BULLETIN №081Last updated · 26 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -20.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 03 Feb 2026 | Partidul Alianța pentru Unirea Românilor (AUR)The National Supervisory Authority for Personal Data Processing imposed a fine on the political party AUR for GDPR violations. The case concerned non-compliance with personal data protection requirements. | RO | ANSPDCP | GDPR | €1,000 | ↗ |
| 03 Feb 2026 | TMAC LtdTMAC Ltd was fined GBP 100,000 by the ICO and served with an enforcement notice for breaches of regulations 21 and 24 of PECR. Between 8 February 2024 and 24 September 2024, the company made 260,332 unsolicited direct marketing calls to numbers listed on the Commissioner’s register. It also failed to provide the required information to call recipients. | GB | ICO | ePrivacy | €115,000 | ↗ |
| 01 Feb 2026 | Biržų ligoninėVDAI imposed a EUR 6,000 fine on Biržų ligoninė for improper processing of personal data. The case concerns a breach of data protection requirements and indicates non-compliance with GDPR obligations. | LT | VDAI | GDPR | €6,000 | ↗ |
| 31 Jan 2026 | SC Tensa Art Design SAThe Romanian data protection authority fined SC Tensa Art Design SA, operator of the Lensa brand, EUR 20,000 under the GDPR. The sanction followed the company’s failure to respond to the authority’s investigative request concerning cookie tracking and behavioral advertising on its website. | RO | Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal | GDPR | €20,000 | ↗ |
| 30 Jan 2026 | un operator persoană fizicăAn individual operator was fined 3,000 EUR for GDPR violations. The case concerned non-compliant processing of personal data and was handled by ANSPDCP. | RO | ANSPDCP | GDPR | €3,000 | ↗ |
| 30 Jan 2026 | un operator persoană fizicăAn individual operator was fined 1,000 EUR by ANSPDCP for GDPR violations. The case concerned non-compliance with personal data protection requirements. | RO | ANSPDCP | GDPR | €1,000 | ↗ |
| 30 Jan 2026 | un operator persoană fizicăA 1,000 EUR fine was imposed on an individual operator for GDPR violations. The case concerned non-compliance with personal data protection requirements. | RO | ANSPDCP | GDPR | €1,000 | ↗ |
| 30 Jan 2026 | Magyar Agrár- és Élettudományi EgyetemThe Hungarian University of Agriculture and Life Sciences was fined by the NAIH for negligent GDPR violations in its dormitory admissions data processing. The authority cited a lack of proper legal basis, insufficient prior information, and failure to apply data minimization. | HU | NAIH | GDPR | €3,945 | ↗ |
| 30 Jan 2026 | deținătorul site-ului evita-teparii.roANSPDCP imposed total fines of 51,000 lei, about 10,000 euro, on the operator, a natural person who runs the site evita-teparii.ro. The case involved multiple GDPR breaches, including the unlawful publication of identity, contact, sensitive, and alleged criminal data without a legal basis. | RO | ANSPDCP | GDPR | €10,007 | ↗ |
| 30 Jan 2026 | un operator persoană fizicăA fine of 5,000 EUR was imposed on an individual controller by ANSPDCP for GDPR violations. The case concerned non-compliance with personal data protection requirements. | RO | ANSPDCP | GDPR | €5,000 | ↗ |
| 29 Jan 2026 | Università Telematica e-CampusThe Garante fined Università Telematica e-Campus EUR 50,000 for violations related to biometric data processing. The authority also found that the university failed to carry out a proper Data Protection Impact Assessment (DPIA). | IT | Garante | GDPR | €50,000 | ↗ |
| 29 Jan 2026 | Ministero della CulturaMinistero della Cultura was fined EUR 12,000 by the Garante for using surveillance footage for disciplinary purposes without ensuring proper transparency toward visitors and employees. The authority found breaches of the GDPR and national data protection rules. | IT | Garante | GDPR | €12,000 | ↗ |
| 29 Jan 2026 | dott. Paolo MontemurroDott. Paolo Montemurro was fined 5,000 EUR by the Garante for posting photographs of a patient's surgical procedure on Instagram without consent. The authority found this breached GDPR principles of lawfulness, fairness, and transparency. | IT | Garante | GDPR | €5,000 | ↗ |
| 29 Jan 2026 | ASSOCIATION RELIGIEUSE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 10,000 on ASSOCIATION RELIGIEUSE (procédure simplifiée) and issued an injunction. The case concerned a confirmed breach of rules supervised by the CNIL. | FR | CNIL | GDPR | €10,000 | ↗ |
| 29 Jan 2026 | ÉTABLISSEMENT PUBLIC EXERÇANT UNE ACTIVITÉ DE TRANSPORT URBAIN (procédure simplifiée)The CNIL imposed an administrative fine of EUR 20,000 on ÉTABLISSEMENT PUBLIC EXERÇANT UNE ACTIVITÉ DE TRANSPORT URBAIN. The case was handled under a simplified procedure. | FR | CNIL | GDPR | €20,000 | ↗ |
| 29 Jan 2026 | Istituto tecnico industriale statale “Stanislao Cannizzaro” di CataniaIstituto tecnico industriale statale “Stanislao Cannizzaro” di Catania was fined by the Garante €10,000 for breaches of data protection principles. The authority found that personal data were processed in a manner that was not lawful, fair, or transparent. | IT | Garante | GDPR | €10,000 | ↗ |
| 29 Jan 2026 | Provincia della Congregazione dei Fratelli delle Suore CristianeThe entity was fined for failing to ensure sufficient transparency in data processing and for not carrying out a data protection impact assessment for workplace surveillance systems. The authority found breaches of the GDPR and the national privacy code. | IT | Garante | GDPR | €12,000 | ↗ |
| 26 Jan 2026 | SportAdmin i Skandinavien ABSportAdmin i Skandinavien AB was fined by IMY 6,000,000 SEK for failing to implement appropriate technical and organizational measures to ensure an adequate level of security for personal data. The deficiency resulted in a data breach. | SE | IMY | GDPR | €564,000 | ↗ |
| 24 Jan 2026 | IBERANUNCIOS SLIBERANUNCIOS SL was fined by the AEPD EUR 15,000 for a data protection breach. The incident allowed unauthorized access to personal data, breaching the confidentiality principle under GDPR. | ES | AEPD | GDPR | €15,000 | ↗ |
| 24 Jan 2026 | CENTRO MÉDICO REY FERNANDO, S.L.P.The entity charged a fee for providing a patient with their medical history, which breached the right of access under GDPR Article 12. The AEPD imposed a fine of 1,000 EUR. | ES | AEPD | GDPR | €1,000 | ↗ |