Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.2%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
19 Oct 2017Pittaluga servizio containers S.p.A.Pittaluga servizio containers S.p.A. was fined by the Garante €8,000 for using a geolocation system on its vehicles without full compliance with data protection rules. The case concerned improper processing of location data linked to vehicles or employees.ITGaranteGDPR€8,000
24 Nov 2023Pitagorasz Oktatási Stúdió Kft.Pitagorasz Oktatási Stúdió Kft. was fined by NAIH for processing minors' personal data without a valid legal basis. The authority found breaches of GDPR principles, including accountability, purpose limitation, and transparency.HUNAIHGDPR€1,315
04 Apr 2022Piraeus Bank S.A.Piraeus Bank S.A. was fined by the HDPA 10,000 EUR for breaching the principle of data confidentiality. The bank sent debit card transaction notifications to incorrect email addresses, failed to notify the authority of the breach, and did not take timely corrective action.GRHDPAGDPR€10,000
12 Jun 2023Piraeus Bank S.A.Piraeus Bank S.A. was fined by the HDPA in the amount of 100,000 EUR for failing to implement appropriate technical and organizational measures. The authority found that the bank did not ensure data protection by design and by default.GRHDPAGDPR€100,000
12 Jun 2023Piraeus Bank S.A.Piraeus Bank S.A. was fined 10,000 EUR by the HDPA. The authority found that the bank did not adequately satisfy the data subject’s right of access.GRHDPAGDPR€10,000
12 Jun 2023Piraeus Bank S.A.Piraeus Bank S.A. was fined by the HDPA EUR 100,000 for processing personal data without a legal basis. The breach affected a large number of data subjects, which increases its compliance significance.GRHDPAGDPR€100,000
23 Jun 2025Piraeus Bank S.A.Piraeus Bank S.A. was fined by the HDPA 50,000 EUR for unlawfully transferring personal data to third parties without the data subject's consent. The authority found breaches of GDPR principles of lawfulness and accuracy.GRHDPAGDPR€50,000
18 Dec 2025Pioneer Hi-Bred Italia Sementi s.r.l.Pioneer Hi-Bred Italia Sementi s.r.l. was fined by the Garante 120,000 EUR for installing telematic devices in company vehicles to monitor employees' driving behavior. The authority found that the processing lacked proper data protection safeguards and privacy information.ITGaranteGDPR€120,000
26 Feb 2021PINTODIS, S.L.PINTODIS, S.L. was fined by the AEPD for installing surveillance cameras that recorded employees in private areas without sufficient justification. The authority found this to be a breach of data protection principles.ESAEPDGDPR€10,000
07 Mar 2024Pinnacle Life LimitedBetween 5 May 2021 and 5 May 2022, the company made 47,998 connected unsolicited direct marketing calls to subscribers registered with the TPS who had not consented to receive such calls. Four complaints were submitted, and the ICO imposed a fine of 80,000 GBP.GBICOGDPR€93,624
07 May 2024PINKGREEN BARCELONA, S.L.PINKGREEN BARCELONA, S.L. was fined by the AEPD 4,000 EUR for disclosing personal data of individuals in responses to negative Google reviews. The authority found that the processing breached Articles 6 and 9 of the GDPR.ESAEPDGDPR€4,000
29 Apr 2026Pianeta s.r.l.Pianeta s.r.l. was fined by the Garante 34,000 EUR for unlawfully processing personal data linked to a loyalty card program. The data were used to initiate disciplinary action against an employee, which breached GDPR requirements.ITGaranteGDPR€34,000
31 Mar 2016Pia GiordanoPia Giordano was fined by the Garante for collecting personal data through her website without providing users with the required information notice. The authority found a breach of Article 13 of the Italian Data Protection Code.ITGaranteGDPR€2,400
01 Jan 2023PHONE HOUSEPHONE HOUSE was fined by the AEPD for failing to ensure data integrity and confidentiality. The breach resulted in a data incident caused by a cyberattack.ESAEPDGDPR€6,500,000
17 Nov 2025PGS SOFA & CO SRLIn October 2025, ANSPDCP completed an investigation at PGS SOFA & CO SRL and found a GDPR violation. The authority imposed a fine of EUR 8,000.ROANSPDCPGDPR€8,000
27 Nov 2025PFA Nițu A. Cleopatra – Expert contabilThe National Supervisory Authority for Personal Data Processing fined PFA Nițu A. Cleopatra – Expert contabil EUR 2,000 for GDPR violations. The case concerned non-compliant processing of personal data.ROANSPDCPGDPR€2,000
22 May 2018Pettirossi AngeloDr Pettirossi Angelo was fined by the Garante for failing to implement minimum security measures for personal data protection. The breach allowed unauthorized access to the healthcare system.ITGaranteGDPR€10,000
06 Apr 2020PETROLIS INDEPENDENTS, S.L.PETROLIS INDEPENDENTS, S.L. was fined by the AEPD in the amount of 3,000 EUR for failing to comply with data protection rules regarding cookie policies on its website. The case concerned information requirements and the compliance of cookie mechanisms with privacy rules.ESAEPDePrivacy€3,000
11 Dec 2023PERSONNALITE POLITIQUE (procédure simplifiée)The CNIL imposed a EUR 3,000 fine on PERSONNALITE POLITIQUE and issued an injunction. The case was handled under a simplified procedure.FRCNILGDPR€3,000
01 Jan 2020PERSONAL MARK, S.L.PERSONAL MARK, S.L. was fined by the AEPD 10,000 EUR for failing to diligently delete personal data from its databases despite the complainant’s requests. The case indicates inadequate handling of data erasure obligations.ESAEPDGDPR€10,000