Enforcement
Living registries of GDPR, AI Act, MiCA, and DORA enforcement cases. Real fines, court status, statutes invoked. Updated when new cases land.
DORA CTPP register: the 19 critical ICT providers under direct EU oversight
On 18 November 2025 the EU designated its first Critical ICT Third-Party Providers (CTPPs) under DORA — 19 tech firms, from the hyperscale clouds to SAP and Bloomberg, now overseen directly by EU regulators. The full list, what designation means, and the powers behind it — sourced to the official ESA document.
MiCA and stablecoins: how USDT left the EU and authorised coins took over
MiCA's most visible real-world effect: by early 2025 the EU's licensed exchanges had removed Tether (USDT) for EEA users, while Circle's MiCA-authorised USDC and EURC moved in. The delisting timeline, why it happened, and how the EBA's 'significant token' test works — sourced to the regulators and editorial press.
Big Tech GDPR fines: the largest data-protection penalties in EU history
A registry of the biggest GDPR fines ever issued — Meta €1.2 billion, Amazon €746 million, TikTok €530 million, Uber €290 million and more. Who was fined, how much, for what, why almost all of them come out of Ireland, and which ones courts have already overturned — every amount sourced to the regulator or the binding EU decision behind it.
AEPD fines: inside the EU's busiest data-protection enforcer
A registry of the largest fines from Spain's AEPD — Google €10M, Vodafone €8.15M, CaixaBank €6M, BBVA €5M and more — and why Spain matters less for the size of any single fine than for sheer volume: it issues a larger share of the EU's GDPR fines than any other country. Who was fined, for what, and why banks and telcos dominate the list. Every amount sourced.
CNIL fines: the EU's cookie-enforcement powerhouse, case by case
A registry of the biggest fines issued by France's CNIL — Google €150M and €100M, Facebook €60M, Microsoft €60M, Orange €50M, Criteo €40M and more. Why most of them are about cookies rather than the GDPR, why the CNIL can fine Big Tech directly when Ireland normally would, and which fines France's top court has upheld — every amount sourced to the regulator.
DPC fines: Europe's most powerful — and most criticised — data regulator
A registry of fines from Ireland's DPC — the lead regulator for most of Big Tech, which imposed over €652 million in a single year, yet is accused of going easy on the platforms and being forced higher by the EU. The Big Tech mega-fines, the modest domestic Irish cases (Tusla, Bank of Ireland), and the bottleneck criticism — every fact sourced.
Garante fines: Italy's war on telemarketing — and on management by algorithm
A registry of the largest GDPR fines from Italy's Garante — Enel Energia €79.1M and €26.5M, TIM €27.8M, Wind Tre €16.7M, Vodafone €12.25M — plus the pioneering gig-economy cases against Foodinho and Deliveroo. Why Italy's enforcement is dominated by unsolicited marketing calls and worker-management algorithms, and what each company did. Every amount sourced to the regulator.
Garante AI fines: Italy's GDPR enforcement against generative AI
A registry of the Italian data protection authority's enforcement against generative-AI services: €15M on OpenAI for ChatGPT (later annulled by a Rome court) and €5M on Luka for Replika. What was violated, the exact articles, and the fate of each decision — every fact sourced to the regulator, the court record and editorial press.
Clearview AI fines: how four EU regulators hit one US facial-recognition firm
A registry of the GDPR fines imposed on Clearview AI by EU data protection authorities — Italy, Greece, France and the Netherlands — for scraping billions of faces without a legal basis. The exact amounts, articles and orders, why the company has paid none of them, and how the UK route diverged. Every fact sourced to the regulator.
AKI fines: every known enforcement case of Estonia's Data Protection Inspectorate
A complete public registry of fines issued by the Estonian Data Protection Inspectorate — from token misdemeanour fines of a few dozen euros on individuals up to €3 million against the Apotheka pharmacy chain. What was violated, which decisions were overturned in court, and why Estonia is the EU's most lenient GDPR jurisdiction — and is right now ceasing to be one.