Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.4%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
07 Jul 2025AURThe Romanian data protection authority imposed two fines on AUR totaling EUR 25,000. The sanctions concerned unauthorized access to supporters' personal data in the AUR app and unlawful collection of personal data on campaign platforms.ROAutoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter PersonalGDPR€25,000
19 Dec 2025ORANGE ESPAGNE, S.A.U.ORANGE ESPAGNE, S.A.U. was fined by the AEPD 25,000 EUR for sending invoices to a person who was not a customer and for failing to properly delete their data after a request. The authority found breaches of data accuracy and the right to erasure under GDPR Articles 5(1)(d) and 17.ESAEPDGDPR€25,000
29 Jun 2018BANCO BILBAO VIZCAYA ARGENTARIA, S.A.Banco Bilbao Vizcaya Argentaria, S.A. was fined by the AEPD EUR 25,000 for sending unsolicited commercial messages. The authority found that recipients were not provided with a free opt-out mechanism.ESAEPDePrivacy€25,000
05 Feb 2026Gemeente DelftGemeente Delft processed personal data without a sufficient legal basis. It also processed special categories of personal data without a valid exception, breaching GDPR principles.NLAPGDPR€25,000
14 Apr 2011Trentino Trasporti Esercizio S.p.A.Trentino Trasporti Esercizio S.p.A. was fined by the Garante 25,000 EUR for collecting personal data through web forms without providing the required privacy notice. This constituted a breach of Article 13 of the Italian Data Protection Code.ITGaranteGDPR€25,000
31 Aug 2023Robin S.r.l.The Garante fined Robin S.r.l. 25,000 EUR for publishing a photograph of minors with insufficient anonymization. The case concerns a breach of personal data protection rules applicable to children.ITGaranteGDPR€25,000
05 Jan 2021DKN.5131.6.2020StatusprawomocnaTytuUODO imposed a fine of PLN 25,000 on the University for failing to report a personal data breach to the President of UODO. The institution also did not notify the affected individuals about the breach.PLUODOGDPR€5,498
15 Nov 2012Gruppo Ro.Ri s.r.l.Gruppo Ro.Ri s.r.l. was fined by the Garante for failing to notify the cessation of data processing after the merger of Casa di cura S. Teresa del Bambin Gesù s.r.l. The authority found a breach of Article 38 of the Italian Data Protection Code.ITGaranteGDPR€25,000
18 Dec 2025TELCOM BUSINESS SOLUTIONS S.L.TELCOM BUSINESS SOLUTIONS S.L. was fined by the AEPD for attempting to process live and biometric data without prior consent. After a purchase, users were redirected to a US-based company for identity verification.ESAEPDGDPR€25,000
05 Feb 2026Gemeente HilversumThe Autoriteit Persoonsgegevens found that Gemeente Hilversum processed personal data without a valid legal basis during an investigation into Muslim residents and organizations. The municipality accepted an administrative fine of 25,000 EUR and acknowledged responsibility.NLAutoriteit PersoonsgegevensGDPR€25,000
01 Jan 2019GLOVOAPP23, S.L.GLOVOAPP23, S.L. was fined by the Spanish data protection authority, AEPD, in the amount of €25,000. The authority found a breach for failing to appoint a Data Protection Officer as required by Article 37 of the GDPR.ESAEPDGDPR€25,000
01 Feb 2025Automobilus International S.R.L.The Romanian data protection authority fined Automobilus International S.R.L. 24,885 RON after concluding its investigation in February 2025. It found breaches of GDPR Articles 32(1) and 32(2) due to inadequate technical and organizational security measures following a personal data breach.ROAutoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter PersonalGDPR€5,000
12 Nov 2024Dane anonimowe (X. w Y.)UODO imposed an administrative fine of PLN 24,555 on Anonymous entity (X. in Y.) for breaches of Articles 24(1), 25(1), and 32(1)-(2) of the GDPR. The authority also ordered the processing operations to be brought into compliance with Regulation (EU) 2016/679.PLUODOGDPR€5,644
06 Feb 2014Oreiade s.r.l.Oreiade s.r.l. was fined by the Garante for installing a video surveillance system at Hotel Blu Inn without adequate safeguards. The authority found a breach of data protection rules.ITGaranteGDPR€24,400
17 May 2023Ministero delle infrastrutture e dei trasportiThe Ministry of Infrastructure and Transport was fined by the Garante for improper online disclosure of personal data. The authority found a breach of GDPR transparency obligations.ITGaranteGDPR€24,000
04 Mar 2010Enel s.p.a.Enel s.p.a. was fined EUR 24,000 by the Garante for failing to respond to a request for information concerning data protection. The breach concerned Articles 157 and 164 of the Italian Data Protection Code.ITGaranteGDPR€24,000
25 Jun 2015San Bartolo s.r.l.San Bartolo s.r.l. was fined by the Garante for processing employees’ biometric data without prior notification and without the required preliminary verification. The case concerns a breach of privacy rules governing special-category data.ITGaranteGDPR€24,000
15 Nov 2012Gruppo Ro.Ri. s.r.l.The Garante fined Gruppo Ro.Ri. s.r.l. 24,000 EUR for inadequate data protection measures linked to its video surveillance systems. The company also failed to provide proper information to data subjects as required by the privacy code.ITGaranteGDPR€24,000
06 Jun 2024Azienda Usl RomagnaThe Garante fined Azienda Usl Romagna EUR 24,000 for data protection violations related to the management of health data. The case concerned irregularities in the processing of sensitive data, which requires heightened safeguards and GDPR compliance.ITGaranteGDPR€24,000
20 Apr 2023Dane anonimowe (Rzecznika Dyscyplinarnego Izby Adwokackiej w X.)UODO imposed a fine of PLN 23,580 on an anonymous entity for failing to implement appropriate technical and organizational measures. The authority also found a lack of regular testing, measuring, and evaluation of the effectiveness of those measures in relation to processing data using external storage media.PLUODOGDPR€5,114