Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.2%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
03 May 2022ReykjavíkurborgReykjavíkurborg was fined ISK 5,000,000 by Persónuvernd for using the Seesaw student system in schools without adequate data protection measures. The case concerned children’s personal data and transfers of data to the United States.ISPersónuverndGDPR€36,350
19 Mar 2026ReykjavíkurborgReykjavíkurborg was fined by Persónuvernd for using Google Workspace for Education in schools without meeting GDPR requirements. The case concerned the processing of children's personal data, which required heightened compliance and safeguards.ISPersónuverndGDPR€13,940
06 Dec 2023ReykjanesbærReykjanesbær was fined by Persónuvernd 2,500,000 ISK for using Google Workspace for Education in schools without full compliance with data protection rules. The authority cited the failure to carry out timely data protection impact assessments and to define processing purposes clearly.ISPersónuverndGDPR€16,650
27 Jun 2013REY2MOND S.n.c. di Reymond Luciano & C.REY2MOND S.n.c. was fined EUR 4,800 by the Garante for collecting personal data through online forms without providing the required privacy notice. The authority found this to be a breach of the Italian Data Protection Code.ITGaranteGDPR€4,800
11 Jan 2023Reweb s.r.l.Reweb s.r.l. was fined 5,000 EUR by the Garante. The company kept a former employee’s email account active and accessed it after the employment relationship ended, in breach of GDPR requirements.ITGaranteGDPR€5,000
25 Apr 2024REVUE LITTERAIRE FRANCAISE (procédure simplifiée)The CNIL imposed a EUR 3,000 penalty on REVUE LITTERAIRE FRANCAISE under a simplified procedure. The case concerns the liquidation of an astreinte, meaning enforcement of a previously ordered monetary obligation.FRCNILGDPR€3,000
28 Sept 2023REVUE LITTERAIRE FRANCAISE (procédure simplifiée)The CNIL imposed a 10,000 EUR fine on REVUE LITTERAIRE FRANCAISE and issued an injunction. The case was handled under a simplified procedure.FRCNILGDPR€10,000
15 Sept 2015Revírní bratrská pokladna, zdravotní pojišťovnaRevírní bratrská pokladna, zdravotní pojišťovna was fined by the UOOU 5,000 CZK for processing inaccurate personal data of an insured person without their knowledge. The case concerns a breach of data protection duties and the requirement to process data accurately.CZUOOUGDPR€185
02 Oct 2025RETSINNAL GROUP, S.L.U.RETSINNAL GROUP, S.L.U. was fined 1,000 EUR by the AEPD for deficiencies in its website privacy policy. The authority found that the company did not provide adequate information about the data controller, in breach of Article 13 GDPR.ESAEPDGDPR€1,000
13 Jun 2024RETSINNAL GROUP, S.L.U.RETSINNAL GROUP, S.L.U. was fined by the AEPD in the amount of 10,000 EUR for failing to comply with cookie management rules on its website. The breach concerned Article 22.2 of the LSSI.ESAEPDePrivacy€10,000
26 Nov 2020Reti Televisive Italiane S.p.a.Reti Televisive Italiane S.p.a. was fined EUR 10,000 by the Garante for broadcasting a segment on “Le Iene” that included footage of an individual recorded without consent. The person was identifiable, which constituted a breach of data protection rules.ITGaranteGDPR€10,000
13 Apr 2023Retimedia S.r.l.Retimedia S.r.l. was fined 2,500 EUR by the Garante for publishing detailed health data of an individual without consent. The conduct breached GDPR Article 9 on special categories of personal data.ITGaranteGDPR€2,500
20 Jun 2024Rețele Electrice Muntenia SARețele Electrice Muntenia SA was fined by ANSPDCP in the amount of 3,000 EUR for violations of GDPR provisions. The case concerns non-compliance with personal data protection requirements.ROANSPDCPGDPR€3,000
20 Jun 2024Rețele Electrice Dobrogea SARețele Electrice Dobrogea SA was fined by ANSPDCP in the amount of EUR 1,000 for violating GDPR provisions. The case concerns non-compliance with personal data protection requirements.ROANSPDCPGDPR€1,000
16 Mar 2026Restaurant Partner PolskaThe Polish Data Protection Authority imposed an administrative fine of PLN 5,898,064 on Restaurant Partner Polska, the operator of Glovo in Poland. The authority found that the company unlawfully collected and processed scans and photos of users’ identity documents, in breach of GDPR requirements.PLUrząd Ochrony Danych OsobowychGDPR€1,381,000
09 Dec 2021RESTAURANTE FUENTEBRO, S.C.The entity was fined for operating a video surveillance system without the required informational signage. The authority found this to be a breach of Article 13 GDPR.ESAEPDGDPR€1,500
21 Mar 2022RESTAURANTCNIL imposed a fine of EUR 10,000 on RESTAURANT. The case concerned a regulatory breach, with no further details provided.FRCNILGDPR€10,000
26 Sept 2023RESTART ENERGY ONE S.A.RESTART ENERGY ONE S.A. was fined by ANSPDCP in the amount of RON 40,000 for additional GDPR violations. The authority also imposed corrective measures to improve data protection processes.ROANSPDCPGDPR€8,048
26 Sept 2023RESTART ENERGY ONE S.A.RESTART ENERGY ONE S.A. was fined by ANSPDCP in the amount of EUR 25,000 for violations related to personal data processing. The case concerned non-compliance with GDPR requirements in data processing activities.ROANSPDCPGDPR€25,000
22 Jan 2020Res iudicata terjedelme a hozzáférési kérelem elbírálása kapcsánThe controller did not adequately respond to the data subject’s access request, breaching Article 15 GDPR. NAIH imposed a fine of HUF 2,000,000.HUNAIHGDPR€5,960