Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.2%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
20 Oct 2022Policlinico Casilino di RomaPoliclinico Casilino di Roma was fined by the Garante for violations related to the handling of personal data in the healthcare sector. The case concerned improper processing of patient data and privacy compliance requirements.ITGaranteGDPR€15,000
12 Dec 2025Police Service of ScotlandThe Information Commissioner's Office (ICO) fined the Police Service of Scotland £66,000 and issued a reprimand for serious failures in handling sensitive personal information. The case concerned improper handling of information requiring special protection, increasing the risk to affected individuals.GBICOGDPR€75,280
03 Oct 2024Police Service of Northern IrelandThe Police Service of Northern Ireland was fined £750,000 by the ICO for breaches of Articles 5(1)(f), 32(1) and (2) of the UK GDPR between 25 May 2018 and 14 June 2024. The case concerned insufficient protection of personal data and inadequate security of processing. The decision indicates a failure to implement appropriate technical and organisational safeguards.GBICOGDPR€890,000
14 Jan 2021Poliambulatorio Talenti S.r.l.Poliambulatorio Talenti S.r.l. was fined €2,000 by the Italian supervisory authority, Garante. The case concerned the improper handling of a data access request, which constitutes a breach of GDPR Article 5.ITGaranteGDPR€2,000
17 Jul 2025Poliambulatorio San Liberale S.r.l.The Garante imposed a EUR 12,500 fine on Poliambulatorio San Liberale S.r.l. for failing to meet information and transparency obligations in the processing of personal data, including health data. The company also did not respond to a data access request, adding a further breach of data subject rights.ITGaranteGDPR€12,500
02 Jul 2021PODEMOS PARTIDO POLÍTICOPODEMOS PARTIDO POLÍTICO was fined by the AEPD for irregularities in its video surveillance system. The cameras excessively captured public space without justification, and proper signage was missing.ESAEPDGDPR€4,000
05 Mar 2026Poczta Polska S.A.The President of the Polish Data Protection Authority imposed a fine of PLN 27,124,816 on Poczta Polska S.A. for processing personal data in connection with preparations for the presidential election at the prime minister's order. The Warsaw Regional Administrative Court overturned the decision on 2026-03-05.PLPrezes Urzędu Ochrony Danych OsobowychGDPR€6,348,000
20 Oct 2021PLUSVECINOS, S.L.PLUSVECINOS, S.L. was fined by the AEPD in the amount of 3,000 EUR for sending commercial emails without prior consent from recipients. The conduct breached Article 21 of the LSSI.ESAEPDePrivacy€3,000
11 Mar 2021Plurima s.r.l.Plurima s.r.l. was fined EUR 5,000 by the Italian data protection authority, Garante. The sanction concerned unsolicited promotional calls made to individuals whose consent was not recorded in the consent database. This conduct breached GDPR requirements for marketing-related processing.ITGaranteGDPR€5,000
11 May 2012PLEGADOS IRUÑA S.L.PLEGADOS IRUÑA S.L. was fined by the AEPD 600 EUR for sending unsolicited commercial emails. The conduct breached Article 21.1 of the LSSI, which restricts marketing communications without prior consent.ESAEPDePrivacy€600
11 Apr 2013PLD srlPLD srl was fined €100,000 by the Italian Garante. The company registered numerous phone cards to unaware third parties without providing the required data protection information.ITGaranteGDPR€100,000
29 Sept 2020PLAY ORENES, S.L.PLAY ORENES, S.L. was fined by the AEPD €20,000 for improperly positioning surveillance cameras. The cameras captured public areas, which breached data protection rules.ESAEPDGDPR€20,000
17 Mar 2023PLAY FUL KIDS, S.L.PLAY FUL KIDS, S.L. was fined by the AEPD EUR 3,000 for breaching Article 6(1) of the GDPR, which requires a lawful basis for processing personal data. The infringement was classified as very serious.ESAEPDGDPR€3,000
11 Mar 2021Planet Group spaPlanet Group spa was fined EUR 80,000 by the Garante. The authority found that the company made unsolicited promotional calls without a proper legal basis, breaching GDPR rules on data processing and privacy by design.ITGaranteGDPR€80,000
22 Dec 2016Planetel s.r.l.Planetel s.r.l. was fined by the Garante in the amount of EUR 30,000 for using inadequate authentication procedures to access telecommunication traffic data. The authority also found that required security measures for data storage were not implemented.ITGaranteGDPR€30,000
20 Jun 2022PLANET COSTA DORADA SOCIEDAD LIMITADAThe company was fined by the AEPD EUR 300 for operating video surveillance that captured public space without proper signage. The authority found a breach of GDPR Articles 5 and 13.ESAEPDGDPR€300
27 Jan 2016Planetcall s.r.l.Planetcall s.r.l. was fined €20,000 by the Garante for failing to designate data processors and for using inadequate authentication credentials. The case concerned breaches of the minimum security measures required under the Italian Data Protection Code.ITGaranteGDPR€20,000
30 Oct 2014Planetcall s.r.l.Planetcall s.r.l. was fined by the Italian data protection authority, Garante, in the amount of €20,000. The case concerned promotional phone calls made without the individuals’ prior consent, in breach of data protection rules.ITGaranteGDPR€20,000
21 Jul 2016Planet Book Service di Mario Manna & C. s.a.s.Planet Book Service di Mario Manna & C. s.a.s. was fined by the Garante for failing to respond to an information request. The conduct breached Article 157 of the Italian Data Protection Code.ITGaranteGDPR€4,000
09 Mar 2016PIXMANIA S.A.S.PIXMANIA S.A.S. was fined by the AEPD in the amount of €20,000 for sending unsolicited commercial emails to a user. The company continued sending messages despite multiple unsubscribe requests, which breached the LSSI.ESAEPDePrivacy€20,000