BULLETIN №081Last updated · 27 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -20.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 23 Oct 2025 | Geturhotels SrlGeturhotels Srl was fined EUR 6,000 by the Garante for sending unsolicited SMS messages to a complainant despite their objection. The authority found that the company’s conduct breached GDPR rules on processing personal data for promotional purposes. | IT | Garante | GDPR | €6,000 | ↗ |
| 23 Oct 2025 | Comune di Arcinazzo RomanoThe Garante fined Comune di Arcinazzo Romano 4,500 EUR for unlawfully processing personal data through a video system. The system was used to verify tax compliance for waste disposal, in breach of the principles of lawfulness, fairness, transparency, and purpose limitation. | IT | Garante | GDPR | €4,500 | ↗ |
| 23 Oct 2025 | Dane anonimowe (Komornika Sądowego przy Sądzie Rejonowym w S. B. F. Kancelaria)The President of UODO imposed an administrative fine on the bailiff’s office for failing to report a personal data breach within the required 72 hours. The authority also found that the affected individual was not notified without undue delay after the data was disclosed to an unauthorized recipient. | PL | UODO | GDPR | €1,819 | ↗ |
| 23 Oct 2025 | Emera SrlEmera Srl was fined by the Garante EUR 6,000 for sending unsolicited promotional SMS messages despite the recipient's repeated requests for data deletion. The authority also found inadequate data retention and organizational procedures to ensure respect for data subject rights. | IT | Garante | GDPR | €6,000 | ↗ |
| 23 Oct 2025 | Provvedimento del 23 ottobre 2025 [10210718]The Garante imposed a EUR 10,000 fine on an individual tobacco shop owner for suspicious financial transactions involving the misuse of a third party’s identification data with a prepaid card. The case concerns unauthorized use of personal data in the context of payment operations. | IT | Garante | GDPR | €10,000 | ↗ |
| 22 Oct 2025 | SPRINTER MEGACENTROS DEL DEPORTE, S.L.SPRINTER MEGACENTROS DEL DEPORTE, S.L. experienced a data breach affecting approximately 6.2 million individuals, involving unauthorized access and encryption of critical systems. The incident was intentional and involved data from multiple EU member states. | ES | AEPD | GDPR | €2,600,000 | ↗ |
| 22 Oct 2025 | AXARNET COMUNICACIONES, S.L.AXARNET COMUNICACIONES, S.L. suffered a data breach caused by a vulnerability in a third-party program. The incident exposed personal data of 50,250 clients, including names, email addresses, and bank account details, leading to a fine by the AEPD. | ES | AEPD | GDPR | €20,000 | ↗ |
| 22 Oct 2025 | Agency for Control of Outstanding Debts S.R.L.The company was fined EUR 2,000 by ANSPDCP for breaching multiple GDPR provisions. The case followed a complaint alleging deficiencies in personal data protection compliance. | RO | ANSPDCP | GDPR | €2,000 | ↗ |
| 22 Oct 2025 | εκδοτικός οίκοςThe Greek Data Protection Authority fined a publishing house EUR 9,000 for disclosing an author's personal and special-category data in an email sent to 55 recipients. It also found failures to implement data protection by design and to notify both the authority and the data subject of the breach. | GR | Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα | GDPR | €9,000 | ↗ |
| 20 Oct 2025 | The Medical Specialist GroupThe Medical Specialist Group LLP reported a personal data breach after suspicious emails indicated that cyber criminals had accessed its mail server. An internal investigation found the server had been compromised in August 2021 through multiple vulnerabilities, allowing access to and theft of stored emails containing personal data. | GG | ODPA | GDPR | €115,000 | ↗ |
| 20 Oct 2025 | S.P.E.E.H. HIDROELECTRICA SAS.P.E.E.H. HIDROELECTRICA SA was fined by ANSPDCP EUR 5,000 for failing to notify a personal data breach. The incident involved customer data, including names, contract details, and billing information. | RO | ANSPDCP | GDPR | €5,000 | ↗ |
| 17 Oct 2025 | Experian Nederland B.V.Experian Nederland B.V. was fined by the AP €2,700,000 for failing to adequately inform data subjects and for processing personal data without a valid legal basis. The case concerns breaches of the GDPR principles of transparency and lawful processing. | NL | AP | GDPR | €2,700,000 | ↗ |
| 16 Oct 2025 | SOCIETE EXERCANT UNE ACTIVITE D'EDITION DE REVUES ET PERIODIQUES (procédure simplifiée)CNIL imposed an administrative fine of EUR 4,000 on SOCIETE EXERCANT UNE ACTIVITE D'EDITION DE REVUES ET PERIODIQUES and issued an injunction. The case concerns a breach of regulatory obligations in the data protection area. | FR | CNIL | GDPR | €4,000 | ↗ |
| 16 Oct 2025 | SUPERMARCHE (procédure simplifiée)CNIL imposed an administrative fine of EUR 20,000 on SUPERMARCHE and issued an injunction. The case was handled under a simplified procedure. | FR | CNIL | GDPR | €20,000 | ↗ |
| 16 Oct 2025 | PRIME TRANSACTION SAPRIME TRANSACTION SA was fined EUR 2,000 by ANSPDCP for a data security breach caused by a cyberattack. The incident led to unauthorized access to personal data of many individuals, including identification, contact, financial information, and copies of identity documents. | RO | ANSPDCP | GDPR | €2,000 | ↗ |
| 16 Oct 2025 | SOCIETE DE CENTRES D'APPELSCNIL imposed an administrative fine of EUR 250,000 on SOCIETE DE CENTRES D'APPELS. The case concerns a breach of personal data protection rules. | FR | CNIL | GDPR | €250,000 | ↗ |
| 16 Oct 2025 | SOCIETE EXERCANT UNE ACTIVITE DE GESTION DE CENTRES DE SPORTS ET DE LOISIRS (procédure simplifiée)The CNIL imposed an administrative fine of EUR 20,000 on SOCIETE EXERCANT UNE ACTIVITE DE GESTION DE CENTRES DE SPORTS ET DE LOISIRS. The authority also issued an injunction to remedy the identified deficiencies. | FR | CNIL | GDPR | €20,000 | ↗ |
| 16 Oct 2025 | SOCIETE EXERCANT UNE ACTIVITE DE VENTE A DISTANCE SUR CATALOGUE SPECIALISE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 3,000 on SOCIETE EXERCANT UNE ACTIVITE DE VENTE A DISTANCE SUR CATALOGUE SPECIALISE. The case concerns a breach of rules supervised by the CNIL. | FR | CNIL | GDPR | €3,000 | ↗ |
| 15 Oct 2025 | CapitaThe ICO fined Capita GBP 14 million after a data breach exposed the personal data of more than 6 million people. The case points to failures in security controls, governance, and GDPR compliance. | GB | Information Commissioner's Office | GDPR | €16,083,000 | ↗ |
| 15 Oct 2025 | Capita plc and Capita Pension Solutions LtdThe UK Information Commissioner’s Office fined Capita plc and Capita Pension Solutions Ltd a combined £14m after a cyber attack in April 2023. Hackers gained access to the data of more than 6 million people. The case highlights serious weaknesses in data protection and incident response. | GB | ICO | GDPR | €16,083,000 | ↗ |