Fino

About Fino · updated 6 Oct 2026

Who made Fino, and how it works.

I’m Lorenzo. I’m a Certified Information Privacy Professional/Europe (CIPP/E), certified by the IAPP in June 2025, and I’m preparing for the Solicitors Qualifying Examination in England.

CIPP/E badge: Certified Information Privacy Professional/Europe, IAPPVerify my certificate ↗

I made Fino because I wanted a simple way to see what data protection regulators actually do: who they fine, for what, and how much. That information is public, but it’s spread across dozens of websites in many languages. Fino puts it in one place, so you can see what regulators did in cases like yours and judge your own.

It’s a personal project. It’s free, there are no ads and no sign-up, and it isn’t a law firm. I’m not a qualified solicitor, and nothing here is legal advice.

I built Fino with the help of Claude Code, an AI coding assistant. The decision summaries come from the sources, not from AI. The explainers are written with AI help, and every quote in them is checked against the official text.

Fino is named after its mascot: a small, round and slightly clumsy reader of fines and fine print.

4,992decisions
34countries
€9.13 billionin fines

How it works

A program I run reads two public sources, puts every decision into one database (SQLite), cleans it and publishes it on this site. Every run is logged, so I can see what changed and when. The sources were last read on 6 Oct 2026.

Where the data comes from

  • The CMS Enforcement Tracker: fines published by European data protection authorities.
  • GDPRhub, run by noyb: decisions with and without fines, with short English summaries written by its volunteers.
  • The GDPR text comes from EUR-Lex, in the consolidated version that includes the published corrections. Only the Official Journal version is legally binding.

Both data sources are licensed CC BY-NC-SA 4.0, so Fino uses the same licence. Every decision page links to the regulator’s original decision and to the source it came from.

The rules I follow

  • Nothing is guessed. A date is only as precise as the source gives it: a day, a month or a year. When the source has no date and I find one, I record the month and year, never an invented day.
  • One decision, shown once. When the same decision appears in both sources, it’s shown once and both records are kept, so nothing is deleted.
  • Who the decision is against. A company is named only when the source makes clear it’s the one the decision is about. When a source lists several parties without saying who is who, they’re shown as “named in the source, roles not yet checked”. When the source names no one, the page says so, or uses the source’s own words (“Hospital”).
  • Private people are never named. They’re described instead (“Doctor”, “Journalist”) and marked as a private person.
  • Fines in other currencies keep their own amount as the real figure. For comparison they’re converted to euro at the European Central Bank rate of the decision day (or the average for the month or year, when that’s all the source gives), marked with ≈, and counted in the totals.
  • Same company, same group. Decisions are linked to the same company when the legal name matches. A name without a legal form (S.A., GmbH) only matches within the same country. Groups of companies (Meta, Google and others) are checked by hand, keeping an EU headquarters and its US parent as separate companies in one group.

Case numbers

Every decision gets a Fino number like 2026/IT/108: the year, the country and a number. A decision with no known date starts with ND. Numbers are never reused. If an undated decision later gets its date, it gets a new number, and the old link still leads to it.

What I check by hand

Whatever the program can’t decide safely goes on a review list that I go through myself: unclear parties, possible duplicates, amounts that don’t add up, fines without a clear amount. Until I’ve checked them, the site shows what the source says and marks what is uncertain.

What it gets wrong

  • Some duplicates still slip through, especially between decisions without a fine. A few decisions may appear twice while I finish checking.
  • The topics (“Data security”, “Consent”…) come from simple rules, not from reading each decision. Use them as filters, not conclusions.
  • Fino only knows what its two sources know, and not every decision has a summary yet.
  • Amounts are as reported when the decision was published, and may not reflect a later appeal.

Reuse and cite

Every decision has a permanent page, and the “Copy citation” button gives you a ready reference. All the data is in one file, cases.json, which you can reuse for non-commercial purposes if you credit Fino, CMS and GDPRhub (CC BY-NC-SA 4.0).

Spotted a mistake, or want to say hello? Write to angelillolorenzo@gmail.com.

How Fino handles your data: Privacy.