BULLETIN №081Last updated · 26 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -20.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 20 Dec 2025 | JOMAFRAN 2013, S. LJOMAFRAN 2013, S. L was fined by the AEPD EUR 1,400 for sending unsolicited commercial emails without prior consent. The authority found this conduct breached Article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €1,400 | ↗ |
| 20 Dec 2025 | KVIKU SPAIN, S.L.KVIKU SPAIN, S.L. was fined by the AEPD 5,000 EUR for processing personal data without a legal basis. The case concerned debt collection related to a loan that the complainant had neither consented to nor requested. | ES | AEPD | GDPR | €5,000 | ↗ |
| 19 Dec 2025 | HelsaMiNorway’s digital accessibility regulator found 119 accessibility errors at HelsaMi, with 64 issues still unresolved after the initial remediation deadline. The operator was ordered to fix the problems by 2025-12-19 or face a daily penalty of NOK 50,000 until compliance is achieved. | NO | Tilsynet for universell utforming av IKT | EAA | €4,197 | ↗ |
| 19 Dec 2025 | MÁV Személyszállítási Zártkörűen Működő RészvénytársaságThe NAIH imposed a 50,000,000 HUF fine on MÁV Személyszállítási Zrt. for breaching GDPR principles. The authority found deficiencies in transparency and data minimization in the company's camera surveillance and audio recording practices at HÉV stations. | HU | NAIH | GDPR | €129,000 | ↗ |
| 19 Dec 2025 | ORANGE ESPAGNE, S.A.U.ORANGE ESPAGNE, S.A.U. was fined by the AEPD 25,000 EUR for sending invoices to a person who was not a customer and for failing to properly delete their data after a request. The authority found breaches of data accuracy and the right to erasure under GDPR Articles 5(1)(d) and 17. | ES | AEPD | GDPR | €25,000 | ↗ |
| 18 Dec 2025 | Comune di NaveComune di Nave was fined by the Garante for failing to ensure transparency in the processing of vehicle license plate data captured by surveillance cameras. The authority also found a breach of GDPR principles and the absence of a data protection impact assessment. | IT | Garante | GDPR | €6,000 | ↗ |
| 18 Dec 2025 | Elba Catering Distribuzioni s.r.l.s.Elba Catering Distribuzioni s.r.l.s. was fined EUR 2,000 by the Garante for installing a video surveillance system that primarily captured public streets. The authority found that this processing breached data protection rules. | IT | Garante | GDPR | €2,000 | ↗ |
| 18 Dec 2025 | Anticimex s.r.l.Anticimex s.r.l. was fined EUR 40,000 by the Garante for breaching data protection rules. The company failed to provide an employee with access to personal data, including work-related emails and CRM access logs, despite a request under Article 15 GDPR. | IT | Garante | GDPR | €40,000 | ↗ |
| 18 Dec 2025 | SOCIETE EXERCANT UNE ACTIVITE D'AGENCE DE VOYAGE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 2,000 on SOCIETE EXERCANT UNE ACTIVITE D'AGENCE DE VOYAGE and issued an injunction. The case concerns a breach of rules supervised by the CNIL. | FR | CNIL | GDPR | €2,000 | ↗ |
| 18 Dec 2025 | SOCIETE AYANT POUR ACTIVITE L'AMENAGEMENT PAYSAGER, L'INSTALLATION DE JARDINS ET DE TERRAINS DE SPORT (procédure simplifiée)The CNIL imposed an administrative fine of EUR 7,000 on the company engaged in landscaping, garden installation, and sports field installation. The case was handled under a simplified procedure. | FR | CNIL | GDPR | €7,000 | ↗ |
