BULLETIN №083Last updated · 06 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -22.8%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 12 Nov 2024 | Dane anonimowe (X. w Y.)UODO imposed an administrative fine of PLN 24,555 on Anonymous entity (X. in Y.) for breaches of Articles 24(1), 25(1), and 32(1)-(2) of the GDPR. The authority also ordered the processing operations to be brought into compliance with Regulation (EU) 2016/679. | PL | UODO | GDPR | €5,644 | ↗ |
| 01 Feb 2025 | Automobilus International S.R.L.The Romanian data protection authority fined Automobilus International S.R.L. 24,885 RON after concluding its investigation in February 2025. It found breaches of GDPR Articles 32(1) and 32(2) due to inadequate technical and organizational security measures following a personal data breach. | RO | Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal | GDPR | €5,000 | ↗ |
| 05 Jul 2021 | Anonymisoitu (TSV 943)The controller unlawfully processed employees' location data, breaching the GDPR principles of data minimization and lawfulness. The case concerned processing that went beyond what was necessary for the stated purpose. | FI | TSV | GDPR | €25,000 | ↗ |
| 25 Nov 2015 | Video s.r.l.Video s.r.l. was fined by the Garante 25,000 EUR for registering 500 phone cards to five unaware individuals without their consent. The case concerns a breach of data protection rules and the absence of a lawful basis for processing personal data. | IT | Garante | GDPR | €25,000 | ↗ |
| 01 Jan 2022 | CAIXABANK S.A.CaixaBank was fined EUR 25,000 by the AEPD for failing to update a customer's address despite repeated requests. The authority found this to be a breach of the GDPR right to rectification. | ES | AEPD | GDPR | €25,000 | ↗ |
| 11 Apr 2024 | Innova Camera – Azienda speciale della Camera di commercio, industria, artigianato e agricoltura di RomaInnova Camera was fined by the Garante EUR 25,000 for inadequate data security measures. The breach resulted in personal data being accessed and published online following an SQL Injection attack. | IT | Garante | GDPR | €25,000 | ↗ |
| 08 Jul 2021 | Azienda ospedaliero-universitaria SeneseAzienda ospedaliero-universitaria Senese was fined by the Garante 25,000 EUR for violations related to data breaches involving health data and patient information. The case concerned the handling of sensitive data and required assessment of compliance with data protection obligations. | IT | Garante | GDPR | €25,000 | ↗ |
| 09 Oct 2025 | EON ENERGIE ROMANIA S.A.ANSPDCP completed an investigation at EON ENERGIE ROMANIA S.A. and found a breach of GDPR provisions. As a result, an administrative fine of EUR 25,000 was imposed. | RO | ANSPDCP | GDPR | €25,000 | ↗ |
| 18 Oct 2024 | X, ul.UODO imposed an administrative fine of PLN 25,000 on X, ul. for breaching Article 37(1)(a) and Article 37(7) of Regulation 2016/679. The authority also ordered the processing operations to be brought into compliance with GDPR requirements. | PL | UODO | GDPR | €5,803 | ↗ |
| 05 Aug 2016 | LinguaphoneLinguaphone was fined 25,000 EUR by the Greek HDPA for sending unsolicited marketing emails without prior recipient consent. The conduct breached Article 11 of Law 3471/2006. | GR | HDPA | ePrivacy | €25,000 | ↗ |
| 01 Jan 2024 | BONTECU DISTRIBUCIONES, S.L.U.BONTECU DISTRIBUCIONES, S.L.U. was fined by the AEPD for processing personal data without consent and for failing to have proper data processing agreements in place. The case concerned a complainant who received an unsolicited contract from Factor Energía. | ES | AEPD | GDPR | €25,000 | ↗ |
| 14 Apr 2021 | MASTER DISTANCIA S.A.MASTER DISTANCIA S.A. was fined EUR 25,000 by the AEPD for unlawfully processing personal data by including it in credit information systems without a valid legal basis. The authority found a breach of GDPR Article 6. | ES | AEPD | GDPR | €25,000 | ↗ |
| 01 Jan 2025 | FEMXA FORMACIÓN, S.L.FEMXA FORMACIÓN, S.L. was fined by the AEPD 25,000 EUR for requiring a full copy of a student's ID during course enrollment. The authority found the data request unnecessary and inconsistent with data protection principles. | ES | AEPD | GDPR | €25,000 | ↗ |
| 24 Nov 2025 | SIA "EUROPARK LATVIA"A fine of EUR 25,000 was imposed. The decision has been appealed. | LV | DVI | GDPR | €25,000 | ↗ |
| 17 Jul 2025 | Juna S.r.l.Juna S.r.l. was fined €25,000 by the Garante for making repeated unwanted and fraudulent promotional calls to individuals. The conduct breached data protection principles, including lawful and fair processing requirements. | IT | Garante | GDPR | €25,000 | ↗ |
| 09 May 2024 | Provvedimento del 9 maggio 2024 [10027595]The authority imposed a fine on an anonymized healthcare entity for unauthorized access to patient health records by personnel without proper authorization. The case concerned GDPR requirements on data protection and processing security. | IT | Garante | GDPR | €25,000 | ↗ |
| 12 Feb 2015 | Aloisio AngeloAloisio Angelo was fined EUR 25,000 by the Italian data protection authority, Garante. The case involved activating 15 phone cards in the names of 5 individuals without their knowledge, which breached data protection rules. | IT | Garante | GDPR | €25,000 | ↗ |
| 04 Apr 2024 | SOCIETE AYANT POUR ACTIVITE LA PROSPECTION COMMERCIALE PAR COURRIEL POUR LE COMPTE D'ANNONCEURSThe CNIL imposed EUR 25,000 on SOCIETE AYANT POUR ACTIVITE LA PROSPECTION COMMERCIALE PAR COURRIEL POUR LE COMPTE D'ANNONCEURS as a liquidation of a penalty. The measure relates to non-compliance with a prior obligation and is enforcement in nature. | FR | CNIL | GDPR | €25,000 | ↗ |
| 26 Sept 2023 | RESTART ENERGY ONE S.A.RESTART ENERGY ONE S.A. was fined by ANSPDCP in the amount of EUR 25,000 for violations related to personal data processing. The case concerned non-compliance with GDPR requirements in data processing activities. | RO | ANSPDCP | GDPR | €25,000 | ↗ |
| 25 Mar 2025 | NTT DATA ROMÂNIA S.A.NTT DATA ROMÂNIA S.A. was fined by ANSPDCP in the amount of EUR 25,000 for GDPR violations. The case concerned non-compliance with personal data protection requirements. | RO | ANSPDCP | GDPR | €25,000 | ↗ |