Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
23 Jul 2025Agricola International SAAgricola International SA was fined EUR 5,000 by ANSPDCP for a data security breach. The incident was reported by the company itself, indicating an internally detected event that required compliance review.ROANSPDCPGDPR€5,000
08 May 2013Agro Informatica di Buracchi GinoAgro Informatica di Buracchi Gino was fined 32,000 EUR by the Garante for sending unsolicited promotional emails without prior explicit consent. The authority also found that the required privacy notice was not provided, in breach of the Italian Data Protection Code.ITGaranteGDPR€32,000
04 Sept 2024Agrotikos Elaiourgikos Synetairismos StylidasAgrotikos Elaiourgikos Synetairismos Stylidas was fined EUR 2,000 by the HDPA. The authority found breaches of data minimization and transparency principles, as well as inadequate technical and organizational measures in its video surveillance system.GRHDPAGDPR€2,000
18 Jun 2019A hozzáférési kérelem pontosítása; a hozzáférési kérelem elektronikus formában való teljesítéseThe controller did not facilitate the data subject’s right of access. It also failed to provide complete information about the personal data processed, including how to access files stored on a DVD.HUNAIHGDPR€1,550
27 Jun 2023A.I.C. ehf.A.I.C. ehf. was fined by Persónuvernd 3,500,000 ISK for registering loan defaults with Creditinfo Lánstraust hf. without meeting the required registration conditions. The case also involved defaults on loans below the minimum threshold for registration.ISPersónuverndGDPR€23,520
10 Jun 2021aiComply S.r.l.aiComply S.r.l. was fined by the Garante in the amount of EUR 20,000 for failing to implement adequate security measures. In particular, it did not use a secure network protocol, which created a risk to the confidentiality and integrity of personal data.ITGaranteGDPR€20,000
20 Nov 2014Aimon s.r.l.Aimon s.r.l. was fined EUR 32,000 by the Garante for sharing customers’ personal data with various companies without proper notice and consent. The authority found that the conduct breached privacy rules.ITGaranteGDPR€32,000
11 Apr 2025AIRE NETWORKS DEL MEDITERRÁNEO, S.L.The AEPD fined AIRE NETWORKS DEL MEDITERRÁNEO, S.L. 100,000 EUR for a data security incident. A SIM card duplication enabled unauthorized bank transactions, indicating insufficient safeguards and access controls.ESAEPDGDPR€100,000
22 Feb 2024Airone società consortile a r.l.Airone società consortile a r.l. was fined EUR 5,000 by Garante for unlawfully processing biometric data through facial recognition to monitor employee attendance. The authority found that the same purpose could have been achieved by less intrusive means.ITGaranteGDPR€5,000
11 Feb 2025A követeléskezelő társaságNAIH imposed a HUF 10 million fine on a debt collection company for continuing to process personal data after a court declared the debt time-barred. The company ignored the data subject’s deletion request and kept the case active in its system.HUNemzeti Adatvédelmi és Információszabadság HatóságGDPR€24,800
28 Oct 2025Aktia PankkiThe sanction panel of the Finnish Data Protection Ombudsman’s Office imposed an EUR 865,000 fine on Aktia Pankki for deficiencies in information security in its strong electronic identification service. The incident caused some users to see other customers’ data in services requiring strong authentication.FITietosuojavaltuutetun toimistoGDPR€865,000
18 Jun 2025Aktiebolaget Storstockholms Lokaltrafik (SL)Aktiebolaget Storstockholms Lokaltrafik (SL) was fined 75,000 SEK by IMY for processing personal data without a legal basis and special-category data without a valid exception. The authority found breaches of GDPR Articles 6 and 9.SEIMYGDPR€6,802
11 Sept 2014Alabarda Gestioni s.r.l.Alabarda Gestioni s.r.l. was fined by the Garante 2,400 EUR for processing personal data related to job applications without providing the required information notice. This breached Article 13 of the Italian Data Protection Code.ITGaranteGDPR€2,400
24 Feb 2010Alampi Carmela & C. s.n.c. di Sapone GiovannaThe company was fined for processing personal data through a video surveillance system without providing the required simplified and detailed information to data subjects. This constituted a breach of Article 13 of the Italian Data Protection Code.ITGaranteGDPR€6,000
04 Mar 2021ALAVA NORTE, S.L.ALAVA NORTE, S.L. was fined by the AEPD in the amount of 4,000 EUR for installing surveillance cameras without sufficient justification. The cameras captured both public and private spaces, which breached data protection principles.ESAEPDGDPR€4,000
16 Jul 2023ALBEN AIRPORT FACILITIES S.L.ALBEN AIRPORT FACILITIES S.L. was fined 500 EUR by the AEPD for failing to provide access to information required under Article 58.1 of the GDPR. This obstructed the data protection authority’s supervisory and investigative functions.ESAEPDGDPR€500
27 Sept 2022ALBERO FORTE COMPOSITE, S.L.The company used employees’ facial images for clocking in and out without proper notice about biometric data processing. AEPD found this to be a breach of data protection rules and imposed a 20,000 EUR fine.ESAEPDGDPR€20,000
01 May 2025ALBOR ENERGÍA S.L.ALBOR ENERGÍA S.L. was fined by the AEPD in the amount of 20,000 EUR for a data protection breach. The case concerned unauthorized subcontracting without informing the responsible party, as required by Article 28 of the GDPR.ESAEPDGDPR€20,000
01 Jan 2015ALDA GLOBAL SERVICES, S.L.ALDA GLOBAL SERVICES, S.L. was fined EUR 600 by the AEPD. The case concerned sending unsolicited commercial communications by SMS without consent, in breach of Article 21.1 of the LSSI.ESAEPDePrivacy€600
02 Jul 2024ALDI MAGYARORSZÁG ÉLELMISZER Élelmiszer Kereskedelmi Betéti TársaságALDI Magyarország was fined by the NAIH 80,000,000 HUF for failing to ensure transparency in data processing related to the purchase of alcoholic beverages. The authority found breaches of GDPR transparency and data minimization principles.HUNAIHGDPR€202,000