FineMeFine Intelligence
Enforcement case tracker

Landmark decisions

15 enforcement cases. Database records show verified, source-linked cases; fallback examples remain for local development.

Google (Alphabet)DG COMPCompetitionEU · 2018
EU Competition — TFEU Art. 102

Google Android — illegal tying of Google Search and Chrome to Android OEM agreements, foreclosing competition.

Fine/max: 86.8%Investigation: 36moAppeal: Upheld (reduced to €4.125B on appeal)
€4.34B
imposed
Google ShoppingDG COMPCompetitionEU · 2017
EU Competition — TFEU Art. 102

Abuse of dominant position — self-preferencing Google Shopping results over rival comparison services.

Fine/max: 80.7%Investigation: 84moAppeal: Upheld on appeal (CJEU 2024)
€2.42B
imposed
Meta / FacebookFTCPrivacyUS · 2019
FTC Act §5

Cambridge Analytica data misuse and deceptive consent practices. Largest consumer privacy fine in US history.

Fine/max: N/AInvestigation: 14moAppeal: Settled — consent order
$5B
imposed
Meta PlatformsDPCPrivacyIE · 2023
GDPR Art. 46

Transfer of EU Facebook user data to the US via SCCs found inadequate post-Schrems II. Largest GDPR fine to date.

Fine/max: 100%Investigation: 48moAppeal: Appealed — pending
€1.2B
imposed
Amazon Europe CoreCNPDPrivacyLU · 2021
GDPR Art. 5, 6

Advertising targeting system without valid consent — GDPR consent and data minimisation violations.

Fine/max: 87.8%Investigation: 30moAppeal: Appealed — reduced on appeal
€746M
imposed
Didi GlobalCACPrivacyCN · 2022
PIPL / Cybersecurity Law / DSL

Largest data fine in Chinese history. Illegal data collection, national security data risk, and unauthorised cross-border transfer.

Fine/max: ~5% revenueInvestigation: 13moAppeal: Not appealed
¥8.026B (~€1.05B)
imposed
WhatsApp (Meta)DPCPrivacyIE · 2021
GDPR Art. 12–14

Transparency failures in privacy policy — insufficient information on data processing and sharing with Meta companies.

Fine/max: 90%Investigation: 30moAppeal: Upheld
€225M
imposed
Google LLCCNILPrivacyFR · 2022
ePrivacy — cookie consent

Cookie rejection mechanism harder to use than acceptance — consent not freely given under French ePrivacy rules.

Fine/max: 75%Investigation: 10moAppeal: Settled
€150M
imposed
Facebook Inc.CNILPrivacyFR · 2022
ePrivacy — cookie consent

Same cookie refusal mechanism violation issued simultaneously with the Google decision.

Fine/max: 30%Investigation: 10moAppeal: Settled
€60M
imposed
British AirwaysICOPrivacyGB · 2020
UK GDPR Art. 5, 32

Insufficient security led to breach exposing 400,000 customer records including payment data via Magecart attack.

Fine/max: 10.9%Investigation: 22moAppeal: Reduced from £183M provisional
£20M
imposed
Marriott InternationalICOPrivacyGB · 2020
UK GDPR Art. 5, 32

339 million guest records exposed via inherited Starwood breach; failure to conduct adequate due diligence on acquisition.

Fine/max: 18.5%Investigation: 22moAppeal: Reduced from £99M provisional
£18.4M
imposed
Clearview AIGarantePrivacyIT · 2022
GDPR Art. 6, 9

Illegal biometric data collection of Italian residents from public web sources without any legal basis.

Fine/max: 100%Investigation: 14moAppeal: Non-compliant — no Italian operations
€20M
imposed
Vodafone SpainAEPDPrivacyES · 2021
GDPR Art. 6, 17

Spam telemarketing calls and failure to honour erasure requests — processing without valid consent.

Fine/max: 40.8%Investigation: 8moAppeal: Upheld
€8.15M
imposed
Advocate Aurora HealthHHS OCRHealthUS · 2024
HIPAA Privacy Rule

Impermissible disclosure of 3M patient health records via Meta Pixel and Google Analytics tracking pixels on patient portals.

Fine/max: 25.8%Investigation: 18moAppeal: Resolution Agreement
$12.9M
imposed
SingHealthPDPCPrivacySG · 2019
PDPA — Personal Data Protection Act

1.5 million patient records breached; PM Lee's data targeted. Singapore's most significant data breach enforcement.

Fine/max: 25%Investigation: 6moAppeal: Upheld
S$250K
imposed

Showing 15 cases for the current LVP dataset