BULLETIN №082Last updated · 02 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 19 Dec 2024 | SOCIETE EDITANT UN SITE DE JEUX DEMATERIALISES (procédure simplifiée)The CNIL imposed an administrative fine of EUR 15,000 on SOCIETE EDITANT UN SITE DE JEUX DEMATERIALISES. The decision was issued under a simplified procedure. | FR | CNIL | GDPR | €15,000 | ↗ |
| 26 Feb 2026 | Flamel S.r.l.Flamel S.r.l. was fined by the Garante 15,000 EUR for carrying out promotional activities without a legal basis. The company used phone numbers not registered with the ROC, affecting the data of more than 500 individuals. | IT | Garante | GDPR | €15,000 | ↗ |
| 18 Dec 2025 | SOCIETE EXERCANT UNE ACTIVITE DE PROGRAMMATION INFORMATIQUE (GESTIONS LOCATIVE ET DE COPROPRIETE) (procédure simplifiée)The CNIL imposed an administrative fine of EUR 15,000 on SOCIETE EXERCANT UNE ACTIVITE DE PROGRAMMATION INFORMATIQUE and issued an injunction. The case concerned a breach of personal data protection obligations. | FR | CNIL | GDPR | €15,000 | ↗ |
| 11 Aug 2025 | FUNDACIÓN PARA EL DESARROLLO DE LA ENFERMERÍA y SINDICATO DE ENFERMERÍA, SATSESATSE and FUDEN were fined by the AEPD EUR 15,000 after a ransomware incident affected personal data. The authority also found that the parties had not properly formalized a joint controllership agreement under the GDPR. | ES | AEPD | GDPR | €15,000 | ↗ |
| 14 May 2026 | Azienda ospedaliera dei colli Monaldi-Cotugno-CTO di NapoliAzienda ospedaliera dei colli Monaldi-Cotugno-CTO di Napoli was fined EUR 15,000 by the Garante. The authority found that the entity provided false statements and interrupted the performance of its tasks. The case concerns breaches of data protection rules. | IT | Garante | GDPR | €15,000 | ↗ |
| 20 Nov 2006 | Anonymised (HDPA 61/2006)An insurance company was fined for unlawfully transmitting the complainant’s sensitive health data. The case concerned a breach of the rules governing the lawful processing of special-category personal data. | GR | HDPA | GDPR | €15,000 | ↗ |
| 18 Jul 2023 | Dane anonimowe (K. za naruszenie przepisów art. 5 ust. 1 lit. f), art. 5 ust. 2, art. 25 ust. 1 oraz art. 32 ust. 1 i 2 rozporządzenia 2016/679)UODO imposed a fine on the controller for failing to implement appropriate technical and organizational measures when employees used portable company laptops. The authority also found a lack of regular testing, measuring, and evaluation of security measures, which breached the principles of integrity, confidentiality, and accountability. | PL | UODO | GDPR | €3,374 | ↗ |
| 29 Jun 2023 | FUNDACIÓN VEDRUNA EDUCACIÓN COLEGIOA teacher publicly disclosed the content of an email concerning a student's issues, breaching the duty of confidentiality. The AEPD found a violation of data protection rules and imposed a 15,000 EUR fine. | ES | AEPD | GDPR | €15,000 | ↗ |
| 22 Jun 2023 | COLEGIO VIRGEN DE EUROPA, S.L.The school processed and published images of a 3-year-old child on Facebook and WhatsApp without parental consent. This disregarded the parents’ explicit refusal and led to a fine imposed by the AEPD. | ES | AEPD | GDPR | €15,000 | ↗ |
| 13 Feb 2025 | MDE – Movimento Diritti Europei s.r.l.s.MDE – Movimento Diritti Europei s.r.l.s. was fined 15,000 EUR by the Garante. The authority found that the company failed to provide shareholders with the information required under GDPR Article 14 and instead referred them to a website that did not contain sufficient details. | IT | Garante | GDPR | €15,000 | ↗ |
| 28 Jul 2025 | KINYO, S.L.KINYO, S.L. was fined by the AEPD in the amount of 15,000 EUR for sending unsolicited commercial emails. The authority also found that recipients were not provided with an effective mechanism to opt out of future communications. | ES | AEPD | ePrivacy | €15,000 | ↗ |
| 06 Nov 2015 | VACACIONES EDREAMS SOCIEDAD LIMITADA UNIPERSONALVACACIONES EDREAMS SOCIEDAD LIMITADA UNIPERSONAL was fined by the AEPD EUR 15,000 for failing to honor unsubscribe requests from commercial newsletters. The case concerned a breach of Article 21.1 of the LSSI and indicates inadequate handling of marketing opt-out requests. | ES | AEPD | ePrivacy | €15,000 | ↗ |
| 23 Jan 2024 | BANCO COOPERATIVO ESPAÑOL, S.A.Banco Cooperativo Español, S.A. was fined by the AEPD for a personal data breach. The incident allowed unauthorized access to personal data and breached the principles of confidentiality and integrity. | ES | AEPD | GDPR | €15,000 | ↗ |
| 06 Jul 2023 | Ad Maiora Distribuzioni S.a.s. di Editrice Ad Maiora S.r.l.s. & C.Ad Maiora Distribuzioni was fined EUR 15,000 by the Garante. The authority found that the company made unsolicited promotional calls and failed to respond to requests for access to and deletion of personal data. | IT | Garante | GDPR | €15,000 | ↗ |
| 24 Jun 2021 | Ospedale Pediatrico Bambino GesùOspedale Pediatrico Bambino Gesù was fined by the Garante 15,000 EUR for breaches involving a data incident and improper handling of patient health data. The authority cited violations of GDPR Articles 5 and 32 on lawful processing and security of personal data. | IT | Garante | GDPR | €15,000 | ↗ |
| 02 Apr 2015 | Midolo MichelaMidolo Michela was fined EUR 15,000 by the Garante for activating phone cards in the names of individuals without their knowledge. The conduct breached data protection rules. | IT | Garante | GDPR | €15,000 | ↗ |
| 12 Feb 2026 | Bressanelli Galli Gelpi Porta & C. S.r.l.The company was fined EUR 15,000 by the Garante for sending promotional emails without prior consent from recipients. The authority found this to be a breach of GDPR principles, including Article 5. | IT | Garante | GDPR | €15,000 | ↗ |
| 01 Jan 2023 | GLOVOGLOVO was fined EUR 15,000 by the AEPD for failing to properly handle a data access request. The authority found a breach of Article 15 of the GDPR. | ES | AEPD | GDPR | €15,000 | ↗ |
| 23 Jan 2024 | CAJA RURAL DE BURGOS, FUENTEPELAYO, SEGOVIA Y CASTELLDANS, S.C.C.CAJABURGOS was fined by the AEPD for failing to ensure the confidentiality and integrity of personal data. The breach resulted in unauthorized access following a data security incident. | ES | AEPD | GDPR | €15,000 | ↗ |
| 24 Jan 2024 | CAIXA RURAL D'ALGEMESÍ, S.C.V.CCAIXA RURAL D'ALGEMESÍ, S.C.V.C. was fined by the AEPD 15,000 EUR for breaching data protection principles, including confidentiality and integrity. The breach led to unauthorized access to personal data. | ES | AEPD | GDPR | €15,000 | ↗ |