Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
05 Mar 2026ASSOCIATION AYANT POUR OBJET DE PROMOUVOIR L'ACCÈS AUX SOINS DENTAIRES DES PERSONNES DÉMUNIES (procédure simplifiée)The CNIL imposed an administrative fine of EUR 6,000 on ASSOCIATION AYANT POUR OBJET DE PROMOUVOIR L'ACCÈS AUX SOINS DENTAIRES DES PERSONNES DÉMUNIES and issued an injunction. The case was handled under a simplified procedure.FRCNILGDPR€6,000
05 Mar 2026Poczta Polska S.A.The President of the Polish Data Protection Authority imposed a fine of PLN 27,124,816 on Poczta Polska S.A. for processing personal data in connection with preparations for the presidential election at the prime minister's order. The Warsaw Regional Administrative Court overturned the decision on 2026-03-05.PLPrezes Urzędu Ochrony Danych OsobowychGDPR€6,348,000
05 Mar 2026ASSOCIATION DE DÉFENSE DE DROITS FONDAMENTAUX(procédure simplifiée)CNIL imposed a EUR 5,100 penalty on ASSOCIATION DE DÉFENSE DE DROITS FONDAMENTAUX in connection with the liquidation of astreinte. The matter concerns enforcement of a prior obligation, with the amount arising from non-compliance.FRCNILGDPR€5,100
05 Mar 2026Altex România S.R.L.The National Supervisory Authority for Personal Data Processing imposed fines totaling EUR 8,000 on Altex România S.R.L. for GDPR violations. The case followed complaints from data subjects.ROANSPDCPGDPR€8,000
02 Mar 2026Nordic Cleaning ApSThe Danish DPA reported Klein2 ApS and Nordic Cleaning ApS to the police for failing to comply with orders to address access requests. Nordic Cleaning ApS accepted a fine notice of 60,000 DKK.DKDatatilsynetGDPR€8,031
27 Feb 2026T., za naruszenie art. 5 ust. 1 lit. f), art. 5 ust. 2 oraz art. 32 ust. 1 i 2 rozporządzenia 2016/679,The Polish DPA (UODO) imposed an administrative fine of PLN 975 on T. for failing to implement appropriate technical and organizational measures and for lacking a proper, accountable data protection policy tailored to its processing activities. The authority also noted deficiencies in transparency notices, processor agreements, access authorizations, and the record of processing activities.PLUODOGDPR€231
26 Feb 2026Groupharma s.r.l.s.Groupharma s.r.l.s. was fined EUR 3,000 by the Italian supervisory authority, Garante. The case concerned the company’s failure to respond to a former employee’s request to access and delete personal data, including photos and contact details, from its website after employment ended.ITGaranteGDPR€3,000
26 Feb 2026Ministero delle Imprese e del Made in ItalyMinistero delle Imprese e del Made in Italy was fined by the Garante €15,000 for unlawfully publishing personal data in a ranking list. The authority found breaches of data minimization and transparency principles.ITGaranteGDPR€15,000
26 Feb 2026Conservatorio “XX” di XXThe Garante fined Conservatorio “XX” di XX EUR 5,000 for processing personal data relating to criminal convictions without a valid legal basis. The authority found breaches of the GDPR and the national privacy code.ITGaranteGDPR€5,000
26 Feb 2026Radio Immagine Uno S.r.l.The Garante imposed a €10,000 fine on Radio Immagine Uno S.r.l. for failing to respond to a data subject's request to remove an online article containing personal data. The company did not comply with the right to be forgotten, resulting in a data protection breach.ITGaranteGDPR€10,000
26 Feb 2026Dante Labs S.r.l.Dante Labs S.r.l. was fined EUR 600 by the Garante for failing to provide the results of a genetic test after receiving a customer's DNA sample. Despite multiple attempts by the customer to contact the company, the results were not delivered or explained.ITGaranteGDPR€600
26 Feb 2026Depac Società Cooperativa Sociale a r.l.Depac Società Cooperativa Sociale a r.l. was fined by the Garante EUR 15,000 for unauthorized processing of employees' biometric data. The case concerned the collection and storage of fingerprint data without proper consent or a valid legal basis.ITGaranteGDPR€15,000
26 Feb 2026Ciemme S.r.l.sThe Italian Data Protection Authority fined Ciemme S.r.l.s EUR 1,000 for failing to respond to a data subject request to exercise rights of access, erasure, and objection. The case arose after unsolicited marketing calls.ITGaranteGDPR€1,000
26 Feb 2026Ministero dell’Economia e delle FinanzeThe Ministry of Economy and Finance was fined 12,000 EUR by Garante for inadequate control measures over the data processor. The authority found breaches of GDPR Articles 3, 5 and 6, as well as Article 2-ter of the Italian Privacy Code.ITGaranteGDPR€12,000
26 Feb 2026Flamel S.r.l.Flamel S.r.l. was fined by the Garante 15,000 EUR for carrying out promotional activities without a legal basis. The company used phone numbers not registered with the ROC, affecting the data of more than 500 individuals.ITGaranteGDPR€15,000
26 Feb 2026Dedalus Italia S.p.A.Dedalus Italia S.p.A. was fined EUR 32,000 by the Garante for inadequate security measures that led to a data breach. The company implemented corrective actions promptly, but prior violations were taken into account when setting the penalty.ITGaranteGDPR€32,000
26 Feb 2026Istituto Tecnico Statale L. 80014050357Istituto Tecnico Statale was fined by the Garante for breaches of data protection principles, including lawfulness, fairness, transparency, and data minimization. The school improperly published personal data on its website.ITGaranteGDPR€2,000
24 Feb 2026SIA Izdevniecība “DIENAS ŽURNĀLI”A fine of EUR 500 was imposed. The decision is final and has entered into force.LVDVIGDPR€500
24 Feb 2026Reddit, Inc.The ICO imposed a GBP 14.5 million UK GDPR fine on Reddit, Inc. for failures related to age-gating and the protection of children’s data. The matter was initially misfiled as an enforcement notice and later refiled as a monetary penalty notice.GBInformation Commissioner's OfficeGDPR€16,606,000
23 Feb 2026Reddit, Inc.The ICO imposed a penalty of 14,472,500 GBP on Reddit, Inc. for breaches of Articles 5(1)(a), 6, 8, and 35 of the UK GDPR. The case concerned unlawful personal data processing and failures to implement appropriate safeguards and a data protection impact assessment.GBICOGDPR€16,571,000