BULLETIN №081Last updated · 26 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -20.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 22 Jan 2026 | ÉTABLISSEMENT PUBLIC ADMINISTRATIFCNIL imposed an administrative fine of EUR 5,000,000 on ÉTABLISSEMENT PUBLIC ADMINISTRATIF and issued an injunction. The case concerns a confirmed breach of rules supervised by CNIL. | FR | CNIL | GDPR | €5,000,000 | ↗ |
| 20 Jan 2026 | Timegrip ASTimegrip AS was fined 250,000 NOK for failing to provide employees access to their own timekeeping data after the bankruptcy of a retail chain. The authority treated the company as the data controller and found a breach of the GDPR right of access. | NO | Datatilsynet | GDPR | €21,340 | ↗ |
| 16 Jan 2026 | BAR GIOIA di XXThe Garante imposed a fine of EUR 600 on BAR GIOIA for the non-compliant installation of a video surveillance system. The case concerned breaches of data protection rules and the requirements for lawful processing. | IT | Garante | GDPR | €600 | ↗ |
| 16 Jan 2026 | Provvedimento del 16 gennaio 2026 [10213836]The Garante imposed a fine of EUR 500 on an anonymized data controller for a minor breach of data protection rules in the health sector. The authority also ordered publication of the decision on its website. | IT | Garante | GDPR | €500 | ↗ |
| 16 Jan 2026 | Liceo Classico e Scientifico Alessandro VoltaLiceo Classico e Scientifico Alessandro Volta was fined 2,000 EUR by the Garante for publishing personal data on its institutional website without a proper legal basis. The authority found breaches of lawfulness, fairness, and transparency principles. | IT | Garante | GDPR | €2,000 | ↗ |
| 16 Jan 2026 | Born S.r.l.Born S.r.l. was fined by the Garante 15,000 EUR for making unsolicited promotional calls to numbers listed in the Public Register of Oppositions. The conduct breached data protection rules governing telephone marketing and the right to object. | IT | Garante | GDPR | €15,000 | ↗ |
| 16 Jan 2026 | Macelleria La Costata s.r.l.s.The Garante fined Macelleria La Costata s.r.l.s. EUR 1,500 for the non-compliant installation of a video surveillance system. The authority found a breach of GDPR Article 5, which sets out the core principles for personal data processing. | IT | Garante | GDPR | €1,500 | ↗ |
| 16 Jan 2026 | Associazione Turistica Pro Loco di CittarealeThe association unlawfully disclosed the personal data of 23 members by publishing it in a public notice and online. The authority found breaches of lawfulness, fairness, transparency, and data minimization. | IT | Garante | GDPR | €600 | ↗ |
| 16 Jan 2026 | Azienda Ospedaliera S. Pio di BeneventoAzienda Ospedaliera S. Pio di Benevento was fined by the Garante EUR 6,000 for violations related to the processing of personal data. The case concerned special categories of data and disclosure to third parties. | IT | Garante | GDPR | €6,000 | ↗ |
| 16 Jan 2026 | Πυροσβεστικό ΣώμαThe Hellenic Data Protection Authority imposed a €10,000 fine on the Fire Service for unlawfully processing an employee’s special-category health data. The authority found breaches of GDPR lawfulness and data minimization principles and noted that the data were accessible through an internal electronic application. | GR | Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα | GDPR | €10,000 | ↗ |
| 15 Jan 2026 | Allay Claims Ltd The ICO issued an MPN and EN to Allay Claims Ltd after a large volume of unsolicited SMS messages promoting PPI tax refund services. The case indicates a breach of direct marketing and electronic communications rules. | GB | ICO | GDPR | €138,000 | ↗ |
| 15 Jan 2026 | CANDIDATS AUX ÉLECTIONS LÉGISLATIVES (procédure simplifiée)CNIL imposed an administrative fine of 2,000 EUR on CANDIDATS AUX ÉLECTIONS LÉGISLATIVES (procédure simplifiée) and issued an injunction. The case concerns a breach of rules supervised by CNIL. | FR | CNIL | GDPR | €2,000 | ↗ |
| 14 Jan 2026 | ZalandoUOKiK imposed a fine on Zalando for misleading consumers by improperly presenting promotional prices and hiding the required lowest price from the previous 30 days. According to the report, the combined sanctions against Zalando and Temu were about PLN 37 million, with Zalando accounting for PLN 31,488,674. | PL | Urząd Ochrony Konkurencji i Konsumentów | Other | €7,465,000 | ↗ |
| 13 Jan 2026 | Free Mobile and FreeFrance’s CNIL fined Free Mobile and Free a combined EUR 42 million for GDPR breaches linked to a 2024 data breach affecting more than 24 million users. The regulator found inadequate security measures and said Free Mobile unlawfully retained former subscribers’ data. | FR | Commission nationale de l’informatique et des libertés | GDPR | €42,000,000 | ↗ |
| 13 Jan 2026 | PREMIER RESTAURANTS ROMANIA SRLThe National Supervisory Authority for Personal Data Processing imposed a fine on PREMIER RESTAURANTS ROMANIA SRL for GDPR violations. The case concerned non-compliance with personal data protection requirements. | RO | ANSPDCP | GDPR | €8,000 | ↗ |
| 12 Jan 2026 | Zalando SEThe President of UOKiK imposed a fine of PLN 30,945,000 on Zalando SE for failing to provide the lowest price from the 30 days before a discount and for misleading discount presentation. The decision concerns consumer protection and is not yet final. | PL | UOKiK | Omnibus | €7,351,000 | ↗ |
| 10 Jan 2026 | NAROBESA INV, S.L.NAROBESA INV, S.L. was fined 1,000 EUR by the AEPD for unlawfully accessing a job applicant's credit information without consent during recruitment. The conduct breached data protection rules and occurred in the hiring process. | ES | AEPD | GDPR | €1,000 | ↗ |
| 10 Jan 2026 | DÉCIMAS, S.L.DÉCIMAS, S.L. was fined by the AEPD in the amount of EUR 200,000 for a personal data breach. The incident exposed personal data and breached GDPR Article 5(1)(f). | ES | AEPD | GDPR | €200,000 | ↗ |
| 10 Jan 2026 | MULTISPORTS GALICIA, S.L.MULTISPORTS GALICIA, S.L. was fined by the AEPD EUR 6,000 for failing to implement appropriate technical and organizational measures proportionate to the risk. The weakness allowed easy access to personal data of race participants through its website. | ES | AEPD | GDPR | €6,000 | ↗ |
| 08 Jan 2026 | OPÉRATEUR DE TÉLÉPHONIE MOBILECNIL imposed an administrative fine of EUR 27 million on OPÉRATEUR DE TÉLÉPHONIE MOBILE and issued an injunction. The case concerns a regulatory breach addressed by the authority’s decision. | FR | CNIL | GDPR | €27,000,000 | ↗ |