Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
14 Apr 2025niegoAn administrative fine of 25,255 PLN was imposed for failure to comply with an order contained in an administrative decision of the President of UODO. The case concerns non-fulfilment of an obligation imposed by the supervisory authority.PLUODOGDPR€5,893
18 Aug 2022niegoThe Polish DPA (UODO) imposed an administrative fine of PLN 4,569 on an individual. The authority found a failure to cooperate with the President of UODO and a failure to provide access to information necessary for the performance of its duties.PLUODOGDPR€967
31 Aug 2022niegoThe President of UODO imposed a fine of PLN 6,854 on an individual for processing the complainant’s image through video surveillance. The breach consisted of failing to cooperate with the authority and not providing information necessary for it to perform its duties.PLUODOGDPR€1,450
17 Mar 2016Nico MannelliNico Mannelli was fined by the Garante EUR 2,400 for inadequate video surveillance signage and for failing to inform individuals about the purpose of processing and the data controller. The authority found a breach of Article 13 of the Italian Privacy Code.ITGaranteGDPR€2,400
18 Jul 2023Nicola PetrolitoThe Garante imposed a EUR 400 fine on Nicola Petrolito for operating a video surveillance system that captured areas owned by third parties and public passageways. The authority found that the required informational signage was missing, constituting a GDPR breach.ITGaranteGDPR€400
01 Jun 2023NH Italia S.p.A.NH Italia S.p.A. was fined EUR 200,000 by the Garante for failing to appoint specific data processors responsible for the installation and maintenance of video surveillance systems. The authority found this breached the GDPR principles of lawful, fair, and transparent processing of personal data.ITGaranteGDPR€200,000
22 Mar 2024NH HOTEL GROUP S.A.NH HOTEL GROUP S.A. was fined by the AEPD EUR 10,000 for using cookies on its website without obtaining user consent. The authority found this to be a breach of the LSSI rules on cookie consent.ESAEPDePrivacy€10,000
13 Jul 2012NH HOTELES, S.A.NH HOTELES, S.A. was fined by the AEPD for sending unsolicited commercial emails to a complainant after confirming the cancellation of their personal data. The authority found a breach of Article 21.1 of the LSSI.ESAEPDePrivacy€33,001
04 Oct 2011NGI s.p.a.NGI s.p.a. was fined by the Garante 50,000 EUR for breaches of data protection rules. The authority found that the company failed to designate data processing officers, did not prepare the required security program document, and improperly retained traffic data.ITGaranteGDPR€50,000
07 Dec 2023N*** Gastronomie GmbHN*** Gastronomie GmbH was fined by the DSB EUR 20,000 for unlawfully processing personal data through video surveillance without a legal basis. The authority also found that the company failed to maintain a record of processing activities required under the GDPR.ATDSBGDPR€20,000
04 Jan 2024N*** -FußballvereinigungThe football association failed to implement appropriate technical and organizational measures for handling data deletion requests. The authority found breaches of Articles 25 and 17 GDPR and imposed a fine of EUR 11,000.ATDSBGDPR€11,000
05 Feb 2021NEXTSTEPAGENCY, S.L.NEXTSTEPAGENCY, S.L. was fined by the AEPD in the amount of 1,000 EUR for failing to provide reliable ownership information and details about data transfers to China on its website. The authority found a breach of the information obligations under Article 13 GDPR.ESAEPDGDPR€1,000
24 Jun 2021NEXTGEN FINANCIAL SERVICES S.L.NEXTGEN FINANCIAL SERVICES S.L. failed to update the address in a loan contract and did not correct inaccurate data in a credit file. The AEPD found this to be a breach of the right to data rectification and imposed a fine of 50,000 EUR.ESAEPDGDPR€50,000
22 Dec 2025NEXPUBLICA FRANCECNIL imposed a fine of 1,700,000 EUR on NEXPUBLICA FRANCE on 2025-12-22. The decision concerns serious security failures under Article 32 GDPR in the PCRM software used by public social action bodies, which processed sensitive personal data.FRCNILGDPR€1,700,000
29 Jun 2020NEW YORK COLLEGE A.ENEW YORK COLLEGE A.E was fined EUR 5,000 by the HDPA for conducting targeted phone calls without providing the required GDPR information. The authority found breaches of data processing principles and accountability obligations.GRHDPAGDPR€5,000
30 Jun 2011New Stereo In srlNew Stereo In srl was fined by the Garante 15,000 EUR for unlawful processing of personal data. The case concerned the activation of two unsolicited phone cards, in breach of Article 157 of the Italian Data Protection Code.ITGaranteGDPR€15,000
11 Apr 2025NEW GAMBLING SOLUTIONS S.R.L.In March 2025, ANSPDCP completed an investigation into NEW GAMBLING SOLUTIONS S.R.L. and found a GDPR violation. The company was fined EUR 2,000.ROANSPDCPGDPR€2,000
27 Jun 2013New Company di Scattolin LorisNew Company di Scattolin Loris was fined EUR 6,400 by the Garante for making unsolicited promotional phone calls without proper consent. The conduct breached Articles 13 and 130 of the Italian Data Protection Code.ITGaranteGDPR€6,400
14 May 2010NEW CENTER SYSTEM, S.L.NEW CENTER SYSTEM, S.L. was fined by the AEPD 1,200 EUR for sending an unsolicited commercial email. The authority found that recipients were not given a simple and free way to object to the use of their data for advertising, in breach of Article 21 of the LSSI.ESAEPDePrivacy€1,200
16 Nov 2023NEW BUY GOLD DI EMANUELE VITA & C. S.A.S.The company was fined EUR 1,000 by the Italian supervisory authority, Garante. The penalty was imposed because it operated a video surveillance system without the required information notice for data subjects, in breach of Article 13 GDPR.ITGaranteGDPR€1,000