BULLETIN №081Last updated · 27 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -20.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 04 Nov 2025 | SOCIETE EXERCANT UNE ACTIVITE DE CONSEIL ET AIDE A LA GESTION AUPRES DE CLUBS DE SPORTS SUBAQUATIQUES (procédure simplifiée)CNIL imposed an administrative fine of 4,000 EUR on SOCIETE EXERCANT UNE ACTIVITE DE CONSEIL ET AIDE A LA GESTION AUPRES DE CLUBS DE SPORTS SUBAQUATIQUES under a simplified procedure. The decision concerns a regulatory breach handled in administrative proceedings. | FR | CNIL | GDPR | €4,000 | ↗ |
| 04 Nov 2025 | McDonald'sThe Polish Data Protection Authority imposed a EUR 4,022,773 fine on McDonald's for insufficient security measures in personal data processing. A separate EUR 43,680 fine was also issued to the service provider involved in the same incident. | PL | Polish Data Protection Authority | GDPR | €4,022,000 | ↗ |
| 03 Nov 2025 | Fiziskas personaA fine of EUR 250 was imposed by DVI. The decision has entered into force. | LV | DVI | GDPR | €250 | ↗ |
| 01 Nov 2025 | LastPass UK LtdIn November 2025, the Information Commissioner’s Office imposed a monetary penalty of about £1.2 million on LastPass UK Ltd. The sanction concerned security and governance failures that led to a breach affecting around 1.6 million UK users, despite the use of strong encryption. | GB | Information Commissioner's Office | GDPR | €1,361,000 | ↗ |
| 01 Nov 2025 | Właścicielka lecznicy stomatologicznejThe owner of a dental clinic was fined 85,588 PLN by UODO for failing to notify affected patients in time after a personal data breach. The WSA and then the NSA upheld the penalty, finding that the required notices were sent too late. | PL | President of the Personal Data Protection Office (UODO) | GDPR | €20,110 | ↗ |
| 28 Oct 2025 | Aktia PankkiThe sanction panel of the Finnish Data Protection Ombudsman’s Office imposed an EUR 865,000 fine on Aktia Pankki for deficiencies in information security in its strong electronic identification service. The incident caused some users to see other customers’ data in services requiring strong authentication. | FI | Tietosuojavaltuutetun toimisto | GDPR | €865,000 | ↗ |
| 28 Oct 2025 | SIA ZZ DatsThe Latvian Data State Inspectorate found that SIA ZZ Dats failed to meet GDPR Article 32 requirements for appropriate technical and organizational measures. The case involved a major personal data leak affecting nearly all Latvian municipalities, and the authority imposed an administrative fine of EUR 300,000. The company has appealed the decision. | LV | Datu valsts inspekcija | GDPR | €300,000 | ↗ |
| 27 Oct 2025 | Anonymisiert (DSB 2025-0.811.087)The controller unlawfully processed personal data through video surveillance, including public sidewalk areas, contrary to data minimization principles. Images were also published online without a legal basis. | AT | DSB | GDPR | €1,500 | ↗ |
| 25 Oct 2025 | MAR DEGUSTACIÓN, S.LMAR DEGUSTACIÓN, S.L was fined by the AEPD 1,000 EUR for installing a video surveillance system without proper consent and for failing to inform affected individuals. The authority cited breaches of GDPR Articles 5(1)(c) and 13. | ES | AEPD | GDPR | €1,000 | ↗ |
| 25 Oct 2025 | TELECONTACT LIST S.L.TELECONTACT LIST S.L. was fined 1,000 EUR by the AEPD for failing to respond to a data subject’s request for access to and deletion of personal data. The authority found a breach of Article 15 of the GDPR. | ES | AEPD | GDPR | €1,000 | ↗ |
| 23 Oct 2025 | Provvedimento del 23 ottobre 2025 [10195910]A fine of EUR 1,000 was imposed for the unlawful online publication of personal data by a local authority. The conduct breached core data protection principles. | IT | Garante | GDPR | €1,000 | ↗ |
| 23 Oct 2025 | Istituto d'Istruzione Superiore “Statista Aldo Moro” di Fara SabinaThe school published on its website a document containing personal data related to a student's disciplinary proceeding. Garante found that this breached the GDPR principles of lawfulness, fairness, and transparency. | IT | Garante | GDPR | €4,000 | ↗ |
| 23 Oct 2025 | Hearst Magazines Italia S.p.A.Hearst Magazines Italia S.p.A. was fined EUR 20,000 by the Garante for publishing personal data relating to an individual's health without a legal basis. The authority found a breach of the principles of lawfulness and fairness in processing. | IT | Garante | GDPR | €20,000 | ↗ |
| 23 Oct 2025 | Ordine degli Avvocati di LatinaOrdine degli Avvocati di Latina was fined EUR 15,000 by the Garante for unlawful, incorrect, and non-transparent processing of personal data. The authority also found a failure to ensure data minimization. | IT | Garante | GDPR | €15,000 | ↗ |
| 23 Oct 2025 | Azzurra Sport s.r.l.Azzurra Sport s.r.l. was fined EUR 4,000 by the Garante for unlawful processing of personal data through a video surveillance system. The breach concerned the absence of appropriate informational signage for individuals subject to the monitoring. | IT | Garante | GDPR | €4,000 | ↗ |
| 23 Oct 2025 | Comune di AvolaThe Garante fined Comune di Avola 2,000 EUR for failing to provide the Authority with the Data Protection Officer’s contact details. The breach concerned the obligation under Article 37(7) GDPR. | IT | Garante | GDPR | €2,000 | ↗ |
| 23 Oct 2025 | Comune di CurtaroloComune di Curtarolo was fined EUR 15,000 by the Garante for using surveillance footage for disciplinary purposes without proper legal justification. The authority also found that adequate privacy information was not provided to the individuals concerned. | IT | Garante | GDPR | €15,000 | ↗ |
| 23 Oct 2025 | Multimedia News Società CooperativaThe Garante fined Multimedia News Società Cooperativa EUR 20,000 for failing to provide a privacy notice and contact details for data requests on its website. The authority found this breached transparency obligations and data subject rights. | IT | Garante | GDPR | €20,000 | ↗ |
| 23 Oct 2025 | Franco SpellecchiaFranco Spellecchia was fined by the Garante for installing a video surveillance system around his residence without the required legal basis. The authority found that the setup breached GDPR rules, including the absence of a legitimate interest or authorization. | IT | Garante | GDPR | €500 | ↗ |
| 23 Oct 2025 | Zephiromedia S.r.l.Zephiromedia S.r.l. was fined EUR 30,000 by the Garante for sending unsolicited promotional emails. The authority also found that recipients were not given an effective way to unsubscribe or exercise their rights. | IT | Garante | GDPR | €30,000 | ↗ |