Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.4%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
31 Oct 2019Partito Democratico, Coordinamento Metropolitano di FirenzePartito Democratico, Coordinamento Metropolitano di Firenze was fined by the Garante €4,000 for a data protection breach. The incident resulted from a cyber attack on its website that exposed personal data of party members.ITGaranteGDPR€4,000
22 Jun 2020PARTIT DELS SOCIALISTES DE CATALUNYA (PSC-PSOE)PSC-PSOE was fined by the AEPD 5,000 EUR for using personal data obtained in a doctor-patient relationship to send requests for political support. The authority found this breached purpose limitation rules for data processing.ESAEPDGDPR€5,000
04 Dec 2025PARTI POLITIQUE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 5,000 on PARTI POLITIQUE under a simplified procedure and issued an injunction. The case concerns a breach of rules supervised by the CNIL.FRCNILGDPR€5,000
15 Mar 2023Partidul Uniunea Salvați RomâniaThe fine was imposed for a data security breach involving the loss of confidentiality and integrity of data stored on a server. The incident resulted from a phishing attack that compromised the system.ROANSPDCPGDPR€4,000
19 Apr 2023Partidul Uniunea Salvați RomâniaThe National Supervisory Authority imposed a fine on Partidul Uniunea Salvați România (USR) for publishing personal data of persons with disabilities on its website without a legal basis. The authority found a breach of personal data processing principles.ROANSPDCPGDPR€3,000
07 Jul 2025Partidul Alianța pentru Unirea Românilor (AUR)Partidul Alianța pentru Unirea Românilor (AUR) was fined €10,000 for violations related to data security breaches reported by the party. The case concerned shortcomings in the protection and safeguarding of personal data.ROANSPDCPGDPR€10,000
03 Feb 2026Partidul Alianța pentru Unirea Românilor (AUR)The National Supervisory Authority for Personal Data Processing imposed a fine on the political party AUR for GDPR violations. The case concerned non-compliance with personal data protection requirements.ROANSPDCPGDPR€1,000
07 Jul 2025Partidul Alianța pentru Unirea Românilor (AUR)Partidul Alianța pentru Unirea Românilor (AUR) was fined EUR 15,000 by ANSPDCP for violations related to data security breaches. The case concerned reported data security incidents within the political party.ROANSPDCPGDPR€15,000
14 Jul 2023PARTIDO POPULARPARTIDO POPULAR was fined by the AEPD 5,000 EUR for using an individual's image without consent in its electoral program. The case concerns a breach of data protection rules.ESAEPDGDPR€5,000
24 May 2023PARTIDO LOCAL DE VILLANUEVA DEL PARDILLOPartido Local de Villanueva del Pardillo was fined EUR 500 by the AEPD for publishing an image on Facebook without the data subject's consent. The authority found a breach of Article 6(1) GDPR.ESAEPDGDPR€500
31 Dec 2024PARTICULIERS (procédure simplifiée)An administrative fine of EUR 5,000 was imposed by the CNIL. The case was handled under a simplified procedure.FRCNILGDPR€5,000
31 Jan 2024PARTICULIER (procédure simplifiée)CNIL imposed an administrative fine of EUR 500 on PARTICULIER under a simplified procedure. The case concerned a regulatory breach, with no further details provided in the record.FRCNILGDPR€500
22 May 2018Parnofiello AntonellaParnofiello Antonella, a general practitioner, was fined for failing to implement minimum security measures to protect personal and sensitive data. This allowed unauthorized access to a healthcare system.ITGaranteGDPR€10,000
21 Apr 2021ParkkiPateThe Finnish Data Protection Ombudsman fined ParkkiPate EUR 70,000 for GDPR violations. The case concerned data minimization, identification of data subjects, and the handling of access rights.FITSVGDPR€70,000
04 Jul 2013Parco Faunistico Le Cornelle S.r.l.Parco Faunistico Le Cornelle S.r.l. was fined by the Garante EUR 2,400 for collecting personal data through a website contact form without providing the required privacy notice. The authority found a breach of Article 13 of the Italian Data Protection Code.ITGaranteGDPR€2,400
08 Aug 2014PARAMOUNT A.E.The company was fined EUR 5,000 by the HDPA for processing publicly available personal data without consent. The authority found a breach of the principles of lawful data collection and proportionality.GRHDPAGDPR€5,000
25 Apr 2016PARABEBES SERVICIOS INFANTILES Y PREMAMÁ, S.L.The entity was fined by the AEPD for sending unsolicited commercial emails to a complainant. The authority found a breach of Article 21.1 of the LSSI.ESAEPDePrivacy€2,900
13 Mar 2014Paolo ZaniniPaolo Zanini was fined EUR 4,000 by the Garante for sending unsolicited promotional faxes. The conduct breached data protection rules and the requirement for prior consent for marketing communications.ITGaranteGDPR€4,000
07 Mar 2013Paolo RanieriPaolo Ranieri was fined 6,400 EUR by the Italian data protection authority, Garante. The sanction concerned sending an electoral email without the required information and without obtaining consent from recipients.ITGaranteGDPR€6,400
23 Mar 2023Paolo MeloniThe condominium administrator, Paolo Meloni, was fined for disclosing to all residents that a family had tested positive for COVID-19. The authority found this to be a breach of data protection rules.ITGaranteGDPR€2,000