BULLETIN №081Last updated · 27 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -20.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 04 Apr 2025 | Unnamed bankThe Polish data protection authority imposed a fine of EUR 928,498.06 on a bank. The authority found that the bank failed to inform customers about a personal data breach. The case concerns post-incident notification obligations. | PL | Polish Data Protection Authority | GDPR | €928,000 | ↗ |
| 15 May 2025 | SOCIETE AYANT UNE ACTIVITE DE MARKETING ET DE CONCEPTION DE SITES WEBThe CNIL imposed an administrative fine of EUR 900,000 on SOCIETE AYANT UNE ACTIVITE DE MARKETING ET DE CONCEPTION DE SITES WEB and issued an injunction. The case concerns a regulatory breach requiring corrective action. | FR | CNIL | GDPR | €900,000 | ↗ |
| 04 Jul 2024 | Postel S.p.A.Postel S.p.A. was fined by the Garante EUR 900,000 for a data breach following a ransomware attack. The attack exploited vulnerabilities in the Microsoft Exchange platform, resulting in unauthorized access to data and publication on the dark web. | IT | Garante | GDPR | €900,000 | ↗ |
| 27 Nov 2024 | E.ON Energia S.p.A.E.ON Energia S.p.A. was fined EUR 892,738 by the Garante for telemarketing-related violations. The authority cited repeated contact attempts and numerous communications sent without proper consent. | IT | Garante | GDPR | €892,000 | ↗ |
| 28 Oct 2025 | Aktia PankkiThe sanction panel of the Finnish Data Protection Ombudsman’s Office imposed an EUR 865,000 fine on Aktia Pankki for deficiencies in information security in its strong electronic identification service. The incident caused some users to see other customers’ data in services requiring strong authentication. | FI | Tietosuojavaltuutetun toimisto | GDPR | €865,000 | ↗ |
| 02 Feb 2017 | Marc 1 s.r.l.Marc 1 s.r.l. was fined €850,000 by the Garante for transferring money to China using techniques designed to avoid anti-money laundering rules. The authority also found that the actual senders had not given consent for the processing of their personal data. | IT | Garante | GDPR | €850,000 | ↗ |
| 28 Mar 2023 | Sky Italia S.r.l.The Italian Data Protection Authority fined Sky Italia S.r.l. EUR 842,062 for violations related to telemarketing and commercial communications. The company failed to properly verify consent, relied on outdated consents, and did not check the Public Register of Oppositions before campaigns. | IT | Garante per la protezione dei dati personali | GDPR | €842,000 | ↗ |
| 12 Sept 2024 | Sky Italia S.r.l.Sky Italia S.r.l. was fined EUR 842,062 by the Garante for telemarketing violations. The authority found that the company contacted individuals without proper consent and failed to consult the Public Register of Objections before promotional campaigns. | IT | Garante | GDPR | €842,000 | ↗ |
| 18 Jan 2018 | Telecom Italia S.p.A.Telecom Italia S.p.A. was fined EUR 840,000 by the Garante for making promotional phone calls to individuals who had not consented to the processing of their data for marketing purposes. The case indicates a breach of lawful processing rules and consent requirements. | IT | Garante | GDPR | €840,000 | ↗ |
| 06 Jul 2020 | Bureau Krediet Registratie (BKR)Bureau Krediet Registratie (BKR) was fined EUR 830,000 by the AP for not providing free electronic access to personal data. The authority found this practice breached the GDPR right of access. | NL | AP | GDPR | €830,000 | ↗ |
| 13 Apr 2023 | Arnia società cooperativaThe Garante imposed a fine of 800,000 EUR on Arnia società cooperativa for unauthorized data processing and telemarketing activities. The case concerned a breach of GDPR Article 5. | IT | Garante | GDPR | €800,000 | ↗ |
| 05 Sept 2024 | SOCIETE SPECIALISEE DANS L’EDITION ET LA VENTE DE LOGICIELS DE GESTION AUX MEDECINSThe CNIL imposed an administrative fine of EUR 800,000 on SOCIETE SPECIALISEE DANS L’EDITION ET LA VENTE DE LOGICIELS DE GESTION AUX MEDECINS. The case concerns a breach of rules supervised by the CNIL. | FR | CNIL | GDPR | €800,000 | ↗ |
| 18 Apr 2018 | Anonymizováno (ÚOOÚ UOOU-09774/17-25)The entity was fined for processing personal data of hundreds of thousands of individuals without consent or another legal basis. The authority found this to be a breach of § 5(2) of the Czech Data Protection Act. | CZ | UOOU | GDPR | €31,616 | ↗ |
| 01 Jan 2021 | ORANGE ESPAGNE, S.A.U.ORANGE ESPAGNE, S.A.U. was fined 800,000 EUR by the AEPD for failing to adequately protect personal data. The breach enabled identity fraud and unauthorized access to banking information through SIM card duplication. | ES | AEPD | GDPR | €800,000 | ↗ |
| 16 May 2018 | Telecom Italia S.p.A.Telecom Italia S.p.A. was fined by the Garante €800,000 for the unauthorized activation of numerous residential phone lines in a citizen's name. The case involved processing and disclosing personal data without a legal basis, as well as failing to notify data breaches. | IT | Garante | GDPR | €800,000 | ↗ |
| 09 Dec 2020 | Ítélet a NAIH/2019/3633/10 sz. ügyben (Fővárosi Törvényszék 106.K.700.561/2019/16) - 2020. december 9.The case concerned a HUF 800,000 fine imposed by the NAIH for unlawful camera surveillance. The authority found that the processing breached GDPR principles of lawfulness, fairness, transparency, purpose limitation, and data minimization. | HU | NAIH | GDPR | €2,240 | ↗ |
| 10 Nov 2022 | SOCIETE DEVELOPPANT UN LOGICIEL DE VOIX SUR IP ET UNE MESSAGERIE INSTANTANEECNIL imposed a fine of 800,000 EUR on SOCIETE DEVELOPPANT UN LOGICIEL DE VOIX SUR IP ET UNE MESSAGERIE INSTANTANEE. The decision concerns a breach of rules covered by the authority’s enforcement action. | FR | CNIL | GDPR | €800,000 | ↗ |
| 09 Jul 2020 | Iliad Italia S.p.A.Iliad Italia S.p.A. was fined EUR 800,000 by the Garante for irregularities in the processing of customer data. The violations concerned SIM card activation, promotional use of data, inadequate security measures, and improper data retention. | IT | Garante | GDPR | €800,000 | ↗ |
| 22 Jul 2021 | Roma CapitaleRoma Capitale was fined EUR 800,000 by the Garante for failing to adequately protect the personal data of motorists using parking meters. The authority also found improper data retention practices, increasing the risk to data subjects. | IT | Garante | GDPR | €800,000 | ↗ |
| 28 Aug 2024 | SOCIETE SPECIALISEE DANS LA REALISATION D'ETUDES STATISTIQUES EN MATIERE DE DONNEES DE SANTECNIL imposed an administrative fine of 800,000 EUR on SOCIETE SPECIALISEE DANS LA REALISATION D'ETUDES STATISTIQUES EN MATIERE DE DONNEES DE SANTE. The decision concerns violations related to data processing and should be assessed against applicable data protection obligations. | FR | CNIL | GDPR | €800,000 | ↗ |