Artmark Holding SRL was fined by ANSPDCP 10,000 RON for sending unsolicited commercial emails without obtaining prior explicit consent from recipients. The case concerns a breach of rules on electronic marketing communications and consent requirements.
Europe has fined companies €8.6bn for breaking digital law.
Most of it wasn't anything dramatic. Most of it was a misconfigured cookie banner, a missing alt text, a fake countdown timer. Here is the data, visualised.
In the last seven days.
Three fresh decisions from three regulators, in three different sectors. The pace is not slowing.
AVIZIERO S.R.L was fined RON 5,000 by ANSPDCP for allowing the storage of information and access to information stored on user equipment when users accessed its website. The authority found this conduct to be in breach of ePrivacy requirements.
ANSPDCP completed an investigation at Dormeo Home SRL in May 2026 and found a breach of GDPR provisions. As a result, a fine of EUR 1,000 was imposed.
Where the fines come from.
A handful of regulators do most of the work. Spain leads in volume; Ireland leads in headline numbers; Germany leads in unpredictability.
Top jurisdictions by total fines
- 01IEIreland€4.2bn
- 02FRFrance€1.7bn
- 03LULuxembourg€747m
- 04NLNetherlands€562.4m
- 05ITItaly€409.4m
- 06EUEuropean Union€320m
- 07ESSpain€147.5m
- 08GBUnited Kingdom€136m
- 09PLPoland€65.2m
- 10DEGermany€46.6m
The wave, month by month.
Enforcement intensifies as new directives come online. EAA arrived in June 2025. AI Act lands in August 2026. The slope only goes up.
The thirty largest fines, at scale.
Each rectangle is one enforcement decision, sized by amount, coloured by directive. Two companies account for nearly half of all enforcement.
Six directives, one tracker.
GDPR still dominates, but ePrivacy and Omnibus are growing fastest. EAA is brand new. AI Act is loaded and waiting.
- Decisions
- 4,563
- Avg fine
- €1.6m
- YoY
- -21.2%
- Decisions
- 697
- Avg fine
- €699.1k
- YoY
- -24%
- Decisions
- 1
- Avg fine
- €4.2k
- YoY
- —
- Decisions
- 4
- Avg fine
- €4.8m
- YoY
- +100%
- Decisions
- 3
- Avg fine
- €106.7m
- YoY
- —
The EU AI Act is in force, but penalties for prohibited and high-risk AI phase in through 2026–2027. No fine has been issued yet — we'll log the first the moment it lands.
- Max penalty
- €35M / 7% of global turnover
- Prohibited-AI ban
- Since Feb 2025
- High-risk rules
- From Aug 2026
This month's full register.
Every fine logged in the last 30 days. With short summaries and the verdict: would we have spotted it.
- EPRIVACYRomania26 Jun 2026
Artmark Holding SRL
€1,908Artmark Holding SRL was fined by ANSPDCP 10,000 RON for sending unsolicited commercial emails without obtaining prior explicit consent from recipients. The case concerns a breach of rules on electronic marketing communications and consent requirements.
- EPRIVACYRomania26 Jun 2026
AVIZIERO S.R.L
lei 5,000AVIZIERO S.R.L was fined RON 5,000 by ANSPDCP for allowing the storage of information and access to information stored on user equipment when users accessed its website. The authority found this conduct to be in breach of ePrivacy requirements.
- GDPRRomania16 Jun 2026
Dormeo Home SRL
€1,000ANSPDCP completed an investigation at Dormeo Home SRL in May 2026 and found a breach of GDPR provisions. As a result, a fine of EUR 1,000 was imposed.
- GDPRRomania15 Jun 2026
SSG SELECT SOLUTIONS S.R.L
€2,000SSG SELECT SOLUTIONS S.R.L. was fined by ANSPDCP in the amount of EUR 2,000 for GDPR violations. The investigation was completed in April 2026.
- GDPRRomania12 Jun 2026
Compania Națională Poșta Română
€5,000Compania Națională Poșta Română was fined by ANSPDCP in the amount of EUR 5,000 for GDPR violations. The case concerned non-compliance with personal data protection requirements.
- GDPRNorway04 Jun 2026
Elkjøp
€1,844,000The Norwegian DPA, Datatilsynet, fined Elkjøp 20 million NOK for processing personal data in its customer club without valid consent. The authority found that the practice breached GDPR requirements on lawful processing.
- GDPRHungary29 May 2026
IndaNext Hungary Korlátolt Felelősségű Társaság
€70,750NAIH imposed a fine of 25,000,000 HUF on IndaNext Hungary Kft. for unlawfully publishing personal data and special category data of an individual on www.blikk.hu. The authority found no legal basis and identified breaches of GDPR Articles 6, 9, and 12.
- GDPRRomania29 May 2026
Unicredit Bank SA
€2,000Unicredit Bank SA was fined EUR 2,000 by ANSPDCP. The authority found that the bank failed to notify a personal data breach within the required 72-hour deadline.
- GDPRRomania29 May 2026
Unicredit Bank SA
€10,000Unicredit Bank SA was fined EUR 10,000 by ANSPDCP for violating GDPR provisions. The case concerns non-compliance with personal data protection requirements and should be considered in compliance risk assessments.
- GDPRItaly28 May 2026
AgID – Agenzia per l’Italia digitale
€55,000The Italian Data Protection Authority fined AgID €55,000 for failing to adequately inform professionals about the automatic registration of their digital domiciles. The authority found breaches of transparency and data processing principles.
- GDPRItaly28 May 2026
Croce Rossa Italiana – Comitato regionale Toscana – Presidio Anna Torrigiani
€700The Italian Data Protection Authority imposed a 700 EUR fine on Croce Rossa Italiana – Comitato regionale Toscana – Presidio Anna Torrigiani. The case concerned a data protection breach during a patient's hospitalization in the orthopedics department, including improper handling of information about HIV status.
- GDPRItaly28 May 2026
Comune di Sciacca
€6,000Comune di Sciacca was fined EUR 6,000 by the Garante for violations related to the processing and dissemination of personal data in the public sector. The case concerned improper handling of personal data within public administration activities.
Methodology, in brief.
All data is sourced from primary documents — official regulator decisions, press releases, and published rulings. No paywalls, no scraping of commercial databases.
- 01
Source
Decisions are pulled directly from regulator websites — CNIL, AEPD, AGCM, ACM, UOKiK, Bundesnetzagentur, the European Commission and 24 others.
- 02
Extract
Each decision passes through an extraction pipeline: structured fields (company, amount, date, articles violated) are parsed and translated into a common schema.
- 03
Classify
Violation types are tagged against the Compliwatch taxonomy of 100+ technical checks. Each fine is then mapped to "detectable by automated scan: yes / partial / no".
- 04
Publish
Verified entries are published with a link to the original source. Errors and corrections are versioned and credited. All amounts are converted to EUR at the date-of-decision rate.