BULLETIN №081Last updated · 26 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -20.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 07 Apr 2022 | Анонимизирано (CPDP решение-по-жалба-с-рег-№-ппн-01-101136-0)The CPDP imposed fines on two individuals for unlawful video surveillance in a co-owned property. The authority found breaches of GDPR principles of lawfulness and data minimization. | BG | CPDP | GDPR | €1,534 | ↗ |
| 12 Feb 2018 | Анонимизирано (CPDP решение-по-жалба-с-рег-№-ж-453-05-10-201)The Commission fined an individual for unlawfully processing personal data by including it in a list supporting registration for a referendum campaign without consent. The case concerned a breach of the legal basis requirements for personal data processing. | BG | CPDP | GDPR | €5,113 | ↗ |
| 16 Jun 2025 | Υφυπουργείο Κοινωνικής ΠρόνοιαςThe Cypriot Data Protection Commissioner imposed an administrative fine of EUR 5,000 on Υφυπουργείο Κοινωνικής Πρόνοιας on 16 June 2025. The case concerned CCTV cameras at the ministry’s headquarters, including three cameras that recorded audio without a legal basis and without the required GDPR safeguards. | CY | Επίτροπος Προστασίας Δεδομένων Προσωπικού Χαρακτήρα | GDPR | €5,000 | ↗ |
| 16 Jan 2026 | Πυροσβεστικό ΣώμαThe Hellenic Data Protection Authority imposed a €10,000 fine on the Fire Service for unlawfully processing an employee’s special-category health data. The authority found breaches of GDPR lawfulness and data minimization principles and noted that the data were accessible through an internal electronic application. | GR | Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα | GDPR | €10,000 | ↗ |
| 10 Mar 2025 | Οργανισμός Χρηματοδοτήσεως ΣτέγηςThe Housing Finance Corporation was fined by the CyDPC in the amount of €10,000 for retaining personal data beyond the legal retention period. The authority found this breached GDPR storage limitation and data accuracy requirements. | CY | CyDPC | GDPR | €10,000 | ↗ |
| 03 Feb 2022 | Κοινοτικό Συμβούλιο ΒορόκληνηςThe Community Council of Voroklini was fined by the CyDPC for failing to exercise due diligence in the processing of personal data. This led to unauthorized changes to mailing addresses without proper consent. | CY | CyDPC | GDPR | €2,000 | ↗ |
| 30 Mar 2026 | Κέντρο Εκπαίδευσης και Αποκατάστασης Τυφλών (ΚΕΑΤ)The Greek Data Protection Authority fined ΚΕΑΤ EUR 5,000 for an untimely and improper response to an employee’s request for access to CCTV footage. The case involved edited footage, missing material, and inadequate technical and organizational measures to support compliance. | GR | Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα | GDPR | €5,000 | ↗ |
| 22 Oct 2025 | εκδοτικός οίκοςThe Greek Data Protection Authority fined a publishing house EUR 9,000 for disclosing an author's personal and special-category data in an email sent to 55 recipients. It also found failures to implement data protection by design and to notify both the authority and the data subject of the breach. | GR | Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα | GDPR | €9,000 | ↗ |
| 16 Jan 2023 | Εκδόσεις Αρκτίνος ΛτδThe decision concerns the unlawful publication of names and photos of police investigators by the newspaper “Politis”. The authority found a breach of the data minimization principle under the GDPR. | CY | CyDPC | GDPR | €10,000 | ↗ |
| 01 Jan 2025 | Εθνική Τράπεζα της Ελλάδος Α.Ε.The data protection authority imposed a EUR 220,000 fine on Εθνική Τράπεζα της Ελλάδος Α.Ε. for a GDPR violation. The case concerned deficiencies in personal data protection and compliance with GDPR requirements. | GR | Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα | GDPR | €220,000 | ↗ |
| 21 Sept 2022 | Αρχή Ηλεκτρισμού ΚύπρουThe Cyprus DPA fined the Cyprus Electricity Authority €5,000 for a personal data breach involving unauthorized disclosure to a third party. The authority found violations of GDPR Articles 5(1)(f), 24(1), and 32. | CY | CyDPC | GDPR | €5,000 | ↗ |
| 18 Feb 2020 | ZSZZS.440.768.2018StatusuchylonaTytuUODO found a breach related to the processing of children’s biometric data in connection with use of the school canteen. A fine of PLN 20,000 was imposed. | PL | UODO | GDPR | €4,679 | ↗ |
| 21 Aug 2020 | ZSOUODO imposed a PLN 50,000 fine on ZSO for breaching personal data protection rules. The case concerned non-compliance with requirements under data protection regulations. | PL | UODO | GDPR | €11,369 | ↗ |
| 18 Nov 2015 | Zsa Zsa srlZsa Zsa srl was fined EUR 2,400 by the Italian Garante. The violation concerned the failure to provide the required privacy notice on the website’s data collection form, in breach of the Italian data protection code. | IT | Garante | GDPR | €2,400 | ↗ |
| 02 Feb 2024 | [...] Zrt.The controller did not provide adequate information about data processing through camera systems in bank branches. This constituted a breach of GDPR Articles 12 and 13. | HU | NAIH | GDPR | €156,000 | ↗ |
| 01 Jan 2015 | ZOWROOM, S.L.ZOWROOM, S.L. was fined by the AEPD EUR 500 for sending unsolicited commercial emails. The authority also found that unsubscribe requests were not honored, which constitutes a breach of the LSSI. | ES | AEPD | ePrivacy | €500 | ↗ |
| 15 Jan 2015 | Zoccatelli MichelaZoccatelli Michela was fined EUR 2,400 by the Garante for failing to provide information to individuals applying for membership in the private Aquila Club. The authority treated this as a breach of data protection rules. | IT | Garante | GDPR | €2,400 | ↗ |
| 11 Dec 2025 | ZMLUK LimitedZMLUK Limited received an MPN from the ICO for sending unsolicited emails promoting energy-saving products. The case concerns a breach of electronic marketing rules and should be reviewed for compliance with applicable consent requirements. | GB | ICO | GDPR | €119,000 | ↗ |
| 12 May 2022 | Zito Auto di Gianfranco ZitoThe company was fined for operating a video surveillance system that did not meet the information requirements under GDPR Article 13 and Article 114 of the Italian Privacy Code. The authority found that the required notices for monitored individuals were not properly provided. | IT | Garante | GDPR | €3,000 | ↗ |
| 31 Mar 2016 | Zhu XiaozhenZhu Xiaozhen was fined by the Garante for failing to provide the simplified information required under the data protection code and the video surveillance rules. The surveillance system was operated without proper notice to the individuals concerned. | IT | Garante | GDPR | €2,400 | ↗ |