Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.2%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
11 Oct 2023B.B.B.The entity installed surveillance cameras without consent in a rented equestrian club. The recordings captured minors and disabled individuals, which constituted a privacy violation.ESAEPDGDPR€2,000
10 Oct 2023UAB RamidonasThe supervisory authority imposed a €6,000 fine on UAB Ramidonas for personal data security violations. The case concerned deficiencies in data protection controls that could have exposed individuals’ information to risk.LTValstybinė duomenų apsaugos inspekcijaGDPR€6,000
10 Oct 2023American ExpressCNIL imposed a EUR 1,500,000 fine on American Express for placing cookies without prior user consent. The case concerns breaches of GDPR and privacy law requirements.FRCNILGDPR€1,500,000
10 Oct 2023ComuneThe Italian data protection authority fined a municipality EUR 12,000 for unlawfully publishing personal data online in access request registers. Documents in the transparency section of the municipal website exposed names, protocol numbers, and other sensitive details of hundreds of citizens.ITGarante per la protezione dei dati personaliGDPR€12,000
10 Oct 2023TemuThe European Commission imposed a EUR 200 million fine on Temu under the Digital Services Act. The authority said Temu failed to identify, analyse, and assess systemic risks linked to illegal products offered on its platform.EUEuropean CommissionDSA€200,000,000
10 Oct 2023Hogeschool van Arnhem en Nijmegen (HAN)The Autoriteit Persoonsgegevens imposed a fine of EUR 175,000 on Hogeschool van Arnhem en Nijmegen (HAN). The authority found that the institution did not provide sufficient protection for students’ personal data.NLAutoriteit PersoonsgegevensGDPR€175,000
10 Oct 2023GALENICUM HEALTH, S.L.U.GALENICUM HEALTH, S.L.U. was fined EUR 500 by the AEPD for failing to display informational signage about its video surveillance system. The authority found a breach of Article 5(1)(c) GDPR in relation to transparency and proper notice.ESAEPDGDPR€500
06 Oct 2023Ítélet a NAIH-19-18-2024 sz. ügyben (Kúria Kfv.IV.37.804/2025/2)The entity was fined for improper processing of personal data in a nationwide energy efficiency program. The authority found inadequate transparency and consent procedures, as well as insufficient data security measures.HUNAIHGDPR€194,000
06 Oct 2023Texas Andreas Petersen A/SThe Danish Data Protection Authority reported Texas Andreas Petersen A/S to the police and recommended a fine of at least DKK 200,000. The case concerned the collection and sharing of website visitors' personal data without a legal basis.DKDatatilsynetGDPR€26,818
06 Oct 2023SOCIETE DE CONSEILS EN SYSTEMES ET LOGICIELS INFORMATIQUES (procédure simplifiée)CNIL imposed a fine of EUR 20,000 on SOCIETE DE CONSEILS EN SYSTEMES ET LOGICIELS INFORMATIQUES under a simplified procedure. The decision concerns a breach of personal data protection rules.FRCNILGDPR€20,000
05 Oct 2023DPP Law LtdThe Information Commissioner's Office issued a monetary penalty notice against DPP Law Ltd. The firm was fined GBP 60,000 for failing to implement appropriate technical and organisational measures to secure personal data.GBInformation Commissioner's OfficeGDPR€69,282
04 Oct 2023Amazon EuropeThe CNPD imposed a fine of EUR 746,000,000 on Amazon Europe for breaches of data protection rules. The case concerned shortcomings in the processing of personal data and compliance with GDPR requirements.LUCNPDGDPR€746,000,000
03 Oct 2023ASOCIACIÓN DE PROFESIONALES DE LA SEGURIDAD PRIVADA DE ESPAÑAThe association was fined for sending emails from personal email addresses instead of corporate ones. The authority found that this practice breached GDPR confidentiality and security requirements.ESAEPDGDPR€1,500
03 Oct 2023MAPFRE ESPAÑA COMPAÑÍA DE SEGUROS Y REASEGUROS, S.A.MAPFRE España was fined by the AEPD 1,140,000 EUR for requesting excessive personal data from a guarantor in a rental contract. The authority found breaches of GDPR data minimization and transparency principles.ESAEPDGDPR€1,140,000
03 Oct 2023Digivo Media LimitedBetween 24 March 2021 and 7 September 2021, 415,041 text messages were sent without valid consent, breaching Regulation 22 of PECR. The ICO identified the matter after reviewing debt management complaints submitted via the SPAM reporting tool.GBICOePrivacy€57,620
03 Oct 2023Utbildningsnämnden i Stockholms stad – Aspuddens skolaThe Stockholm City Education Committee was fined by IMY 800,000 SEK for unlawful camera surveillance at Aspuddens school. The authority found breaches of legality and data minimization principles, as well as a failure to provide the required information under GDPR.SEIMYGDPR€68,744
02 Oct 2023AVENTURA EN TRAMPOLINES, S.L.Aventura en Trampolines, S.L. was fined by the AEPD EUR 2,000 for breaching GDPR Article 7. The company required consent for image use without allowing users to refuse specific terms, which did not meet data protection requirements.ESAEPDGDPR€2,000
02 Oct 2023COMUNIDAD DE PROPIETARIOS A.A.A.The president of a homeowners' association shared a bank receipt containing personal data in a WhatsApp group. AEPD found a breach of confidentiality principles under GDPR and imposed a EUR 2,000 fine.ESAEPDGDPR€2,000
02 Oct 2023Cez Vânzare S.A.Cez Vânzare S.A. was fined by ANSPDCP EUR 1,000 for a data protection breach. The incident resulted in unauthorized disclosure or access to personal data, including names, correspondence addresses, and customer codes of both individuals and legal entities.ROANSPDCPGDPR€1,000
01 Oct 2023Capita plc and CPSLThe Information Commissioner's Office imposed a GBP 2,000,000 fine on Capita plc and CPSL. The case concerned data protection breaches linked to unsolicited marketing calls, indicating improper use of contact data.GBInformation Commissioner's OfficeGDPR€2,313,000