BULLETIN №083Last updated · 06 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -22.8%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 29 Apr 2022 | Fire Brigade HeadquartersA fine was imposed for unlawful processing of personal data, which breached data protection principles and security obligations. The case concerned failures to ensure compliance with data protection requirements. | GR | HDPA | GDPR | €25,000 | ↗ |
| 17 Oct 2024 | AziendaThe company was fined for failing to implement adequate security measures, which led to a data breach affecting a large number of individuals. The case indicates insufficient protection of personal data and elevated risk to data subjects. | IT | Garante | GDPR | €25,000 | ↗ |
| 27 Feb 2025 | Istarski vodovod d.o.o.Istarski vodovod d.o.o. was fined by AZOP EUR 25,000 for failing to implement adequate technical security measures. The deficiencies included the absence of two-factor authentication and monitoring systems, which led to unauthorized access and a data breach. | HR | AZOP | GDPR | €25,000 | ↗ |
| 23 Aug 2022 | Anonymisiert (DSB 2022-0.585.764)The responsible party unlawfully processed personal data by installing a hidden WiFi camera in a public restroom. This breached the GDPR principles of lawfulness, purpose limitation, and data minimization, and the data subjects were not informed. | AT | DSB | GDPR | €25,000 | ↗ |
| 01 Jan 2024 | GASEXPRESS PATRAIX, S.L.GASEXPRESS PATRAIX, S.L. was fined by the AEPD 25,000 EUR for allowing unauthorized access to previous users' data in its automated gas station system. The exposed information included DNI numbers and partial credit card numbers. | ES | AEPD | GDPR | €25,000 | ↗ |
| 07 Jul 2025 | AURThe Romanian data protection authority imposed two fines on AUR totaling EUR 25,000. The sanctions concerned unauthorized access to supporters' personal data in the AUR app and unlawful collection of personal data on campaign platforms. | RO | Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal | GDPR | €25,000 | ↗ |
| 19 Dec 2025 | ORANGE ESPAGNE, S.A.U.ORANGE ESPAGNE, S.A.U. was fined by the AEPD 25,000 EUR for sending invoices to a person who was not a customer and for failing to properly delete their data after a request. The authority found breaches of data accuracy and the right to erasure under GDPR Articles 5(1)(d) and 17. | ES | AEPD | GDPR | €25,000 | ↗ |
| 29 Jun 2018 | BANCO BILBAO VIZCAYA ARGENTARIA, S.A.Banco Bilbao Vizcaya Argentaria, S.A. was fined by the AEPD EUR 25,000 for sending unsolicited commercial messages. The authority found that recipients were not provided with a free opt-out mechanism. | ES | AEPD | ePrivacy | €25,000 | ↗ |
| 05 Feb 2026 | Gemeente DelftGemeente Delft processed personal data without a sufficient legal basis. It also processed special categories of personal data without a valid exception, breaching GDPR principles. | NL | AP | GDPR | €25,000 | ↗ |
| 14 Apr 2011 | Trentino Trasporti Esercizio S.p.A.Trentino Trasporti Esercizio S.p.A. was fined by the Garante 25,000 EUR for collecting personal data through web forms without providing the required privacy notice. This constituted a breach of Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €25,000 | ↗ |
| 31 Aug 2023 | Robin S.r.l.The Garante fined Robin S.r.l. 25,000 EUR for publishing a photograph of minors with insufficient anonymization. The case concerns a breach of personal data protection rules applicable to children. | IT | Garante | GDPR | €25,000 | ↗ |
| 05 Jan 2021 | DKN.5131.6.2020StatusprawomocnaTytuUODO imposed a fine of PLN 25,000 on the University for failing to report a personal data breach to the President of UODO. The institution also did not notify the affected individuals about the breach. | PL | UODO | GDPR | €5,498 | ↗ |
| 15 Nov 2012 | Gruppo Ro.Ri s.r.l.Gruppo Ro.Ri s.r.l. was fined by the Garante for failing to notify the cessation of data processing after the merger of Casa di cura S. Teresa del Bambin Gesù s.r.l. The authority found a breach of Article 38 of the Italian Data Protection Code. | IT | Garante | GDPR | €25,000 | ↗ |
| 18 Dec 2025 | TELCOM BUSINESS SOLUTIONS S.L.TELCOM BUSINESS SOLUTIONS S.L. was fined by the AEPD for attempting to process live and biometric data without prior consent. After a purchase, users were redirected to a US-based company for identity verification. | ES | AEPD | GDPR | €25,000 | ↗ |
| 05 Feb 2026 | Gemeente HilversumThe Autoriteit Persoonsgegevens found that Gemeente Hilversum processed personal data without a valid legal basis during an investigation into Muslim residents and organizations. The municipality accepted an administrative fine of 25,000 EUR and acknowledged responsibility. | NL | Autoriteit Persoonsgegevens | GDPR | €25,000 | ↗ |
| 01 Jan 2019 | GLOVOAPP23, S.L.GLOVOAPP23, S.L. was fined by the Spanish data protection authority, AEPD, in the amount of €25,000. The authority found a breach for failing to appoint a Data Protection Officer as required by Article 37 of the GDPR. | ES | AEPD | GDPR | €25,000 | ↗ |
| 14 Apr 2025 | niegoAn administrative fine of 25,255 PLN was imposed for failure to comply with an order contained in an administrative decision of the President of UODO. The case concerns non-fulfilment of an obligation imposed by the supervisory authority. | PL | UODO | GDPR | €5,893 | ↗ |
| 22 Nov 2012 | Mediabusiness Int. s.r.l.Mediabusiness Int. s.r.l. was fined EUR 26,000 by the Garante for sending unsolicited promotional faxes. The authority found that the company did not obtain valid consent from recipients, which breached data protection rules. | IT | Garante | GDPR | €26,000 | ↗ |
| 08 Mar 2018 | INFOMOBILITY S.P.A.INFOMOBILITY S.P.A. was fined EUR 26,000 by the Garante for providing inadequate information to customers about geolocation activities in its car sharing service. The authority found that the disclosures did not meet transparency requirements for users. | IT | Garante | GDPR | €26,000 | ↗ |
| 06 Dec 2011 | Composad s.r.l.Composad s.r.l. was fined by the Garante €26,000 for processing personal data collected through its website without properly appointing a data processor. The case concerned a breach of data protection rules and related organizational obligations. | IT | Garante | GDPR | €26,000 | ↗ |