Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.2%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
14 Sept 2023Intesa Sanpaolo S.p.a.Intesa Sanpaolo S.p.a. was fined 42,000 EUR by the Garante for failing to provide timely access to personal data requested by a parent under GDPR Article 15. The authority said the delay resulted from an operational error that prevented timely handling of the request.ITGaranteGDPR€42,000
29 Nov 2012Enterprise Work s.r.l.Enterprise Work s.r.l. was fined by the Garante in the amount of 41,600 EUR. The case concerned the sending of unsolicited promotional faxes without valid recipient consent.ITGaranteGDPR€41,600
16 Jan 2014VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD 41,000 EUR for sending commercial communications by email and SMS without the recipients’ consent. The conduct breached Article 21.1 of the LSSI, which requires prior consent for such messages.ESAEPDePrivacy€41,000
08 Jun 2023RCS Mediagroup S.p.a.RCS Mediagroup S.p.a. was fined EUR 40,660 by the Italian Garante. The case concerned the publication of unauthorized photographs of a private individual taken inside her home, which infringed her privacy rights.ITGaranteGDPR€40,660
15 Oct 2025Dane anonimowe (B. Sp. z o.o. z siedzibą w M. za naruszenie przepisu art. 33 ust. 1 rozporządzenia 2016/679)UODO imposed an administrative fine on B. Sp. z o.o. for failing to notify the President of the Personal Data Protection Office of a personal data breach without undue delay and, at the latest, within 72 hours of becoming aware of it. The case concerns the reporting obligation under Article 33(1) GDPR.PLUODOGDPR€9,519
28 Oct 2015MUTUA MADRILEÑA AUTOMOVILISTA SOCIEDAD DE SEGUROS A PRIMA FIJAMutua Madrileña was fined 40,001 EUR by the AEPD for sending unsolicited commercial emails despite the recipient’s objection. The case concerns a breach of data protection and direct marketing rules.ESAEPDePrivacy€40,001
13 May 2015Iperal S.p.A.Iperal S.p.A. was fined EUR 40,000 by the Garante for activating 11 phone cards in the names of 5 individuals without their knowledge. The conduct breached data protection rules.ITGaranteGDPR€40,000
15 Aug 2024Coastal Windows & Conservatories (UK) LimitedCoastal Windows & Conservatories (UK) Limited made more than 18,000 unsolicited marketing calls between 1 January and 1 June 2023 to numbers registered with the TPS. The ICO and TPS received numerous complaints from people who said they had not consented to the calls or continued to receive them after asking for the calls to stop.GBICOGDPR€46,720
10 Oct 2024Service Box Group LimitedService Box Group Limited made 5,361 marketing calls to individuals in breach of regulation 21 of PECR. The ICO imposed a fine of GBP 40,000 and issued an enforcement notice.GBICOePrivacy€47,796
01 Jan 2019VODAFONE ESPAÑA, S.A.U.Vodafone España was fined 40,000 EUR by the AEPD for charging a customer for a Netflix service that had not been contracted. The authority found a breach of GDPR Article 6 due to the lack of a lawful basis for the charge and related processing.ESAEPDGDPR€40,000
20 Oct 2011Betfair Italia srlBetfair Italia srl was fined EUR 40,000 by the Garante for violations related to the omission of information on how data subjects can exercise their rights, as well as other data protection obligations. The case concerned incomplete compliance with information requirements toward users.ITGaranteGDPR€40,000
06 Sept 2023Simply Connecting LtdSimply Connecting Ltd sent 441,830 direct marketing text messages to individuals in breach of regulation 22 of PECR. The ICO imposed a £40,000 fine and issued an enforcement notice.GBICOePrivacy€46,780
14 Feb 2013Face2Face s.r.l.Face2Face s.r.l. was fined EUR 40,000 by the Italian data protection authority, Garante. The authority found that the company failed to provide the required privacy notice and did not obtain specific consent from data subjects before processing their data.ITGaranteGDPR€40,000
02 Feb 2012Casa di cura Villa Giustina s.r.l.Casa di cura Villa Giustina s.r.l. was fined 40,000 EUR by the Garante. The authority found that the company failed to submit the required notification for personal data processing activities under the Italian Data Protection Code.ITGaranteGDPR€40,000
12 Dec 2024Agenzia delle Dogane e dei MonopoliAgenzia delle Dogane e dei Monopoli was fined by the Garante in the amount of EUR 40,000 for violations related to data processing. The case concerned non-compliance with Art. 2-ter of the Italian Data Protection Code.ITGaranteGDPR€40,000
29 Apr 2025Comune di BolognaThe Garante imposed a fine of 40,000 EUR on Comune di Bologna for breaches of data protection principles. The case concerned non-compliance with requirements on lawfulness, fairness, transparency, and data minimization.ITGaranteGDPR€40,000
19 Jul 2018Go Internet S.p.AGo Internet S.p.A was fined by the Garante in the amount of 40,000 EUR for processing and retaining telephone and internet traffic data beyond the permitted period. The authority found this conduct contrary to the Italian Data Protection Code.ITGaranteGDPR€40,000
21 Dec 2018Nationale PolitieThe Dutch Data Protection Authority imposed a penalty payment on Nationale Politie for failing to regularly and proactively review log files. The authority found this breached the Police Data Act.NLAPGDPR€40,000
08 Aug 2022CAJA DE SEGUROS REUNIDOS, COMPAÑÍA DE SEGUROS Y REASEGUROS, S.A. (CASER)CASER was fined 40,000 EUR by the AEPD for modifying insurance policy data without the policyholder’s consent. The authority found that this breached GDPR data processing principles.ESAEPDGDPR€40,000
01 Dec 2024Orange România SAThe Romanian data protection authority completed an investigation in December 2024 into Orange România SA and found a breach of Article 12(3) GDPR. The case concerned failure to meet the deadline for responding to a data subject access request, resulting in a EUR 40,000 fine.ROAutoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter PersonalGDPR€40,000