Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
18 Oct 2019National Revenue Agency (Bulgaria)The Commission for Personal Data Protection imposed a fine of 5,100,000 BGN on Bulgaria’s National Revenue Agency. The sanction concerned the unauthorized disclosure and dissemination of personal data following a major security breach.BGCommission for Personal Data ProtectionGDPR€2,607,000
21 Dec 2018Nationale PolitieThe Dutch Data Protection Authority imposed a penalty payment on Nationale Politie for failing to regularly and proactively review log files. The authority found this breached the Police Data Act.NLAPGDPR€40,000
21 Dec 2018Nationale PolitieThe Dutch Data Protection Authority imposed a penalty payment on Nationale Politie for failing to regularly and proactively review log files. The authority found this breached the Police Data Act.NLAPGDPR€40,000
14 Oct 2024National Debt Advice LimitedNational Debt Advice Limited sent 129,902 unsolicited direct marketing text messages, breaching regulation 22 of PECR. The activity generated more than 4,000 complaints to the 7726 spam reporting service. The ICO imposed a £30,000 fine and issued an enforcement notice.GBICOePrivacy€35,856
21 Aug 2018National Bank of GreeceNational Bank of Greece was fined EUR 5,000 by the HDPA for failing to maintain accurate data about its debtors. The case concerned compliance with data protection obligations.GRHDPAGDPR€5,000
09 Jan 2025National Bank of GreeceNational Bank of Greece was fined €20,000 by the HDPA. The authority found that the bank failed to provide data subjects with timely access to their personal data, breaching GDPR Articles 15 and 12.GRHDPAGDPR€20,000
20 Feb 2025NAROBESA INV, S.L.NAROBESA INV, S.L. was fined EUR 2,000 by the AEPD for failing to provide the required documentation to the data protection authority. The case concerns a breach of the cooperation duty under Article 58(1) GDPR.ESAEPDGDPR€2,000
10 Jan 2026NAROBESA INV, S.L.NAROBESA INV, S.L. was fined 1,000 EUR by the AEPD for unlawfully accessing a job applicant's credit information without consent during recruitment. The conduct breached data protection rules and occurred in the hiring process.ESAEPDGDPR€1,000
07 May 2015Nappo Nicola JolandaNappo Nicola Jolanda was fined EUR 45,000 by the Garante for activating 37 phone cards in the names of 15 individuals without their knowledge. The conduct breached data protection rules.ITGaranteGDPR€45,000
09 Jan 2023NANDIVALE, S.L.NANDIVALE, S.L. was fined by the AEPD EUR 10,000 for publishing images of minors on Instagram without parental consent. The authority found this conduct to be in breach of GDPR Article 6(1).ESAEPDGDPR€10,000
25 Jul 2022MZN HELLAS A.E.The company was fined for sending unsolicited SMS messages for marketing purposes despite the recipient's objection. This conduct breached GDPR rules on personal data processing and direct marketing.GRHDPAGDPR€5,000
07 Apr 2021MZN HELLAS A.E.The company was fined for sending unsolicited marketing SMS messages to a customer who had explicitly objected to such communications. The authority found this to be a breach of GDPR rules on data subject rights and data protection by design.GRHDPAGDPR€20,000
11 Sept 2025MY s.r.l.MY s.r.l. was fined by the Garante for operating video surveillance without proper alignment with data protection requirements. The case concerned breaches related to the processing of personal data through the camera system.ITGaranteGDPR€6,000
03 Dec 2019MYMOVILES EUROPA 2000, S.L.MYMOVILES EUROPA 2000, S.L. was fined by the AEPD €1,500 for failing to provide the required privacy information on its website. The authority found a breach of Article 13 GDPR.ESAEPDGDPR€1,500
15 Oct 2012MYID ESPAÑA S.L.MYID ESPAÑA S.L. was fined by the AEPD in the amount of 1,200 EUR for sending unsolicited commercial emails despite requests to unsubscribe. The authority found a breach of Article 21.1 of the LSSI.ESAEPDePrivacy€1,200
02 Nov 2021MYHERITAGE, LTDMYHERITAGE, LTD was fined EUR 20,000 by the AEPD for international data transfers without adequate safeguards and for unclear legal grounds for processing. The authority also found insufficient information provided to data subjects and improper handling of genetic data.ESAEPDePrivacy€20,000
01 Jan 2022MUXERS CONCEPT, S.L.MUXERS CONCEPT, S.L. was fined EUR 20,000 by the AEPD for installing an unauthorized audio recording system in employee areas. The authority found this conduct to be in breach of Article 6 of the GDPR.ESAEPDGDPR€20,000
28 Oct 2015MUTUA MADRILEÑA AUTOMOVILISTA SOCIEDAD DE SEGUROS A PRIMA FIJAMutua Madrileña was fined 40,001 EUR by the AEPD for sending unsolicited commercial emails despite the recipient’s objection. The case concerns a breach of data protection and direct marketing rules.ESAEPDePrivacy€40,001
27 Jan 2022Musicraiser S.r.l.Musicraiser S.r.l. was fined 1,000 EUR by the Garante for continuing to send newsletters to a user despite multiple requests to be removed. The case concerns a breach of data protection rules on respecting opt-out and cancellation requests for marketing communications.ITGaranteGDPR€1,000
07 Dec 2023Mushtaq RubinaThe Garante fined Mushtaq Rubina 2,000 EUR for operating a video surveillance system without adequate informational signage. The authority found a breach of GDPR transparency requirements toward recorded individuals.ITGaranteGDPR€2,000