BULLETIN №081Last updated · 26 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -20.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 21 May 2026 | The European House – Ambrosetti spaThe Italian data protection authority fined The European House – Ambrosetti spa EUR 85,000 for security shortcomings following a data breach affecting 61,670 people. The company notified affected individuals too late, only after intervention by the authority. | IT | Garante per la protezione dei dati personali | GDPR | €85,000 | ↗ |
| 20 May 2026 | KRA Consultancy LtdKRA Consultancy Ltd was fined £300,000 by the ICO for sending more than 5.5 million unsolicited direct marketing texts and fake bailiff messages. The conduct breached regulations 22 and 23 of PECR and generated over 60,000 complaints to the 7726 spam reporting service. | GB | ICO | ePrivacy | €346,000 | ↗ |
| 15 May 2026 | Unnamed Hungarian employerHungary’s data protection authority, NAIH, imposed a HUF 7 million GDPR fine on an unnamed employer. The case involved continuous camera monitoring in employee dining and rest areas, as well as deficiencies in documentation and privacy notices. | HU | Nemzeti Adatvédelmi és Információszabadság Hatóság | GDPR | €19,460 | ↗ |
| 14 May 2026 | Comune di Mirabella ImbaccariComune di Mirabella Imbaccari was fined for disclosing personal data online without a legal basis and for violating the data minimization principle. The authority also found that the municipality had failed to appoint a Data Protection Officer and to communicate the DPO’s contact details to the supervisory authority. | IT | Garante | GDPR | €1,800 | ↗ |
| 14 May 2026 | Azienda ospedaliera dei colli Monaldi-Cotugno-CTO di NapoliAzienda ospedaliera dei colli Monaldi-Cotugno-CTO di Napoli was fined EUR 15,000 by the Garante. The authority found that the entity provided false statements and interrupted the performance of its tasks. The case concerns breaches of data protection rules. | IT | Garante | GDPR | €15,000 | ↗ |
| 14 May 2026 | EmiratesEmirates was fined by the Italian Garante €180,000 for breaching data protection rules. The airline required passengers with reduced mobility to complete a medical form without providing adequate information about how their data would be processed. | IT | Garante | GDPR | €180,000 | ↗ |
| 14 May 2026 | Comune di VentassoComune di Ventasso was fined EUR 8,000 by the Garante. The authority found breaches of the principles of lawful, fair and transparent processing of personal data, as well as data minimization. | IT | Garante | GDPR | €8,000 | ↗ |
| 14 May 2026 | Energia Sostenibile S.r.l.Energia Sostenibile S.r.l. was fined EUR 100,000 by the Garante for making unsolicited calls to numbers listed in the Public Opposition Register. The authority also found that the company did not adequately respond to data subjects’ requests to exercise their rights. | IT | Garante | GDPR | €100,000 | ↗ |
| 14 May 2026 | FeGi M&A Services s.r.l.FeGi M&A Services s.r.l. was fined EUR 1,000 by the Garante for making promotional phone calls without the required consent. The authority found this conduct breached GDPR principles of fairness and transparency. | IT | Garante | GDPR | €1,000 | ↗ |
| 12 May 2026 | SWDESWDE was fined by the APD 50,000 EUR for unlawful call recordings and monitoring used for quality evaluation and training purposes. The authority found breaches of transparency, data minimization, and other GDPR principles. | BE | APD | GDPR | €50,000 | ↗ |
| 11 May 2026 | Geanonimiseerd (APD 100/2026)The Litigation Chamber imposed a fine for violations related to camera surveillance at a residential complex. It found a lack of transparency and a failure to properly facilitate data subject rights. | BE | APD | GDPR | €5,000 | ↗ |
| 11 May 2026 | South Staffordshire PlcThe ICO issued a monetary penalty against South Staffordshire Plc and South Staffordshire Water Plc in the amount of GBP 963,000. The case concerned a security breach affecting more than 633,000 individuals and an admitted infringement of Article 5(1)(f) UK GDPR. | GB | Information Commissioner's Office | GDPR | €1,113,000 | ↗ |
| 08 May 2026 | Permanent TSBPermanent TSB was fined EUR 277,500 by Ireland's Data Protection Commission. The case involved fraudsters impersonating customers at a contact centre, resulting in three GDPR breaches and financial loss to three customers. | IE | Data Protection Commission | GDPR | €277,000 | ↗ |
| 08 May 2026 | MLU B.V.MLU B.V. was fined €100,000,000 by AP for transferring personal data of users in Finland and Norway to Russia without adequate safeguards. The authority found breaches of GDPR Articles 44, 46, and 5. | NL | AP | GDPR | €100,000,000 | ↗ |
| 08 May 2026 | MLU B.V.The Dutch data protection authority imposed a EUR 100 million fine on MLU B.V. for transferring personal data to Russia without adequate safeguards. It also ordered the company to stop transferring personal data of individuals in Norway and Finland to Russia via the Yango app. | NL | Autoriteit Persoonsgegevens | GDPR | €100,000,000 | ↗ |
| 07 May 2026 | South Staffordshire Plc and South Staffordshire Water PlcThe Information Commissioner’s Office (ICO) imposed a fine of 963,900 GBP on South Staffordshire Plc and South Staffordshire Water Plc for breaches of Article 5(1)(f) and Article 32(1) of the UK GDPR. The case followed a cyber incident in which personal data relating to approximately 633,887 UK data subjects was exfiltrated. | GB | ICO | GDPR | €1,115,000 | ↗ |
| 05 May 2026 | VOX ESPAÑAVOX ESPAÑA was fined by the AEPD 500 EUR for publishing personal data on Facebook without proper consent. The authority found that this breached Article 6 of the GDPR. | ES | AEPD | GDPR | €500 | ↗ |
| 01 May 2026 | Anonymised (IDPC 0583_001)The Commissioner found that the insurance company continued to process the complainant’s personal data for direct marketing despite his objection. The authority also identified inadequate safeguards, weak accountability measures, and non-compliant arrangements with third-party processors. A reprimand was issued, corrective measures were ordered within 20 days, and administrative fines totalling EUR 1,000 were imposed. | MT | IDPC | GDPR | €1,000 | ↗ |
| 30 Apr 2026 | BLUE PROJECTS INDUSTRIES S.R.L.ANSPDCP completed an investigation in April 2026 into BLUE PROJECTS INDUSTRIES S.R.L. and found a GDPR violation. A fine of EUR 2,500 was imposed. | RO | ANSPDCP | GDPR | €2,500 | ↗ |
| 30 Apr 2026 | Intesa SanpaoloItaly’s data protection authority, Garante, fined Intesa Sanpaolo EUR 31.8 million. The sanction concerned serious failures in security and access management for personal data. | IT | Garante per la protezione dei dati personali | GDPR | €31,800,000 | ↗ |