BULLETIN №081Last updated · 26 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -20.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 27 Nov 2025 | SOCIETE EDITANT ET COMMERCIALISANT DES CARTES DE PAIEMENT A DEBIT DIFFERECNIL imposed an administrative fine of 1 500 000 EUR on SOCIETE EDITANT ET COMMERCIALISANT DES CARTES DE PAIEMENT A DEBIT DIFFERE. The case concerns a breach of rules supervised by CNIL. | FR | CNIL | GDPR | €1,500,000 | ↗ |
| 27 Nov 2025 | Conde NastThe French data protection authority CNIL fined Conde Nast EUR 750,000 over cookie practices on the Vanity Fair website. The authority found that the company placed cookies without valid consent, did not provide sufficient information about necessary cookies, and made refusal and withdrawal mechanisms ineffective. | FR | CNIL | GDPR | €750,000 | ↗ |
| 27 Nov 2025 | Istituto Comprensivo “G. Falcone” Rende-Quattromiglia (CS)The Garante fined Istituto Comprensivo “G. Falcone” EUR 2,000 for breaches of data processing principles, including lawfulness, fairness, and transparency. The authority also found non-compliance with data processing agreements. | IT | Garante | GDPR | €2,000 | ↗ |
| 27 Nov 2025 | CANDIDAT AUX ELECTIONS AU PARLEMENT EUROPEEN DE 2024 (procédure simplifiée)The CNIL imposed an administrative fine of €8,000 on CANDIDAT AUX ELECTIONS AU PARLEMENT EUROPEEN DE 2024 and issued an injunction. The case concerns a breach of rules supervised by the CNIL. | FR | CNIL | GDPR | €8,000 | ↗ |
| 27 Nov 2025 | Logika Group s.r.l.Logika Group s.r.l. was fined EUR 5,000 by the Italian supervisory authority, Garante. The authority found that the company sent unsolicited commercial communications and failed to respond to a data access request, in breach of GDPR requirements. | IT | Garante | GDPR | €5,000 | ↗ |
| 27 Nov 2025 | Verisure Italy s.r.l.Verisure Italy s.r.l. was fined by the Garante EUR 400,000 for breaches of data retention and information obligations in connection with marketing activities. The case concerned customer and former customer data processed without proper consent and notice. | IT | Garante | GDPR | €400,000 | ↗ |
| 27 Nov 2025 | Infobel NVInfobel NV was fined by the APD in the amount of 5,000 EUR for unlawfully processing personal data for direct marketing purposes without a valid legal basis. The authority found breaches of GDPR Articles 5(1)(a), 6(1), and 24. | BE | APD | GDPR | €5,000 | ↗ |
| 26 Nov 2025 | Cucina di Fabio S.R.L.ANSPDCP imposed a fine of EUR 1,000 on Cucina di Fabio S.R.L. for a GDPR violation. The case concerns a confirmed breach of personal data protection rules. | RO | ANSPDCP | GDPR | €1,000 | ↗ |
| 26 Nov 2025 | Cucina di Fabio S.R.L.ANSPDCP imposed a fine of EUR 2,000 on Cucina di Fabio S.R.L. for a GDPR violation. The case concerned non-compliance with personal data protection requirements. | RO | ANSPDCP | GDPR | €2,000 | ↗ |
| 26 Nov 2025 | Anonimizirano (IP-RS 0609-104/2025/18)The entity was fined EUR 6,000 for systematically and indiscriminately collecting employees’ location data through GPS devices in company vehicles without a legal basis. The authority found a breach of the lawfulness principle under Article 5 GDPR. | SI | IP-RS | GDPR | €6,000 | ↗ |
| 25 Nov 2025 | Dane anonimowe (D. C., prowadzącego działalność gospodarczą pod firmą W.)UODO imposed a fine of PLN 7,577 on an anonymous entrepreneur for failing to implement adequate technical and organizational measures to secure data processing. The authority also found that processing was not properly limited to the controller’s instructions and that no record of processing activities was maintained. | PL | UODO | GDPR | €1,794 | ↗ |
| 24 Nov 2025 | SIA "EUROPARK LATVIA"A fine of EUR 25,000 was imposed. The decision has been appealed. | LV | DVI | GDPR | €25,000 | ↗ |
| 21 Nov 2025 | Anonimizirano (IP-RS 0609-114/2025/9)A legal entity was fined by IP-RS for failing to implement adequate organizational and technical measures to secure personal data processing on a publicly accessible web server. This led to unauthorized access to the personal data of 12 individuals. | SI | IP-RS | GDPR | €16,250 | ↗ |
| 20 Nov 2025 | LastPass UK LtdThe ICO imposed a GBP 1,228,283 penalty on LastPass UK Ltd for breaches of Article 5(1)(f) and Article 32(1)(f) UK GDPR. Failure to implement appropriate technical and organisational measures allowed a threat actor to exfiltrate personal data relating to about 1.6 million UK customers from a backup database. The most sensitive data in customer password vaults remained encrypted because of LastPass' zero-knowledge system. | GB | ICO | GDPR | €1,393,000 | ↗ |
| 20 Nov 2025 | SOCIETE AYANT POUR ACTIVITE L'EDITION DE REVUES ET PERIODIQUES ET LA REGIE PUBLICITAIRECNIL imposed an administrative fine of EUR 750,000 on SOCIETE AYANT POUR ACTIVITE L'EDITION DE REVUES ET PERIODIQUES ET LA REGIE PUBLICITAIRE. The case concerns a confirmed breach of rules supervised by the CNIL. | FR | CNIL | GDPR | €750,000 | ↗ |
| 20 Nov 2025 | SOCIETE EXERCANT DES ACTIVITES DE SOCIETES DE HOLDING ET DEVELOPPANT DES SOLUTIONS EN RESSOURCES HUMAINES (procédure simplifiée)The CNIL imposed an administrative fine of EUR 10,000 under a simplified procedure. The case concerns a breach of rules covered by the authority's decision. | FR | CNIL | GDPR | €10,000 | ↗ |
| 19 Nov 2025 | About YouThe Hungarian Competition Authority (GVH) found that About You used misleading discount pricing and pressured consumers with countdown timers and scarcity messages. The company was ordered to pay HUF 505 million to the Hungarian central budget and to provide compensation to affected Hungarian customers. | HU | Gazdasági Versenyhivatal | Omnibus | €1,323,000 | ↗ |
| 19 Nov 2025 | Greencorp S.R.L.Greencorp S.R.L. was fined EUR 3,000 by ANSPDCP. The authority found that the company failed to notify a personal data security breach. | RO | ANSPDCP | GDPR | €3,000 | ↗ |
| 18 Nov 2025 | Anonymisiert (DSB 2025-0.902.556)The responsible party unlawfully published parts of a private complaint on a social media platform. This breached data minimization principles and there was no legal basis for processing personal data. | AT | DSB | GDPR | €1,200 | ↗ |
| 17 Nov 2025 | PGS SOFA & CO SRLIn October 2025, ANSPDCP completed an investigation at PGS SOFA & CO SRL and found a GDPR violation. The authority imposed a fine of EUR 8,000. | RO | ANSPDCP | GDPR | €8,000 | ↗ |