BULLETIN №082Last updated · 02 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 07 Jul 2025 | Partidul Alianța pentru Unirea Românilor (AUR)Partidul Alianța pentru Unirea Românilor (AUR) was fined EUR 15,000 by ANSPDCP for violations related to data security breaches. The case concerned reported data security incidents within the political party. | RO | ANSPDCP | GDPR | €15,000 | ↗ |
| 02 Oct 2025 | UNIVERSITE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 15,000 on UNIVERSITE (procédure simplifiée). The case concerns a breach of rules supervised by the CNIL. | FR | CNIL | GDPR | €15,000 | ↗ |
| 20 Oct 2022 | Policlinico Casilino di RomaPoliclinico Casilino di Roma was fined by the Garante for violations related to the handling of personal data in the healthcare sector. The case concerned improper processing of patient data and privacy compliance requirements. | IT | Garante | GDPR | €15,000 | ↗ |
| 10 Jul 2025 | Outly di Veneziani & Co s.r.l.The Garante fined Outly di Veneziani & Co s.r.l. EUR 15,000 for insufficient transparency when obtaining consent and for inadequate information on data retention periods. The issues affected all interested parties and potential customers. | IT | Garante | GDPR | €15,000 | ↗ |
| 08 Dec 2025 | Dane anonimowe (S.)The UODO imposed an administrative fine of PLN 14,816 on Anonymous data (S.). The penalty was issued for failing to provide access to all personal data and information necessary for the President of the UODO to perform his duties. | PL | UODO | GDPR | €3,502 | ↗ |
| 13 Sept 2017 | Jump 3000 s.r.l.Jump 3000 s.r.l. was fined by the Garante 14,800 EUR for providing clients with inadequate data protection information. The authority found that the privacy notices did not properly identify the data controller. | IT | Garante | GDPR | €14,800 | ↗ |
| 25 Feb 2016 | Associazione sportivo dilettantistica Feriolo Sporting ClubFeriolo Sporting Club was fined by the Garante 14,400 EUR for failing to provide adequate simplified information about its video surveillance system. The authority also found that recorded images were retained longer than permitted. | IT | Garante | GDPR | €14,400 | ↗ |
| 12 Oct 2017 | Hu GuangyuHu Guangyu was fined EUR 14,400 by the Garante. The authority found inadequate simplified information on video surveillance and retention of recorded images beyond the permitted period. | IT | Garante | GDPR | €14,400 | ↗ |
| 20 Mar 2014 | SIGE S.p.a.SIGE S.p.a. was fined by the Italian data protection authority, Garante, in the amount of €14,400. The case concerned a video surveillance system that retained images longer than permitted under the Garante's guidelines. | IT | Garante | GDPR | €14,400 | ↗ |
| 09 Mar 2017 | Moto One s.r.l.Moto One s.r.l. was fined by the Garante in the amount of 14,400 EUR for violations related to its video surveillance system. The authority found that recorded images were retained longer than permitted and that required informational signage was missing. | IT | Garante | GDPR | €14,400 | ↗ |
| 11 Jul 2013 | Cowboys' Guest Ranch S.r.l.Cowboys' Guest Ranch S.r.l. was fined EUR 14,400 by the Garante for failing to provide the required privacy notice when collecting personal data through online forms, paper questionnaires, and dance competition registration forms. The breach concerned the obligation to inform data subjects about the processing of their personal data. | IT | Garante | GDPR | €14,400 | ↗ |
| 20 Nov 2024 | Anonymisé (CNPD decision-03-fr-2024)The company was fined for installing surveillance cameras without a legal basis. The authority found breaches of GDPR principles of lawfulness, transparency, and security. | LU | CNPD | GDPR | €14,288 | ↗ |
| 31 May 2023 | Dane anonimowe (G. Sp. z o.o. z siedzibą w K. przy ul.)The President of UODO imposed an administrative fine of PLN 14,148 on G. Sp. z o.o. The sanction was issued for failing to cooperate with the authority in the performance of its duties and for not providing access to information necessary for those duties. | PL | UODO | GDPR | €3,119 | ↗ |
| 16 Nov 2023 | Dane anonimowe (W. sp. j. z siedzibą we W. przy ul.)The President of the Personal Data Protection Office imposed an administrative fine of PLN 14,148 on the company. The sanction was issued because the company failed to provide access to personal data and information necessary for the authority’s tasks. | PL | UODO | GDPR | €3,235 | ↗ |
| 20 Dec 2012 | Regione Emilia RomagnaRegione Emilia Romagna was fined EUR 14,000 by the Garante for unlawfully disseminating personal data through the Regional Student Registry without a legal basis. The authority also found unauthorized retention of sensitive student data. | IT | Garante | GDPR | €14,000 | ↗ |
| 09 Oct 2014 | Comune di UdineThe Municipality of Udine was fined 14,000 EUR by the Garante. The authority found that the Security Policy Document (DPS) had not been updated from 2005 to 2011, which breached data protection rules. | IT | Garante | GDPR | €14,000 | ↗ |
| 10 Apr 2023 | COLEGIO OFICIAL DE ARQUITECTOS DE GRANADACOLEGIO OFICIAL DE ARQUITECTOS DE GRANADA was fined €14,000 by the AEPD for data protection breaches. The authority found a conflict of interest in the appointment of the Data Protection Officer, missing required information on data processing in complaint forms, and the use of third-party cookies without user consent. | ES | AEPD | ePrivacy | €14,000 | ↗ |
| 13 Jan 2022 | Azienda sanitaria unica regionale MarcheAzienda sanitaria unica regionale Marche was fined EUR 14,000 by the Garante for inadequate data protection measures. The breach involved health data and was linked to QR code generation; improved security measures were later implemented. | IT | Garante | GDPR | €14,000 | ↗ |
| 06 Sept 2019 | Anonymised (CyDPC ΑΝΟΝΥΜΟΠΟΙΗΜΕΝΗ ΑΠΟΦΑΣΗ δημοσί)A medical practice was fined EUR 14,000 for posting a patient's pre- and post-surgery images on Instagram without consent. The authority found a breach of GDPR rules on personal data processing and the protection of special-category data. | CY | CyDPC | GDPR | €14,000 | ↗ |
| 30 Jun 2021 | Dane anonimowe (Fundację)UODO imposed a PLN 13,644 administrative fine on the Foundation for failing to report a personal data breach without undue delay. The Foundation also did not notify the affected individuals about the incident, breaching controller obligations. | PL | UODO | GDPR | €3,018 | ↗ |