| 18 Dec 2025 | Provvedimento del 18 dicembre 2025 [10210431]A professional sent a communication containing personal data to an institutional email address, which breached data protection rules. The Garante imposed a fine of EUR 1,000. | IT | Garante | GDPR | €1,000 | ↗ |
| 18 Dec 2025 | SOCIETE EXERCANT UNE ACTIVITE DE REALISATION D'OPERATIONS DE PROSPECTION COMMERCIALE PAR VOIE ELECTRONIQUE POUR LE COMPTE D'AGENCES DE PUBLICITE (procédure simplifiée)CNIL imposed an administrative fine of EUR 6,000 on SOCIETE EXERCANT UNE ACTIVITE DE REALISATION D'OPERATIONS DE PROSPECTION COMMERCIALE PAR VOIE ELECTRONIQUE POUR LE COMPTE D'AGENCES DE PUBLICITE. The case was handled under a simplified procedure. | FR | CNIL | GDPR | €6,000 | ↗ |
| 18 Dec 2025 | LTL S.p.A.LTL S.p.A. was fined 40,000 EUR by the Garante for unlawfully maintaining access to an ex-employee’s email account after termination. The authority found this to be a breach of data protection rules. | IT | Garante | GDPR | €40,000 | ↗ |
| 18 Dec 2025 | SOCIETE EXERCANT UNE ACTIVITE DE PROGRAMMATION INFORMATIQUE (GESTIONS LOCATIVE ET DE COPROPRIETE) (procédure simplifiée)The CNIL imposed an administrative fine of EUR 15,000 on SOCIETE EXERCANT UNE ACTIVITE DE PROGRAMMATION INFORMATIQUE and issued an injunction. The case concerned a breach of personal data protection obligations. | FR | CNIL | GDPR | €15,000 | ↗ |
| 18 Dec 2025 | SOCIETE EXERCANT UNE ACTIVITE DE COLLECTE DE DONNEES PROVENANT DE JEUX CONCOURS, DE PROSPECTION COMMERCIALE ET DE TRANSMISSION DE DONNEES A SES CLIENTS (procédure simplifiée)CNIL imposed an administrative fine of 20,000 EUR on a company engaged in collecting data from prize contests, commercial prospecting, and data transmission to clients. The case was handled under a simplified procedure. | FR | CNIL | GDPR | €20,000 | ↗ |
| 18 Dec 2025 | Pioneer Hi-Bred Italia Sementi s.r.l.Pioneer Hi-Bred Italia Sementi s.r.l. was fined by the Garante 120,000 EUR for installing telematic devices in company vehicles to monitor employees' driving behavior. The authority found that the processing lacked proper data protection safeguards and privacy information. | IT | Garante | GDPR | €120,000 | ↗ |
| 18 Dec 2025 | TELCOM BUSINESS SOLUTIONS S.L.TELCOM BUSINESS SOLUTIONS S.L. was fined by the AEPD for attempting to process live and biometric data without prior consent. After a purchase, users were redirected to a US-based company for identity verification. | ES | AEPD | GDPR | €25,000 | ↗ |
| 17 Dec 2025 | Stichting Hogeschool van Arnhem en NijmegenThe Autoriteit Persoonsgegevens imposed a fine of €175,000 on Stichting Hogeschool van Arnhem en Nijmegen for failing to implement adequate technical and organizational measures appropriate to the risk. These deficiencies resulted in a data breach. | NL | AP | GDPR | €175,000 | ↗ |
| 17 Dec 2025 | HAN University of Applied SciencesThe Autoriteit Persoonsgegevens announced on 17 December 2025 that it had imposed a fine on HAN University of Applied Sciences. According to the notice, the university was hacked in September 2021, resulting in a data breach, and HAN will not object to the decision. | NL | Autoriteit Persoonsgegevens | GDPR | €100,000 | ↗ |
| 16 Dec 2025 | Anonymisé (CNPD decision-06-fr-2025)The company failed to maintain a proper record of processing activities under Article 30 GDPR. The register contained inaccuracies and omissions, indicating a breach of documentation obligations. | LU | CNPD | GDPR | €1,277 | ↗ |