Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.4%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
11 Apr 2024Innova Camera – Azienda speciale della Camera di commercio, industria, artigianato e agricoltura di RomaInnova Camera was fined by the Garante EUR 25,000 for inadequate data security measures. The breach resulted in personal data being accessed and published online following an SQL Injection attack.ITGaranteGDPR€25,000
08 Jul 2021Azienda ospedaliero-universitaria SeneseAzienda ospedaliero-universitaria Senese was fined by the Garante 25,000 EUR for violations related to data breaches involving health data and patient information. The case concerned the handling of sensitive data and required assessment of compliance with data protection obligations.ITGaranteGDPR€25,000
09 Oct 2025EON ENERGIE ROMANIA S.A.ANSPDCP completed an investigation at EON ENERGIE ROMANIA S.A. and found a breach of GDPR provisions. As a result, an administrative fine of EUR 25,000 was imposed.ROANSPDCPGDPR€25,000
18 Oct 2024X, ul.UODO imposed an administrative fine of PLN 25,000 on X, ul. for breaching Article 37(1)(a) and Article 37(7) of Regulation 2016/679. The authority also ordered the processing operations to be brought into compliance with GDPR requirements.PLUODOGDPR€5,803
05 Aug 2016LinguaphoneLinguaphone was fined 25,000 EUR by the Greek HDPA for sending unsolicited marketing emails without prior recipient consent. The conduct breached Article 11 of Law 3471/2006.GRHDPAePrivacy€25,000
01 Jan 2024BONTECU DISTRIBUCIONES, S.L.U.BONTECU DISTRIBUCIONES, S.L.U. was fined by the AEPD for processing personal data without consent and for failing to have proper data processing agreements in place. The case concerned a complainant who received an unsolicited contract from Factor Energía.ESAEPDGDPR€25,000
14 Apr 2021MASTER DISTANCIA S.A.MASTER DISTANCIA S.A. was fined EUR 25,000 by the AEPD for unlawfully processing personal data by including it in credit information systems without a valid legal basis. The authority found a breach of GDPR Article 6.ESAEPDGDPR€25,000
01 Jan 2025FEMXA FORMACIÓN, S.L.FEMXA FORMACIÓN, S.L. was fined by the AEPD 25,000 EUR for requiring a full copy of a student's ID during course enrollment. The authority found the data request unnecessary and inconsistent with data protection principles.ESAEPDGDPR€25,000
24 Nov 2025SIA "EUROPARK LATVIA"A fine of EUR 25,000 was imposed. The decision has been appealed.LVDVIGDPR€25,000
17 Jul 2025Juna S.r.l.Juna S.r.l. was fined €25,000 by the Garante for making repeated unwanted and fraudulent promotional calls to individuals. The conduct breached data protection principles, including lawful and fair processing requirements.ITGaranteGDPR€25,000
09 May 2024Provvedimento del 9 maggio 2024 [10027595]The authority imposed a fine on an anonymized healthcare entity for unauthorized access to patient health records by personnel without proper authorization. The case concerned GDPR requirements on data protection and processing security.ITGaranteGDPR€25,000
12 Feb 2015Aloisio AngeloAloisio Angelo was fined EUR 25,000 by the Italian data protection authority, Garante. The case involved activating 15 phone cards in the names of 5 individuals without their knowledge, which breached data protection rules.ITGaranteGDPR€25,000
04 Apr 2024SOCIETE AYANT POUR ACTIVITE LA PROSPECTION COMMERCIALE PAR COURRIEL POUR LE COMPTE D'ANNONCEURSThe CNIL imposed EUR 25,000 on SOCIETE AYANT POUR ACTIVITE LA PROSPECTION COMMERCIALE PAR COURRIEL POUR LE COMPTE D'ANNONCEURS as a liquidation of a penalty. The measure relates to non-compliance with a prior obligation and is enforcement in nature.FRCNILGDPR€25,000
26 Sept 2023RESTART ENERGY ONE S.A.RESTART ENERGY ONE S.A. was fined by ANSPDCP in the amount of EUR 25,000 for violations related to personal data processing. The case concerned non-compliance with GDPR requirements in data processing activities.ROANSPDCPGDPR€25,000
25 Mar 2025NTT DATA ROMÂNIA S.A.NTT DATA ROMÂNIA S.A. was fined by ANSPDCP in the amount of EUR 25,000 for GDPR violations. The case concerned non-compliance with personal data protection requirements.ROANSPDCPGDPR€25,000
29 Apr 2022Fire Brigade HeadquartersA fine was imposed for unlawful processing of personal data, which breached data protection principles and security obligations. The case concerned failures to ensure compliance with data protection requirements.GRHDPAGDPR€25,000
17 Oct 2024AziendaThe company was fined for failing to implement adequate security measures, which led to a data breach affecting a large number of individuals. The case indicates insufficient protection of personal data and elevated risk to data subjects.ITGaranteGDPR€25,000
27 Feb 2025Istarski vodovod d.o.o.Istarski vodovod d.o.o. was fined by AZOP EUR 25,000 for failing to implement adequate technical security measures. The deficiencies included the absence of two-factor authentication and monitoring systems, which led to unauthorized access and a data breach.HRAZOPGDPR€25,000
23 Aug 2022Anonymisiert (DSB 2022-0.585.764)The responsible party unlawfully processed personal data by installing a hidden WiFi camera in a public restroom. This breached the GDPR principles of lawfulness, purpose limitation, and data minimization, and the data subjects were not informed.ATDSBGDPR€25,000
01 Jan 2024GASEXPRESS PATRAIX, S.L.GASEXPRESS PATRAIX, S.L. was fined by the AEPD 25,000 EUR for allowing unauthorized access to previous users' data in its automated gas station system. The exposed information included DNI numbers and partial credit card numbers.ESAEPDGDPR€25,000