BULLETIN №082Last updated · 04 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 21 Nov 2022 | ING Bank NV Amsterdam Sucursala BucureștiANSPDCP completed an investigation into ING Bank NV Amsterdam Bucharest Branch and found a breach of GDPR provisions. The case was opened following a data breach notification submitted by the controller. | RO | ANSPDCP | GDPR | €20,000 | ↗ |
| 27 Aug 2025 | INGPoland’s data protection authority, UODO, fined ING more than PLN 18 million. The authority found that the bank scanned identity documents in situations not required by AML rules, including for non-customers and in cases unrelated to service provision. | PL | Urząd Ochrony Danych Osobowych | GDPR | €4,215,000 | ↗ |
| 18 Feb 2021 | INFORMÁTICA MÉDICA, S.L.INFORMÁTICA MÉDICA, S.L. was fined by the AEPD 60,000 EUR for failing to have a proper data processing agreement with its processor, OUTENUVE. The authority treated this as a breach of Article 28 GDPR. | ES | AEPD | GDPR | €60,000 | ↗ |
| 29 Jul 2011 | INFORMA D&B, SAINFORMA D&B, SA was fined by the AEPD 50,000 EUR for continuing to send commercial emails after the recipient requested unsubscribing and objected to data processing. The authority found a breach of Article 21 of the LSSI. | ES | AEPD | ePrivacy | €50,000 | ↗ |
| 08 Mar 2018 | INFOMOBILITY S.P.A.INFOMOBILITY S.P.A. was fined EUR 26,000 by the Garante for providing inadequate information to customers about geolocation activities in its car sharing service. The authority found that the disclosures did not meet transparency requirements for users. | IT | Garante | GDPR | €26,000 | ↗ |
| 27 Nov 2025 | Infobel NVInfobel NV was fined by the APD in the amount of 5,000 EUR for unlawfully processing personal data for direct marketing purposes without a valid legal basis. The authority found breaches of GDPR Articles 5(1)(a), 6(1), and 24. | BE | APD | GDPR | €5,000 | ↗ |
| 27 Nov 2025 | InfobelThe Belgian Data Protection Authority (APD) imposed a EUR 40,000 fine on Infobel on 2025-11-27. The authority found that the company resold telecom-derived personal data for marketing purposes without valid consent and ordered it to inform its business customers of the decision. | BE | Autorité de protection des données (APD) | GDPR | €40,000 | ↗ |
| 08 Aug 2014 | INFOASSIST A.E.INFOASSIST A.E. was fined by the HDPA 7,500 EUR for processing personal data without consent. The authority found breaches of legality and data minimization principles. | GR | HDPA | GDPR | €7,500 | ↗ |
| 06 Oct 2016 | Infantino Auto S.r.l. | IT | Garante | GDPR | €2,400 | ↗ |
| 23 Jul 2010 | INEXTRAMA SOL INF. SECTOR GRAFICO S.L.INEXTRAMA SOL INF. SECTOR GRAFICO S.L. was fined by the AEPD EUR 30,001 for sending unsolicited commercial emails. The conduct breached Article 21.1 of the LSSI, which prohibits unsolicited marketing communications. | ES | AEPD | ePrivacy | €30,001 | ↗ |
| 18 Jan 2021 | INDUSTRIAS METÁLICAS ANRO, S.L.INDUSTRIAS METÁLICAS ANRO, S.L. was fined by the AEPD for failing to comply with cookie policy requirements on its website. The breach concerned Article 22.2 of the LSSI. | ES | AEPD | ePrivacy | €2,000 | ↗ |
| 13 May 2024 | INDEPENDENTS DE VALLROMANESThe political party Independents de Vallromanes was fined by the AEPD €2,000. The case concerned posting images of a court judgment on social media that included the complainant’s first and last name. | ES | AEPD | GDPR | €2,000 | ↗ |
| 29 May 2026 | IndaNext Hungary Korlátolt Felelősségű TársaságNAIH imposed a fine of 25,000,000 HUF on IndaNext Hungary Kft. for unlawfully publishing personal data and special category data of an individual on www.blikk.hu. The authority found no legal basis and identified breaches of GDPR Articles 6, 9, and 12. | HU | NAIH | GDPR | €70,750 | ↗ |
| 28 Nov 2021 | INCOPROSOL, S.L.INCOPROSOL, S.L. was fined EUR 5,000 by the AEPD for recording a customer's phone conversation without informing them. The authority treated this as a breach of data protection principles. | ES | AEPD | GDPR | €5,000 | ↗ |
| 01 Jan 2024 | INCIBEINCIBE was fined EUR 2,000 by the AEPD for failing to implement data protection by design and by default, in breach of Article 25 GDPR. The procedure concerning the alleged breach of Article 5(1)(f) was dismissed because no serious threat to rights and freedoms was found. | ES | AEPD | GDPR | €2,000 | ↗ |
| 24 Feb 2010 | INBORNTECH S.L.INBORNTECH S.L. was fined by the AEPD 1,200 EUR for sending an unsolicited commercial email. The authority found that the requirements of Article 21 of the LSSI were not met. | ES | AEPD | ePrivacy | €1,200 | ↗ |
| 18 May 2012 | INATED S.L.INATED S.L. was fined by the AEPD EUR 600 for sending unsolicited commercial communications by email. This conduct breached Article 21.1 of the LSSI, which prohibits such messages without prior recipient consent. | ES | AEPD | ePrivacy | €600 | ↗ |
| 01 Jan 2015 | IMPROCONSULTEX FORMACION INFORMATICA S.L.IMPROCONSULTEX FORMACION INFORMATICA S.L. was fined by the AEPD EUR 1,000 for sending commercial communications by electronic means without prior consent. The case concerns a breach of Article 21.1 of the LSSI and indicates insufficient legal basis for electronic marketing. | ES | AEPD | ePrivacy | €1,000 | ↗ |
| 04 Jun 2025 | impresa individuale Pasquale GuadagnoThe company was fined for installing a surveillance camera without proper signage. The camera also captured areas beyond its commercial premises, which breached data protection rules. | IT | Garante | GDPR | €2,000 | ↗ |
| 30 Jan 2014 | impresa individuale Otelma di Belelli Marco AmletoThe sole proprietorship Otelma di Belelli Marco Amleto was fined EUR 6,400 by the Garante for failing to implement minimum security measures when processing sensitive data via its website. The breaches included not appointing a data processor and not preparing a security program document. | IT | Garante | GDPR | €6,400 | ↗ |