Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
06 Jun 2024Eni Plenitude S.p.A. Società BenefitEni Plenitude S.p.A. was fined by the Garante 6,419,631 EUR for making unsolicited promotional calls without prior consent. The company also used numbers listed in the Public Opposition Register, which constituted a breach of GDPR rules.ITGaranteGDPR€6,419,000
05 Feb 2026Dane anonimowe (X.)UODO imposed an administrative fine of PLN 6,251,471 on Dane anonimowe (X.) for breaching Article 28(3) GDPR. The company used external transport providers without prior data processing agreements and without implementing adequate organizational measures to ensure data security.PLUODOGDPR€1,481,000
01 Dec 2023ENDESA, S.A.The Spanish data protection authority imposed a EUR 6.1 million fine on ENDESA in December 2023. The case involved a security breach that led to the sale of customer personal data through Facebook ads.ESAgencia Española de Protección de DatosGDPR€6,100,000
26 Feb 2025SportadminIMY fined Sportadmin SEK 6 million after an IT attack exposed personal data of more than 2.1 million individuals, mostly children. The authority found that the company had not maintained an appropriate security level for the personal data it processed.SEIntegritetsskyddsmyndighetenGDPR€538,000
01 Jan 2022CosmoteThe Greek data protection authority imposed a €6 million fine on Cosmote under decision 4/2022. The sanction concerned inadequate security measures and retaining more data than permitted after a 2020 cyberattack.GRΑρχή Προστασίας Δεδομένων Προσωπικού ΧαρακτήραGDPR€6,000,000
17 Jun 2024FÚTBOL CLUB BARCELONAFútbol Club Barcelona was fined by the AEPD for processing biometric data without explicit consent during a mandatory member census update. The authority found breaches of GDPR Articles 9 and 35, relating to special-category data processing and data protection impact assessment requirements.ESAEPDGDPR€6,000,000
26 Aug 2020Anonymizováno (ÚOOÚ UOOU-03916/19-49)The entity was fined for sending unsolicited commercial communications without a valid legal basis. The conduct violated the Czech law on certain information society services.CZUOOUePrivacy€228,000
26 Jan 2026SportAdmin i Skandinavien ABSportAdmin i Skandinavien AB was fined by IMY 6,000,000 SEK for failing to implement appropriate technical and organizational measures to ensure an adequate level of security for personal data. The deficiency resulted in a data breach.SEIMYGDPR€564,000
16 Mar 2026Restaurant Partner PolskaThe Polish Data Protection Authority imposed an administrative fine of PLN 5,898,064 on Restaurant Partner Polska, the operator of Glovo in Poland. The authority found that the company unlawfully collected and processed scans and photos of users’ identity documents, in breach of GDPR requirements.PLUrząd Ochrony Danych OsobowychGDPR€1,381,000
19 Feb 2026Dane anonimowe (W.)UODO imposed an administrative fine of PLN 5,898,064 on Dane anonimowe (W.). The authority found that the company processed personal data without a legal basis and in a manner that was excessive and disproportionate to the stated purpose, including by collecting photos or scans of identity cards or passports.PLUODOGDPR€1,397,000
02 Feb 2017Sigue Global Service LimitedSigue Global Service Limited was fined by the Garante 5,880,000 EUR for breaches of data protection rules and anti-money laundering requirements. The authority cited money transfers carried out without proper consent, techniques used to obscure the true origin of funds, and non-compliance with AML obligations.ITGaranteGDPR€5,880,000
12 Jan 2023WhatsApp Ireland Ltd.The Irish DPC fined WhatsApp Ireland Ltd. EUR 5,500,000 in case IN-18-5-6. The decision is currently under appeal.IEDPCGDPR€5,500,000
11 Jul 2024EOS MatrixAZOP imposed a EUR 5.47 million fine on EOS Matrix for a personal data protection breach following an incident involving the data of 181,641 debtors. The case was described as a GDPR violation and the largest fine in the authority's history.HRAZOPGDPR€5,470,000
17 Apr 2023SOCIETE DEVELOPPANT UN LOGICIEL DE RECONNAISSANCE FACIALECNIL imposed a penalty of EUR 5,200,000 on SOCIETE DEVELOPPANT UN LOGICIEL DE RECONNAISSANCE FACIALE in connection with the liquidation of astreinte. The case concerns failure to comply with a prior obligation within the required timeframe, resulting in this amount being due.FRCNILGDPR€5,200,000
18 Oct 2019National Revenue Agency (Bulgaria)The Commission for Personal Data Protection imposed a fine of 5,100,000 BGN on Bulgaria’s National Revenue Agency. The sanction concerned the unauthorized disclosure and dissemination of personal data following a major security breach.BGCommission for Personal Data ProtectionGDPR€2,607,000
18 Aug 2023Személyes adatok kezelése online közszolgáltatás nyújtása soránThe supervisory authority found that the controller did not provide adequate information about the data retention period. It also unlawfully refused access to the requested call recordings, breaching GDPR Articles 12, 13, and 15.HUNAIHGDPR€13,050
19 Apr 2021BankThe Bank was fined by NAIH for breaching the principles of purpose limitation and data minimization when transferring personal data without a proper legal basis. The authority also found failures to respect the data subject's rights of access and objection.HUNAIHGDPR€13,900
27 Oct 2021ImportőrImportőr was fined by the NAIH 5,000,000 HUF for processing personal data without properly informing the data subjects and without a valid legal basis. The authority found breaches of lawfulness, transparency, accountability, and data minimization principles.HUNAIHGDPR€13,750
27 Jun 2022NAVThe Norwegian DPA fined NAV 5,000,000 NOK for making CVs available on arbeidsplassen.no without a lawful basis under the GDPR. The case concerned unauthorized processing of personal data relating to job seekers and employees.NODatatilsynetGDPR€480,000
18 Jun 2021Kiskorúra vonatkozó egészségügyi adatok közlése országos híradásbanThe authority found that the respondent disclosed the complainant’s personal data and special-category health data without a lawful basis. Several GDPR provisions were breached, and a fine of HUF 5,000,000 was imposed.HUNAIHGDPR€14,050