BULLETIN №082Last updated · 31 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.4%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 25 Nov 2025 | Dane anonimowe (D. C., prowadzącego działalność gospodarczą pod firmą W.)UODO imposed a fine of PLN 7,577 on an anonymous entrepreneur for failing to implement adequate technical and organizational measures to secure data processing. The authority also found that processing was not properly limited to the controller’s instructions and that no record of processing activities was maintained. | PL | UODO | GDPR | €1,794 | ↗ |
| 11 Jun 2021 | Anonymisé (CNPD decision-21-fr-2021)The company did not comply with the data minimization principle and failed to adequately inform employees and third parties about data processing activities. CNPD found these practices to breach GDPR Articles 5(1)(c) and 13. | LU | CNPD | GDPR | €7,600 | ↗ |
| 30 Apr 2026 | Dane anonimowe (Burmistrza Miasta i Gminy D.)UODO imposed an administrative fine of 7,700 PLN on Anonymous data (Mayor of D. Municipality). The sanction resulted from failing to notify the President of the Personal Data Protection Office of a personal data breach without undue delay, and no later than 72 hours after becoming aware of it. | PL | UODO | GDPR | €1,807 | ↗ |
| 23 Oct 2025 | Dane anonimowe (Komornika Sądowego przy Sądzie Rejonowym w S. B. F. Kancelaria)The President of UODO imposed an administrative fine on the bailiff’s office for failing to report a personal data breach within the required 72 hours. The authority also found that the affected individual was not notified without undue delay after the data was disclosed to an unauthorized recipient. | PL | UODO | GDPR | €1,819 | ↗ |
| 14 Jan 2021 | Agenzia regionale protezione ambientale Campania (ARPAC)ARPAC was fined by the Garante EUR 8,000 for violations concerning data security measures and data breach notification obligations. The case involved non-compliance with GDPR Articles 5 and 32. | IT | Garante | GDPR | €8,000 | ↗ |
| 29 Jan 2015 | Abruzzo Vigilanza s.r.l.Abruzzo Vigilanza s.r.l. was fined €8,000 by the Garante for using a vehicle tracking system without the required notification. The case concerns non-compliance with data protection notification obligations. | IT | Garante | GDPR | €8,000 | ↗ |
| 09 Oct 2025 | Arienti & C. s.r.l. a socio unicoThe Garante fined Arienti & C. s.r.l. a socio unico EUR 8,000 for denying a former employee access to their email account after the employment contract ended. The authority found this breached GDPR Article 15 on the right of access to personal data. | IT | Garante | GDPR | €8,000 | ↗ |
| 04 May 2015 | CitibankThe HDPA imposed a fine of EUR 8,000 on Citibank. The case concerned the bank’s failure to satisfy the complainant’s right of access to personal data. | GR | HDPA | GDPR | €8,000 | ↗ |
| 02 Oct 2014 | Comune di Piana degli AlbanesiThe Municipality of Piana degli Albanesi was fined EUR 8,000 by the Garante for failing to appoint data processing officers. The authority also found that the required security program document had not been drafted, in breach of data protection rules. | IT | Garante | GDPR | €8,000 | ↗ |
| 27 Aug 2024 | YThe case concerns a football club that obtained a member list during a takeover and used the personal data for commercial mailings without a valid legal basis. The authority found breaches of several GDPR provisions and imposed a monetary fine. | BE | APD | GDPR | €8,000 | ↗ |
| 04 Dec 2020 | BORJAMOTOR, S.A.BORJAMOTOR, S.A. was fined by the AEPD €8,000 for sending commercial SMS messages without explicit consent from recipients. The authority also identified improper consent practices for personal data processing on the company’s website. | ES | AEPD | ePrivacy | €8,000 | ↗ |
| 13 Nov 2024 | Azienda Sanitaria provinciale di EnnaAzienda Sanitaria provinciale di Enna was fined by the Garante 8,000 EUR for breaches of GDPR Articles 5 and 6 and Article 2-ter of the Italian Privacy Code. The case concerned improper handling of personal data. The decision indicates non-compliance with core rules on lawful and proper processing. | IT | Garante | GDPR | €8,000 | ↗ |
| 15 Dec 2011 | dott. Mancini Endriodott. Mancini Endrio was fined EUR 8,000 by the Garante for violating data protection rules. The case concerned inadequate compliance with data security requirements under Article 162, paragraph 2-bis, of the Italian Privacy Code. | IT | Garante | GDPR | €8,000 | ↗ |
| 20 Aug 2024 | Ana Hotels SRLAna Hotels SRL was fined by ANSPDCP €8,000 after a data security incident caused by a ransomware attack. The incident led to unauthorized disclosure of personal data belonging to a significant number of employees. | RO | ANSPDCP | GDPR | €8,000 | ↗ |
| 17 Jul 2025 | Smart R.E. S.r.l.Smart R.E. S.r.l. was fined EUR 8,000 by the Italian authority Garante for failing to comply with a former employee’s deletion request. After the employment ended, the assigned email account remained active and redirected messages to another company account. | IT | Garante | GDPR | €8,000 | ↗ |
| 07 Sept 2011 | Aga s.r.l.Aga s.r.l. was fined EUR 8,000 by the Garante for processing online customers' personal data without ensuring freely given and specific consent. The authority found this to be a breach of data protection rules. | IT | Garante | GDPR | €8,000 | ↗ |
| 14 Nov 2024 | Comune di Borgo Val di TaroComune di Borgo Val di Taro was fined EUR 8,000 by the Garante for improper handling of personal data. The authority found breaches of lawfulness, fairness, transparency, and data minimization principles. | IT | Garante | GDPR | €8,000 | ↗ |
| 14 Oct 2021 | Azienda per la Tutela della Salute (ATS) della SardegnaAzienda per la Tutela della Salute (ATS) della Sardegna was fined EUR 8,000 by the Garante for improper processing of personal data, including health data. The authority found breaches of GDPR Articles 5 and 9. | IT | Garante | GDPR | €8,000 | ↗ |
| 29 Oct 2020 | Città Metropolitana di NapoliCittà Metropolitana di Napoli was fined EUR 8,000 by the Garante for improper handling of personal data. The authority found that a disciplinary document was not marked as confidential, which allowed unauthorized access within the administration. | IT | Garante | GDPR | €8,000 | ↗ |
| 17 Jan 2013 | Bagno sport 70 s.a.s.Bagno sport 70 s.a.s. was fined 8,000 EUR by the Garante for processing customers' biometric data for payments. The company failed to notify the supervisory authority, which breached the Italian Data Protection Code. | IT | Garante | GDPR | €8,000 | ↗ |