Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-20.7%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
Timegrip ASDatatilsynet imposed an administrative fine of NOK 250,000 on Timegrip AS for denying employees access to their personal data relating to time tracking. The authority found that Timegrip effectively acted as the controller and had no valid basis to refuse the access requests.NODatatilsynet€22,435
Enel Energia SpAEnel Energia SpA was fined EUR 79.1 million by the Italian data protection authority, Garante. The case concerned misuse of personal data and was a major GDPR enforcement action.ITGarante per la protezione dei dati personaliGDPR€79,100,000
Lensa.roLensa.ro, operated by Tensa Art Design, was fined EUR 20,000 by Romania’s data protection authority, ANSPDCP. The case involved cookie-based tracking and behavioral advertising without clear user consent, as well as failure to respond to the authority’s official information requests.ROAutoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter PersonalGDPR€20,000
DPD PolskaThe President of the Personal Data Protection Office imposed an administrative fine of more than PLN 11 million on DPD Polska for GDPR violations. The authority cited the failure to conclude data processing agreements with external carriers and inadequate organizational measures to protect data security.PLPrezes Urzędu Ochrony Danych Osobowych€2,568,000
26 Jun 2026Artmark Holding SRLArtmark Holding SRL was fined by ANSPDCP 10,000 RON for sending unsolicited commercial emails without obtaining prior explicit consent from recipients. The case concerns a breach of rules on electronic marketing communications and consent requirements.ROANSPDCPePrivacy€1,908
26 Jun 2026AVIZIERO S.R.LAVIZIERO S.R.L was fined RON 5,000 by ANSPDCP for allowing the storage of information and access to information stored on user equipment when users accessed its website. The authority found this conduct to be in breach of ePrivacy requirements.ROANSPDCPePrivacylei 5,000
16 Jun 2026Dormeo Home SRLANSPDCP completed an investigation at Dormeo Home SRL in May 2026 and found a breach of GDPR provisions. As a result, a fine of EUR 1,000 was imposed.ROANSPDCPGDPR€1,000
15 Jun 2026SSG SELECT SOLUTIONS S.R.LSSG SELECT SOLUTIONS S.R.L. was fined by ANSPDCP in the amount of EUR 2,000 for GDPR violations. The investigation was completed in April 2026.ROANSPDCPGDPR€2,000
12 Jun 2026Compania Națională Poșta RomânăCompania Națională Poșta Română was fined by ANSPDCP in the amount of EUR 5,000 for GDPR violations. The case concerned non-compliance with personal data protection requirements.ROANSPDCPGDPR€5,000
04 Jun 2026ElkjøpThe Norwegian DPA, Datatilsynet, fined Elkjøp 20 million NOK for processing personal data in its customer club without valid consent. The authority found that the practice breached GDPR requirements on lawful processing.NODatatilsynetGDPR€1,844,000
29 May 2026IndaNext Hungary Korlátolt Felelősségű TársaságNAIH imposed a fine of 25,000,000 HUF on IndaNext Hungary Kft. for unlawfully publishing personal data and special category data of an individual on www.blikk.hu. The authority found no legal basis and identified breaches of GDPR Articles 6, 9, and 12.HUNAIHGDPR€70,750
29 May 2026Unicredit Bank SAUnicredit Bank SA was fined EUR 2,000 by ANSPDCP. The authority found that the bank failed to notify a personal data breach within the required 72-hour deadline.ROANSPDCPGDPR€2,000
29 May 2026Unicredit Bank SAUnicredit Bank SA was fined EUR 10,000 by ANSPDCP for violating GDPR provisions. The case concerns non-compliance with personal data protection requirements and should be considered in compliance risk assessments.ROANSPDCPGDPR€10,000
28 May 2026AgID – Agenzia per l’Italia digitaleThe Italian Data Protection Authority fined AgID €55,000 for failing to adequately inform professionals about the automatic registration of their digital domiciles. The authority found breaches of transparency and data processing principles.ITGaranteGDPR€55,000
28 May 2026Croce Rossa Italiana – Comitato regionale Toscana – Presidio Anna TorrigianiThe Italian Data Protection Authority imposed a 700 EUR fine on Croce Rossa Italiana – Comitato regionale Toscana – Presidio Anna Torrigiani. The case concerned a data protection breach during a patient's hospitalization in the orthopedics department, including improper handling of information about HIV status.ITGaranteGDPR€700
28 May 2026Comune di SciaccaComune di Sciacca was fined EUR 6,000 by the Garante for violations related to the processing and dissemination of personal data in the public sector. The case concerned improper handling of personal data within public administration activities.ITGaranteGDPR€6,000
28 May 2026Regione Autonoma della SardegnaThe Garante fined Regione Autonoma della Sardegna EUR 3,000 for sharing disciplinary sanction information with unauthorized internal units. The authority found this breached the GDPR and national data protection rules.ITGaranteGDPR€3,000
28 May 2026Action Fit di MilanoThe Garante fined Action Fit di Milano EUR 3,930 for sending unsolicited commercial emails to a customer without consent. The authority found this to be a breach of data protection rules.ITGaranteGDPR€3,930
28 May 2026Azienda Tutela della Salute per la LiguriaAzienda Tutela della Salute per la Liguria was fined by the Garante 6,000 EUR for violations related to the processing of personal data using a satellite localization system in a disciplinary procedure against an employee. The case concerned the use of data in a manner that did not comply with data protection requirements.ITGaranteGDPR€6,000
26 May 2026Mediaworks Hungary Zrt.Mediaworks Hungary Zrt. was fined by NAIH 50,000,000 HUF for publishing links to a map containing personal data and special category data, including political opinions. The authority found that the processing lacked a lawful basis.HUNAIHGDPR€140,000