDCP €2,000 for processing personal data without a legal basis. The breach concerned the principles of lawfulness, fairness, and transparency.ROANSPDCPGDPR€2,000
12 Sept 2022ROMESTONE, S.L.ROMESTONE, S.L. was fined by the AEPD 6,000 EUR for installing a surveillance camera in a shared rental property without tenant consent. The case concerns a privacy breach in the context of personal data processing.ESAEPDGDPR€6,000