Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
21 Feb 2026VERTI ASEGURADORA, COMPAÑÍA DE SEGUROS Y REASEGUROS, S.A.VERTI Aseguradora was fined by the AEPD €5,000 for sending promotional emails without providing a simple and free way for recipients to opt out. The authority found this to be a breach of Article 21.2 of the LSSI.ESAEPDePrivacy€5,000
20 Feb 2026Szegedi TudományegyetemSzegedi Tudományegyetem was fined HUF 2,000,000 by NAIH for GDPR breaches in data processing related to dormitory admissions. The authority found a lack of proper legal basis, insufficient transparency, and failure to respect data minimization.HUNAIHGDPR€5,260
20 Feb 2026VodafoneThe Greek Data Protection Authority fined Vodafone EUR 30,000 for GDPR breaches related to a subscriber’s request to access recorded phone conversations. The authority found violations of transparency obligations under Article 12 and of the rights of access and restriction of processing under Articles 15 and 18 GDPR.GRΑρχή Προστασίας Δεδομένων Προσωπικού ΧαρακτήραGDPR€30,000
19 Feb 2026Hrvatska agencija za nekretnineAZOP imposed an administrative fine of EUR 100,000 on a Croatian real estate agency for GDPR breaches. The authority found unlawful retention of personal data of 11,887 clients after the processing purpose had expired, processing without a legal basis, and inadequate technical and organizational measures.HRAZOPGDPR€100,000
19 Feb 2026Dane anonimowe (W.)UODO imposed an administrative fine of PLN 5,898,064 on Dane anonimowe (W.). The authority found that the company processed personal data without a legal basis and in a manner that was excessive and disproportionate to the stated purpose, including by collecting photos or scans of identity cards or passports.PLUODOGDPR€1,397,000
18 Feb 2026ALÍA GESTIÓN INTEGRAL DE SERVICIOS, S.L.ALÍA GESTIÓN INTEGRAL DE SERVICIOS, S.L. was fined EUR 250,000 by the AEPD for a data protection breach. The incident involved unauthorized access to the internal network after VPN credentials were compromised.ESAEPDGDPR€250,000
16 Feb 2026KONECTA BTO, S.L.KONECTA BTO, S.L. was fined by the AEPD EUR 500,000 for a personal data breach. The case involved unauthorized access to personal data, which breached the confidentiality principle under Article 5(1)(f) of the GDPR.ESAEPDGDPR€500,000
13 Feb 2026Dane anonimowe (Komitet Wyborczy Kandydata na Prezydenta Rzeczypospolitej Polskiej M. W.)UODO imposed a fine of 35,582 PLN on the Election Committee of Presidential Candidate M. W. The authority found that campaign activities infringed the privacy of other individuals by using their personal data. The right to present truthful information about a candidate does not justify such processing.PLUODOGDPR€8,442
12 Feb 2026Sportitalia Società Sportiva Dilettantistica a.r.l.Sportitalia Società Sportiva Dilettantistica a.r.l. was fined EUR 30,000 by the Garante for violations related to the processing of personal data in promotional emails. The authority found that the company did not comply with GDPR requirements in connection with these marketing communications.ITGaranteGDPR€30,000
12 Feb 2026Comune di AnconaThe Garante fined Comune di Ancona EUR 3,000 for failing to ensure lawful, fair, and transparent processing of personal data. The authority also found that no proper contract was in place with a data processor, in breach of GDPR Articles 5 and 28.ITGaranteGDPR€3,000
12 Feb 2026Conversion Media S.r.l.Conversion Media S.r.l. was fined EUR 10,000 by the Garante for failing to meet data protection obligations. The case concerned telemarketing activities in which required transparency and information duties toward data subjects were not fulfilled.ITGaranteGDPR€10,000
12 Feb 2026Comune di AversaThe Garante fined Comune di Aversa 3,000 EUR for failing to communicate the contact details of the Data Protection Officer. The case concerns Article 37 GDPR and the obligation to make DPO contact information available.ITGaranteGDPR€3,000
12 Feb 2026Provvedimento del 12 febbraio 2026 [10225084]The Garante fined a retail business for failing to provide adequate informational signage for its video surveillance system. The authority found a breach of data protection rules because individuals on the premises were not properly informed about the processing of their personal data.ITGaranteGDPR€2,000
12 Feb 2026Comune di Mazara del ValloComune di Mazara del Vallo was fined EUR 4,000 by the Garante for breaches of data protection principles. The authority found that the municipality failed to provide adequate information to data subjects and did not carry out a data protection impact assessment for its video surveillance system.ITGaranteGDPR€4,000
12 Feb 2026Provvedimento del 12 febbraio 2026 [10225110]The Garante imposed a EUR 1,000 fine for using a video surveillance system without providing the required information notice to data subjects. The case concerned a breach of GDPR transparency obligations.ITGaranteGDPR€1,000
12 Feb 2026Comune di CoccaglioComune di Coccaglio was fined EUR 6,000 for using surveillance footage for disciplinary purposes without informing employees. The authority also found that no data protection impact assessment had been carried out, in breach of data protection rules.ITGaranteGDPR€6,000
12 Feb 2026Depurazione Acqua S.r.l.Depurazione Acqua S.r.l. was fined by the Garante for carrying out promotional activities without a valid legal basis. The case concerns GDPR breaches related to data processing and consent.ITGaranteGDPR€15,000
12 Feb 2026Unleadmited S.r.l.Unleadmited S.r.l. was fined EUR 5,000 by the Garante for violations linked to aggressive telemarketing practices. The authority found non-compliance with data protection requirements.ITGaranteGDPR€5,000
12 Feb 2026Acea Energia S.p.A.Acea Energia S.p.A. was fined by the Garante 2,000,000 EUR for processing inaccurate and outdated personal data of customers. This led to the activation of unsolicited energy supply contracts, indicating significant deficiencies in data quality controls.ITGaranteGDPR€2,000,000
12 Feb 2026Ristorante pizzeria CN 45The Garante fined Ristorante pizzeria CN 45 2,000 EUR for operating a video surveillance system without proper compliance. The case concerns GDPR breaches related to the lawful operation and implementation of CCTV monitoring.ITGaranteGDPR€2,000