BULLETIN №083Last updated · 05 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -22.5%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 11 Sept 2025 | COMMUNE (procédure simplifiée)CNIL imposed an administrative fine of EUR 10,000 on COMMUNE under a simplified procedure and issued a warning. The case concerns a breach of rules requiring supervisory intervention. | FR | CNIL | GDPR | €10,000 | ↗ |
| 29 May 2026 | Unicredit Bank SAUnicredit Bank SA was fined EUR 10,000 by ANSPDCP for violating GDPR provisions. The case concerns non-compliance with personal data protection requirements and should be considered in compliance risk assessments. | RO | ANSPDCP | GDPR | €10,000 | ↗ |
| 14 Mar 2019 | Comune di Porto Sant’ElpidioThe Garante fined Comune di Porto Sant’Elpidio EUR 10,000 for publishing documents on its website that contained personal data revealing the health status of individuals with disabilities. The authority found a breach of data protection rules. | IT | Garante | GDPR | €10,000 | ↗ |
| 11 May 2023 | Libra Internet Bank SALibra Internet Bank SA was fined EUR 10,000 by ANSPDCP for another breach of GDPR provisions. The case concerns non-compliance with personal data protection requirements. | RO | ANSPDCP | GDPR | €10,000 | ↗ |
| 31 May 2017 | Unit Contact s.r.l.Unit Contact s.r.l. was fined by the Garante EUR 10,000 for making unsolicited promotional calls to a number listed in the public opt-out register. The conduct breached data protection rules and telephone marketing requirements. | IT | Garante | GDPR | €10,000 | ↗ |
| 11 Sept 2025 | SOCIETE EXERCANT UNE ACTIVITE DE BANQUE ET ASSURANCE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 10,000 on SOCIETE EXERCANT UNE ACTIVITE DE BANQUE ET ASSURANCE. The case was handled under a simplified procedure. | FR | CNIL | GDPR | €10,000 | ↗ |
| 27 Dec 2023 | COMITE SOCIAL ECONOMIQUE D'ENTREPRISES (procédure simplifiée)The CNIL imposed an administrative fine of 10,000 EUR on COMITE SOCIAL ECONOMIQUE D'ENTREPRISES under a simplified procedure. The case concerns a confirmed regulatory breach, with no further details provided in the record. | FR | CNIL | GDPR | €10,000 | ↗ |
| 26 Oct 2023 | A.C. Group S.r.l.s.A.C. Group S.r.l.s. was fined by the Garante 10,000 EUR for making an unsolicited marketing call to a number listed in the Public Register of Objections without prior informed consent. The authority also found that the company failed to adequately respond to a data subject rights request. | IT | Garante | GDPR | €10,000 | ↗ |
| 13 Feb 2024 | LA VANGUARDIA EDICIONES, S.L.LA VANGUARDIA EDICIONES, S.L. was fined by the AEPD €10,000 for installing non-essential cookies on its website without obtaining valid user consent. The authority found this to be a breach of the LSSI. | ES | AEPD | ePrivacy | €10,000 | ↗ |
| 05 Oct 2017 | Qiu JunjieQiu Junjie was fined EUR 10,000 by the Garante for failing to protect video surveillance recordings with a password. The authority found this breached the minimum security measures required under the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 04 Apr 2024 | GAFAS EN RED DE ÓPTICAS, S.L.GAFAS EN RED DE ÓPTICAS, S.L. was fined €10,000 by the AEPD for sending unsolicited advertising SMS messages without providing an opt-out link. The conduct breached the LSSI rules governing electronic marketing communications. | ES | AEPD | ePrivacy | €10,000 | ↗ |
| 24 Oct 2019 | Anonymizováno (ÚOOÚ UOOU-01096/19-19)The entity was fined by the UOOU for sending commercial communications without a valid legal basis. The messages were not properly identified as commercial and the sender was not correctly identified. | CZ | UOOU | ePrivacy | €391 | ↗ |
| 30 Apr 2025 | BITDEFENDER SRLIn April 2025, the Romanian authority ANSPDCP completed an investigation into BITDEFENDER SRL and found a GDPR violation. The company was fined EUR 10,000. | RO | ANSPDCP | GDPR | €10,000 | ↗ |
| 08 Mar 2012 | Comune di Marano PrincipatoThe Municipality of Marano Principato was fined by the Garante for processing personal data without appointing data processors and for failing to adopt minimum security measures. The authority found a breach of Article 33 of the Italian Privacy Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 22 May 2018 | Ordinanza ingiunzione - 22 maggio 2018 [9027240]A general practitioner was fined for failing to adopt minimum security measures in a health information system. The deficiencies allowed unauthorized access to the data. | IT | Garante | GDPR | €10,000 | ↗ |
| 29 Jan 2020 | CASA GRACIO OPERATION, SLUCASA GRACIO OPERATION, SLU was fined by the AEPD 10,000 EUR for installing a video surveillance system that could capture public areas and access points. The authority found that this processing breached data protection rules. | ES | AEPD | GDPR | €10,000 | ↗ |
| 28 Apr 2022 | Ministero della DifesaMinistero della Difesa was fined EUR 10,000 by the Garante for improperly disclosing personal data, including health-related information, to unauthorized personnel. The authority found a breach of the principles of lawfulness, fairness, and transparency. | IT | Garante | GDPR | €10,000 | ↗ |
| 15 Jan 2020 | Comune di Francavilla FontanaThe Municipality of Francavilla Fontana was fined 10,000 EUR by the Garante for publishing personal data on its institutional website. The conduct breached data protection rules and triggered supervisory action. | IT | Garante | GDPR | €10,000 | ↗ |
| 18 Jan 2024 | Dane anonimowe (przez Pana B.W. prowadzącego działalność gospodarczą pod firmą: B.)UODO imposed an administrative fine on B. for failing to notify the supervisory authority of a personal data breach without undue delay. The authority also found that the affected individuals were not informed of the breach without undue delay. | PL | UODO | GDPR | €2,251 | ↗ |
| 04 Sept 2025 | Owner of the studentenkotenThe Belgian Data Protection Authority (GBA) imposed a total fine of EUR 9,700 on the owner of a student house. The case concerned the unlawful use of surveillance cameras inside and around the property to monitor students. | BE | Gegevensbeschermingsautoriteit (GBA) | GDPR | €9,700 | ↗ |