BULLETIN №082Last updated · 04 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 16 Nov 2023 | Dane anonimowe (W. sp. j. z siedzibą we W. przy ul.)The President of the Personal Data Protection Office imposed an administrative fine of PLN 14,148 on the company. The sanction was issued because the company failed to provide access to personal data and information necessary for the authority’s tasks. | PL | UODO | GDPR | €3,235 | ↗ |
| 20 Nov 2024 | Anonymisé (CNPD decision-03-fr-2024)The company was fined for installing surveillance cameras without a legal basis. The authority found breaches of GDPR principles of lawfulness, transparency, and security. | LU | CNPD | GDPR | €14,288 | ↗ |
| 25 Feb 2016 | Associazione sportivo dilettantistica Feriolo Sporting ClubFeriolo Sporting Club was fined by the Garante 14,400 EUR for failing to provide adequate simplified information about its video surveillance system. The authority also found that recorded images were retained longer than permitted. | IT | Garante | GDPR | €14,400 | ↗ |
| 12 Oct 2017 | Hu GuangyuHu Guangyu was fined EUR 14,400 by the Garante. The authority found inadequate simplified information on video surveillance and retention of recorded images beyond the permitted period. | IT | Garante | GDPR | €14,400 | ↗ |
| 20 Mar 2014 | SIGE S.p.a.SIGE S.p.a. was fined by the Italian data protection authority, Garante, in the amount of €14,400. The case concerned a video surveillance system that retained images longer than permitted under the Garante's guidelines. | IT | Garante | GDPR | €14,400 | ↗ |
| 09 Mar 2017 | Moto One s.r.l.Moto One s.r.l. was fined by the Garante in the amount of 14,400 EUR for violations related to its video surveillance system. The authority found that recorded images were retained longer than permitted and that required informational signage was missing. | IT | Garante | GDPR | €14,400 | ↗ |
| 11 Jul 2013 | Cowboys' Guest Ranch S.r.l.Cowboys' Guest Ranch S.r.l. was fined EUR 14,400 by the Garante for failing to provide the required privacy notice when collecting personal data through online forms, paper questionnaires, and dance competition registration forms. The breach concerned the obligation to inform data subjects about the processing of their personal data. | IT | Garante | GDPR | €14,400 | ↗ |
| 13 Sept 2017 | Jump 3000 s.r.l.Jump 3000 s.r.l. was fined by the Garante 14,800 EUR for providing clients with inadequate data protection information. The authority found that the privacy notices did not properly identify the data controller. | IT | Garante | GDPR | €14,800 | ↗ |
| 08 Dec 2025 | Dane anonimowe (S.)The UODO imposed an administrative fine of PLN 14,816 on Anonymous data (S.). The penalty was issued for failing to provide access to all personal data and information necessary for the President of the UODO to perform his duties. | PL | UODO | GDPR | €3,502 | ↗ |
| 11 Sept 2025 | ISV Group SrlsISV Group Srls was fined €15,000 by the Garante for sending unsolicited promotional emails without consent. The authority also found that the company failed to properly control its partner Ismax, which carried out unlawful data processing activities. | IT | Garante | GDPR | €15,000 | ↗ |
| 19 May 2021 | CP&A B.V.CP&A B.V. was fined by the AP in the amount of EUR 15,000 for processing employees' health data without a legal basis. The authority also found that adequate security measures were not implemented for this processing. | NL | AP | GDPR | €15,000 | ↗ |
| 13 Apr 2023 | Citynews S.p.A.Citynews S.p.A. was fined EUR 15,000 by the Italian data protection authority, Garante. The case concerned the publication of detailed health information about an individual without consent, in breach of GDPR Article 9 on special categories of personal data. | IT | Garante | GDPR | €15,000 | ↗ |
| 25 Apr 2024 | SOCIETE EXPLOITANT DES MAGASINS DE CHAUSSURES ET D'HABILLEMENT DE SPORT (procédure simplifiée)The CNIL imposed an administrative fine of EUR 15,000 on SOCIETE EXPLOITANT DES MAGASINS DE CHAUSSURES ET D'HABILLEMENT DE SPORT. The case was handled under a simplified procedure. | FR | CNIL | GDPR | €15,000 | ↗ |
| 20 Dec 2019 | GESTHOTEL ACTIVOS BALAGARES S.L.GESTHOTEL ACTIVOS BALAGARES S.L. was fined by the AEPD 15,000 EUR for disclosing special categories of personal data, including medical information. The authority found a breach of the integrity and confidentiality principle under GDPR Article 5(1)(f). | ES | AEPD | GDPR | €15,000 | ↗ |
| 24 Jan 2024 | CAIXA RURAL LA VALL SAN ISIDRO, S.C.C.CAIXA RURAL LA VALL SAN ISIDRO was fined by the AEPD 15,000 EUR for a personal data breach. The incident allowed unauthorized third-party access and affected the confidentiality and integrity of the data. | ES | AEPD | GDPR | €15,000 | ↗ |
| 26 Sept 2024 | SOCIETE PROPOSANT DES SERVICES DE CONSEIL EN SYSTÈMES ET LOGICIELS INFORMATIQUES, L'EDITION ET LA REALISATION DE LOGICIELS (procédure simplifiée)CNIL imposed an administrative fine of 15,000 EUR and issued an injunction. The case was handled under a simplified procedure. | FR | CNIL | GDPR | €15,000 | ↗ |
| 20 Jan 2025 | Vodafone Romania S.A.Vodafone Romania S.A. was fined EUR 15,000 by ANSPDCP for violations of GDPR provisions. The case concerns non-compliance with personal data protection requirements. | RO | ANSPDCP | GDPR | €15,000 | ↗ |
| 23 Mar 2023 | Dedalus Italia S.p.a.Dedalus Italia S.p.a. was fined EUR 15,000 by the Garante for failing to implement adequate measures to protect personal data. The authority found a breach of Article 32 GDPR on security of processing. | IT | Garante | GDPR | €15,000 | ↗ |
| 10 Oct 2024 | Dane anonimowe (X w K.)The UODO imposed an administrative fine of PLN 15,000 on the entity identified as Anonymous data (X in K.). The authority found breaches of data protection principles, including integrity and confidentiality, accountability, data protection by design, processor obligations, and security measures. | PL | UODO | GDPR | €3,485 | ↗ |
| 05 Nov 2015 | VACACIONES EDREAMS SOCIEDAD LIMITADA UNIPERSONALVACACIONES EDREAMS was fined by the AEPD for sending unsolicited commercial emails despite the recipient’s repeated attempts to unsubscribe. The authority found a breach of Article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €15,000 | ↗ |