Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.1%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
03 Oct 2022o persoana fizicăAn individual was fined 100 EUR for violating the General Data Protection Regulation. The case concerned a confirmed breach of obligations under the GDPR.ROANSPDCPGDPR€100
03 Oct 2022o persoana fizicăA fine of 50 EUR was imposed on an individual for violating a provision of the General Data Protection Regulation. The case was handled by ANSPDCP in Romania.ROANSPDCPGDPR€50
31 Aug 2023operator persoană fizicăA EUR 2,000 fine was imposed on an individual operator for photographing or filming a patient in a medical unit without consent. The authority also applied a corrective measure to ensure compliance of data processing operations with the GDPR.ROANSPDCPGDPR€2,000
08 Jan 2026OPÉRATEUR DE TÉLÉPHONIE MOBILECNIL imposed an administrative fine of EUR 27 million on OPÉRATEUR DE TÉLÉPHONIE MOBILE and issued an injunction. The case concerns a regulatory breach addressed by the authority’s decision.FRCNILGDPR€27,000,000
08 Jan 2026OPÉRATEUR DE TÉLÉPHONIE FIXECNIL imposed an administrative fine of EUR 15 million on a fixed-line telecom operator and issued an injunction. The case concerns a breach requiring corrective action and compliance with regulatory obligations.FRCNILGDPR€15,000,000
14 Nov 2024OPERATEUR DE TELECOMMUNICATIONSOPERATEUR DE TELECOMMUNICATIONS was issued an administrative fine of EUR 50 million and an injunction. The case concerns a CNIL decision dated 2024-11-14.FRCNILGDPR€50,000,000
30 Nov 2022OPERATEUR DE TELECOMMUNICATION FIXECNIL imposed a fine of EUR 300,000 on OPERATEUR DE TELECOMMUNICATION FIXE and issued an injunction subject to penalty payments. The case concerns a compliance breach in the area of data protection.FRCNILGDPR€300,000
01 Jan 2013OPEN COMUNICACION, S.L.OPEN COMUNICACION, S.L. was fined by the AEPD in the amount of 30,001 EUR for sending numerous unsolicited advertising emails without prior express consent from recipients. The authority also found that the company failed to provide an effective system for recipients to object to such messages, in breach of Article 21 of the LSSI.ESAEPDePrivacy€30,001
01 Jan 2023OPEN BANK, S.A.Openbank was fined by the AEPD for opening a bank account without the individual's authorization. The account was later used for fraudulent activities, indicating failures in verification and data protection controls.ESAEPDGDPR€70,000
26 Oct 2021OPEN BANK, S.A.OPEN BANK, S.A. was fined by the AEPD for using non-essential third-party cookies without prior user consent. The authority also found that the cookies could not be removed, which breached Article 22.2 of the LSSI.ESAEPDePrivacy€5,000
20 Dec 2024OpenAIThe Italian data protection authority fined OpenAI EUR 15 million for GDPR noncompliance related to ChatGPT. The 20 December 2024 decision cites issues with the legal basis for training data processing, transparency obligations, age verification, breach notification, and the security and accuracy of outputs.ITGarante per la protezione dei dati personaliGDPR€15,000,000
15 Dec 2023O nouă amendă - operator persoană fizicăA fine was imposed on an individual operator for violating GDPR provisions. The case concerned non-compliance with obligations under personal data protection rules.ROANSPDCPGDPR€200
30 Jul 2025ONEY SERVICIOS FINANCIEROS EFC, S.A.The AEPD fined ONEY Servicios Financieros EFC, S.A. 150,000 EUR for failing to adequately protect personal data. The breach led to a security incident in which a third party accessed a customer's account through a vishing attack.ESAEPDGDPR€150,000
06 Feb 2023ONEY SERVICIOS FINANCIEROS E.F.C., S.A.ONEY SERVICIOS FINANCIEROS E.F.C., S.A. was fined by the AEPD 50,000 EUR for inaccurately processing personal data. The company included incorrect debt information in credit information systems, breaching data protection principles.ESAEPDGDPR€50,000
20 Mar 2025ONE UNITED PROPERTIES S.AIn February 2025, ANSPDCP completed an investigation at ONE UNITED PROPERTIES S.A. The authority found GDPR violations and imposed a fine of 1,000 EUR.ROANSPDCPGDPR€1,000
20 Mar 2025ONE UNITED PROPERTIES S.AIn February 2025, ANSPDCP completed an investigation at ONE UNITED PROPERTIES S.A. The authority found GDPR violations and imposed a fine of EUR 1,000.ROANSPDCPGDPR€1,000
12 Nov 2014One Italia s.r.l.One Italia s.r.l. was fined €200,000 by the Garante for sending unsolicited promotional messages related to a value-added service. The authority found that proper consent and adequate information were not obtained, in breach of data protection rules.ITGaranteGDPR€200,000
06 Sept 2012One Italia S.p.A.One Italia S.p.A. was fined €20,000 by the Garante for sending promotional MMS messages without obtaining prior consent from recipients. The conduct breached Articles 23 and 130 of the Italian Data Protection Code.ITGaranteGDPR€20,000
25 Mar 2021OneDirect S.r.l.OneDirect S.r.l. was fined EUR 30,000 by the Garante. The authority found that the company sent unsolicited promotional emails despite objections and failed to respond to data subject requests.ITGaranteGDPR€30,000
12 Oct 2023Onda Più S.r.l.Onda Più S.r.l. was fined EUR 200,000 by the Garante for activating energy supply contracts without customer consent. The authority also found the use of inaccurate and outdated personal data.ITGaranteGDPR€200,000