Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21.4%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
27 Jan 2025Orange România SAOrange România SA was fined EUR 20,000 by ANSPDCP for GDPR violations. The case concerns non-compliance with personal data protection requirements, creating regulatory risk for organizations processing data in Romania.ROANSPDCPGDPR€20,000
12 Dec 2024BDM Banca S.p.A.BDM Banca S.p.A. was fined by the Italian data protection authority, Garante, in the amount of EUR 20,000. The sanction concerned the failure to provide a timely response to a data subject’s access request, which constitutes a breach of GDPR Article 15.ITGaranteGDPR€20,000
01 Jan 2023QUALITY-PROVIDER S.A.QUALITY-PROVIDER S.A. was fined 20,000 EUR by the AEPD for unlawfully obtaining personal data from a website. The data was then used for promotional purposes without the consent of the data subjects.ESAEPDGDPR€20,000
26 Oct 2017Verde Luna s.a.s. di Antonietta Minnicelli & C.Verde Luna s.a.s. was fined EUR 20,000 by the Garante. The sanction concerned the company’s failure to provide information requested by the supervisory authority in a data protection matter.ITGaranteGDPR€20,000
12 Dec 2024SOCIETE DE COMMERCE DE DETAIL D'HABILLEMENT (procédure simplifiée)The CNIL imposed an administrative fine of EUR 20,000 on SOCIETE DE COMMERCE DE DETAIL D'HABILLEMENT. The case was handled under a simplified procedure.FRCNILGDPR€20,000
01 Jan 2022MUXERS CONCEPT, S.L.MUXERS CONCEPT, S.L. was fined EUR 20,000 by the AEPD for installing an unauthorized audio recording system in employee areas. The authority found this conduct to be in breach of Article 6 of the GDPR.ESAEPDGDPR€20,000
30 Oct 2014Planetcall s.r.l.Planetcall s.r.l. was fined by the Italian data protection authority, Garante, in the amount of €20,000. The case concerned promotional phone calls made without the individuals’ prior consent, in breach of data protection rules.ITGaranteGDPR€20,000
21 Jul 2022Acqua Novara.VCO S.p.a.Acqua Novara.VCO S.p.a. was fined EUR 20,000 by the Garante for breaches related to the processing of personal data. The case concerned confidentiality and the risks arising from handling sensitive data in a workplace context.ITGaranteGDPR€20,000
20 Jul 2017Aria S.p.a.Aria S.p.a. was fined 20,000 EUR by the Garante. The authority found a data protection breach for failing to designate employees as data processors.ITGaranteGDPR€20,000
01 Jun 2023AUSL Toscana Sud EstThe Garante fined AUSL Toscana Sud Est 20,000 EUR for the unlawful dissemination of a patient's health data. The authority found a breach of data protection principles.ITGaranteGDPR€20,000
27 Nov 2024Azienda Sanitaria provinciale di EnnaAzienda Sanitaria provinciale di Enna was fined by the Garante 20,000 EUR for publishing employees’ personal data without a legal basis. The disclosure included details on additional payments, sickness absences, and union rights, breaching the GDPR and the national privacy code.ITGaranteGDPR€20,000
13 Nov 2025GROUPEMENT D'INTERET ECONOMIQUE (GIE) EXERCANT UNE ACTIVITE D'ORGANISATION, DE DEVELOPPEMENT ET DE PROMOTION DE CENTRES COMMERCIAUX (procédure simplifiée)The CNIL imposed an administrative fine of EUR 20,000 on a GIE engaged in the organization, development, and promotion of shopping centers. The case was handled under a simplified procedure.FRCNILGDPR€20,000
08 Mar 2018Tekne Progetti s.r.l.Tekne Progetti s.r.l. was fined for failing to respond to an information request from the Garante concerning its data processing activities. The conduct was found to violate Article 164 of the Italian Privacy Code.ITGaranteGDPR€20,000
11 Apr 2024Istituto Nazionale Previdenza Sociale - INPSThe Italian Data Protection Authority fined INPS EUR 20,000 for violating data protection principles. The case concerned the improper handling of candidates’ personal data in a public competition.ITGaranteGDPR€20,000
03 May 2018Ordinanza ingiunzione - 3 maggio 2018 [9023941]A fine of EUR 20,000 was imposed for failing to notify the Garante about the processing of geolocation data collected through GPS devices. The case concerns a breach of the Italian Data Protection Code.ITGaranteGDPR€20,000
19 Feb 2021SERVICIOS LOGÍSTICOS MARTORELL SIGLO XXI, S.L.The company was fined by the AEPD for deploying a biometric fingerprint system for employee attendance control without carrying out a data protection impact assessment. The authority found this to be a breach of Article 35 GDPR because the processing involved biometric data requiring prior risk assessment.ESAEPDGDPR€20,000
16 May 2018Conafi Prestitò s.p.a.Conafi Prestitò s.p.a. was fined by the Garante for failing to notify certain data processing activities related to loan management. The breach concerned obligations under the Italian Data Protection Code.ITGaranteGDPR€20,000
25 Sept 2025Azienda Ospedaliero Universitaria di FerraraAzienda Ospedaliero Universitaria di Ferrara was fined EUR 20,000 by the Garante for irregularities in the handling of personal data in its health dossier system. The authority found that the organization failed to implement adequate measures to protect data privacy.ITGaranteGDPR€20,000
21 Nov 2022ING Bank NV Amsterdam Sucursala BucureștiANSPDCP completed an investigation into ING Bank NV Amsterdam Bucharest Branch and found a breach of GDPR provisions. The case was opened following a data breach notification submitted by the controller.ROANSPDCPGDPR€20,000
14 Sept 2023Shardana Working Soc. Coop. a r.l.Shardana Working Soc. Coop. a r.l. was fined by the Garante 20,000 EUR for failing to fully comply with data access requests. The authority found a breach of Article 15 GDPR.ITGaranteGDPR€20,000