BULLETIN №081Last updated · 27 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -20.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 05 Jul 2018 | Vodafone Italia S.p.A.Vodafone Italia S.p.A. was fined EUR 800,000 by the Garante for making unsolicited promotional phone calls and sending SMS messages without proper consent. The authority found that these practices breached data protection rules. | IT | Garante | GDPR | €800,000 | ↗ |
| 03 Oct 2023 | Utbildningsnämnden i Stockholms stad – Aspuddens skolaThe Stockholm City Education Committee was fined by IMY 800,000 SEK for unlawful camera surveillance at Aspuddens school. The authority found breaches of legality and data minimization principles, as well as a failure to provide the required information under GDPR. | SE | IMY | GDPR | €68,744 | ↗ |
| 20 Nov 2025 | SOCIETE AYANT POUR ACTIVITE L'EDITION DE REVUES ET PERIODIQUES ET LA REGIE PUBLICITAIRECNIL imposed an administrative fine of EUR 750,000 on SOCIETE AYANT POUR ACTIVITE L'EDITION DE REVUES ET PERIODIQUES ET LA REGIE PUBLICITAIRE. The case concerns a confirmed breach of rules supervised by the CNIL. | FR | CNIL | GDPR | €750,000 | ↗ |
| 27 Feb 2023 | Bank of Ireland 365 (‘BOI’)The Irish DPC fined Bank of Ireland 365 (‘BOI’) €750,000 in inquiry IN-20-7-2. The fine has been collected. | IE | DPC | GDPR | €750,000 | ↗ |
| 27 Nov 2025 | Conde NastThe French data protection authority CNIL fined Conde Nast EUR 750,000 over cookie practices on the Vanity Fair website. The authority found that the company placed cookies without valid consent, did not provide sufficient information about necessary cookies, and made refusal and withdrawal mechanisms ineffective. | FR | CNIL | GDPR | €750,000 | ↗ |
| 03 Oct 2024 | Police Service of Northern IrelandThe Police Service of Northern Ireland was fined £750,000 by the ICO for breaches of Articles 5(1)(f), 32(1) and (2) of the UK GDPR between 25 May 2018 and 14 June 2024. The case concerned insufficient protection of personal data and inadequate security of processing. The decision indicates a failure to implement appropriate technical and organisational safeguards. | GB | ICO | GDPR | €890,000 | ↗ |
| 10 Oct 2024 | SOCIETE COMMERCIALISANT DES PORTEFEUILLES DE CRYPTOMONNAIEThe CNIL imposed an administrative fine of EUR 750,000 on SOCIETE COMMERCIALISANT DES PORTEFEUILLES DE CRYPTOMONNAIE. The record indicates a regulatory breach, but no further details are provided. | FR | CNIL | GDPR | €750,000 | ↗ |
| 22 Jul 2021 | TikTok Inc.TikTok Inc. was fined 750,000 EUR by the Dutch authority AP for providing its privacy policy to users in the Netherlands, including children, only in English. The authority found this breached Article 12 GDPR, which requires information to be provided in a clear and easily accessible form. | NL | AP | GDPR | €750,000 | ↗ |
| 30 Apr 2020 | vingerafdrukken personeelThe Autoriteit Persoonsgegevens imposed a fine for the unlawful processing of employees' biometric data, specifically fingerprints, for time registration purposes. The authority found this to be a breach of Article 9 of the GDPR. | NL | AP | GDPR | €725,000 | ↗ |
| 31 May 2019 | Kamerafelvételek kiadásának elmulasztásaThe controller did not inform the data subject about the actions taken on their requests within the required timeframe. It also failed to provide access to certain data, which constituted a GDPR breach. | HU | NAIH | GDPR | €2,156 | ↗ |
| 14 Oct 2020 | Munkahelyi kamerás megfigyelés célhoz kötöttséggel, adattakarékossággal és az érintettek tájékoztatásával kapcsolatos hiányosságaiThe entity was fined by NAIH in the amount of HUF 700,000 for improperly implementing camera surveillance of employees. The authority also found that employees were not adequately informed about the scope and rules of the video monitoring. | HU | NAIH | GDPR | €1,925 | ↗ |
| 17 Jan 2025 | Dane anonimowe (X. z siedzibą w K.)The UODO imposed administrative fines on X. based in K. for breaches of Article 6(1), Article 9(1), Article 13(1) and (2), Article 25(1), and Article 32(1) and (2) of the GDPR. These breaches also resulted in violations of the principles in Article 5(1)(a) and (f) and Article 5(2) of the GDPR. | PL | UODO | GDPR | €161,000 | ↗ |
| 13 Nov 2024 | Illumia S.p.A.Illumia S.p.A. was fined by the Italian data protection authority, Garante, for violations related to the processing of personal data for telemarketing purposes. The authority cited inadequate contractual arrangements with sub-processors and insufficient oversight of commercial partners. | IT | Garante | GDPR | €678,000 | ↗ |
| 14 Apr 2023 | Sorgenia S.p.a.Sorgenia S.p.a. was fined EUR 676,956 by the Italian data protection authority, Garante. The case concerned failure to respect data deletion and objection rights in connection with unlawful telemarketing practices in the energy sector. | IT | Garante | GDPR | €676,000 | ↗ |
| 07 Jun 2021 | Voice Integrate Nordic ABVoice Integrate Nordic AB exposed audio files of recorded calls to 1177 Vårdguiden on the internet, including personal data. IMY found that the company failed to implement adequate safeguards under Article 32 GDPR and imposed a fine of SEK 650,000. | SE | IMY | GDPR | €64,643 | ↗ |
| 11 May 2018 | Česká republika – Ministerstvo vnitraThe Ministry of the Interior was fined by UOOU for processing sensitive personal data, including DNA profiles, without explicit consent. The authority found this to be a breach of data protection law. | CZ | UOOU | GDPR | €25,487 | ↗ |
| 12 Oct 2023 | SOCIETE EDITANT DES CHAINES ET DISTRIBUANT DES OFFRES DE TELEVISION PAYANTESCNIL imposed a fine of EUR 600,000 on SOCIETE EDITANT DES CHAINES ET DISTRIBUANT DES OFFRES DE TELEVISION PAYANTES. The case concerns a confirmed regulatory breach, with no further details provided in the record. | FR | CNIL | GDPR | €600,000 | ↗ |
| 10 Jun 2020 | UniCredit S.p.A.UniCredit S.p.A. was fined by Garante EUR 600,000 for a data breach. The incident involved unauthorized access to personal data of about 762,000 individuals after an intrusion using credentials of employees from an external partner. | IT | Garante | GDPR | €600,000 | ↗ |
| 03 Aug 2022 | SOCIETE SPECIALISEE DANS LE SECTEUR DE L'HOTELLERIECNIL imposed a fine of 600,000 EUR on SOCIETE SPECIALISEE DANS LE SECTEUR DE L'HOTELLERIE. The case concerns a breach of rules supervised by the French data protection authority. | FR | CNIL | GDPR | €600,000 | ↗ |
| 24 Nov 2022 | SOCIETE FOURNISSANT DE l'ELECTRICITE, DU GAZ ET DES SERVICESCNIL imposed a fine of 600,000 EUR on SOCIETE FOURNISSANT DE l'ELECTRICITE, DU GAZ ET DES SERVICES. The available record indicates an administrative penalty issued by the French data protection authority. | FR | CNIL | GDPR | €600,000 | ↗ |