BULLETIN №082Last updated · 04 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 02 May 2023 | InternetThe company was fined for failing to implement adequate security measures for personal data processing. The deficiency led to a data breach involving user accounts, including accounts protected by weak passwords. | CZ | UOOU | GDPR | €63,600 | ↗ |
| 16 Jan 2024 | International Card Services B.V.International Card Services B.V. was fined by the Dutch AP in the amount of EUR 150,000. The company failed to carry out a Data Protection Impact Assessment (DPIA) before implementing a customer identification and verification process, in breach of Article 35 GDPR. | NL | AP | GDPR | €150,000 | ↗ |
| 24 Jul 2014 | Intermatica Holding s.r.l.Intermatica Holding s.r.l. was fined by the Italian Garante for failing to adopt minimum security measures. The company used passwords of seven characters instead of the required eight, breaching Article 33 of the Italian Data Protection Code. | IT | Garante | GDPR | €4,000 | ↗ |
| 13 Mar 2025 | Interflora Italia S.p.A.Interflora Italia S.p.A. was fined EUR 40,000 by the Garante for sending promotional SMS messages without providing an opt-out option. The case indicates a breach of GDPR requirements for marketing communications and data subject rights. | IT | Garante | GDPR | €40,000 | ↗ |
| 16 Nov 2023 | Intelling LtdBetween 1 January 2021 and 11 November 2021, Intelling sent 1,164,877 direct marketing messages in breach of Regulation 22 of PECR. The Commissioner opened the case after receiving 1,103 complaints via the 7726 Spam Reporting Service. | GB | ICO | ePrivacy | €79,982 | ↗ |
| 13 Jan 2023 | Intellexa A.E.Intellexa A.E. was fined EUR 50,000 by the HDPA. The authority found that the company failed to cooperate with the supervisory authority as required under Article 31 of the GDPR. | GR | HDPA | GDPR | €50,000 | ↗ |
| 03 Oct 2025 | INTEGRAL DE VIGILANCIA Y CONTROL, S.L.INTEGRAL DE VIGILANCIA Y CONTROL, S.L. was fined by the AEPD 5,000 EUR for sending emails to a personal email address without a proper legal basis. The authority treated this as a breach of data protection rules. | ES | AEPD | GDPR | €5,000 | ↗ |
| 06 Mar 2023 | Integral Collection SRLIntegral Collection SRL was fined EUR 3,000 by ANSPDCP after a ransomware incident. The attack led to unauthorized access and loss of integrity and availability of personal data. | RO | ANSPDCP | GDPR | €3,000 | ↗ |
| 12 Apr 2018 | Insurances Global Services S.r.l.Insurances Global Services S.r.l. was fined by the Garante EUR 20,000 for violations involving access to and handling of client data from credit risk databases without proper authorization. The case concerned the unauthorized use of personal data in the context of credit risk assessment. | IT | Garante | GDPR | €20,000 | ↗ |
| 07 Mar 2012 | INSTITUTO TECNOLOGICO AUTESEL SLINSTITUTO TECNOLOGICO AUTESEL SL was fined by the AEPD EUR 600 for sending unsolicited commercial emails. The conduct breached Article 21 of the LSSI, which restricts marketing communications without prior consent. | ES | AEPD | ePrivacy | €600 | ↗ |
| 01 Jan 2015 | INSTITUTO SUPERIOR DE ESTUDIOS EMPRESARIALES CAMBRIDGE S.A.The entity was fined by the AEPD 1,500 EUR for sending commercial messages without providing recipients a way to oppose further communications. The authority treated this as a breach of the right to data cancellation and control over continued contact. | ES | AEPD | ePrivacy | €1,500 | ↗ |
| 01 Jan 2014 | INSTITUTO SUPERIOR DE EDUCACIÓN, ADMINISTRACIÓN Y DESARROLLO S.L.The entity sent unsolicited commercial emails without prior recipient consent. This breached Article 21.1 of the LSSI and resulted in an EUR 800 fine imposed by the AEPD. | ES | AEPD | ePrivacy | €800 | ↗ |
| 11 Dec 2024 | INSTITUTO RAIMON GAJA, S.L.INSTITUTO RAIMON GAJA, S.L. was fined by the AEPD 2,000 EUR for sending unsolicited commercial communications by email. The conduct breached Article 21.1 of the LSSI, despite the recipient’s request to stop receiving such messages. | ES | AEPD | ePrivacy | €2,000 | ↗ |
| 01 Jan 2023 | INSTITUTO OFTALMOLÓGICO DE ***LOCALIDAD.1 B.B.B., S.L.INSTITUTO OFTALMOLÓGICO DE ***LOCALIDAD.1 B.B.B., S.L. was fined by the AEPD EUR 7,000 for unlawfully disclosing personal data, including health information, in response to a Google review. The authority found a breach of confidentiality and of the security obligations under the GDPR. | ES | AEPD | GDPR | €7,000 | ↗ |
| 02 Oct 2020 | INSTITUTO DEL DAÑO CEREBRAL Y PSÍQUICO, S.L.The entity did not provide timely access to clinical records, which constituted a breach of data protection obligations. Deficiencies were also identified in the website's cookie policy, leading the AEPD to impose a fine. | ES | AEPD | ePrivacy | €3,000 | ↗ |
| 21 Feb 2014 | INSTITUCIÓN EUROAMERICANA DE FORMACIÓN E.I.R.L.The entity was fined by the AEPD in the amount of 39,000 EUR for sending unsolicited commercial emails without prior recipient consent. This constituted a breach of Article 21 of the LSSI governing electronic marketing communications. | ES | AEPD | ePrivacy | €39,000 | ↗ |
| 12 Apr 2021 | INSTAPACK, S.L.INSTAPACK, S.L. was fined by the AEPD for sending unsolicited SMS messages without valid consent. The authority also found that the company failed to respond to a deletion request, constituting a breach of GDPR Article 6(1)(a). | ES | AEPD | GDPR | €3,000 | ↗ |
| 09 Aug 2018 | InsingerGilissen Bankiers N.V.Theodoor Gilissen Bankiers N.V. failed to provide a complete overview of personal data processing upon request, which breached data protection rules. Its successor, InsingerGilissen Bankiers N.V., was fined EUR 48,000. | NL | AP | GDPR | €48,000 | ↗ |
| 20 Dec 2021 | INSEKT FOOD S.L.INSEKT FOOD S.L. was fined by the AEPD EUR 4,000 for sharing an individual's personal data in WhatsApp group chats without consent. The authority found that the processing lacked a lawful basis under Article 6 of the GDPR. | ES | AEPD | GDPR | €4,000 | ↗ |
| 12 Mar 2026 | INPS – Istituto nazionale previdenza socialeThe Italian Data Protection Authority fined INPS EUR 40,000 for improperly displaying personal data of individuals residing in a care facility during an ISEE precompilation request. The authority found a breach of data protection principles. | IT | Garante | GDPR | €40,000 | ↗ |