BULLETIN №081Last updated · 27 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -20.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 15 Oct 2025 | Dane anonimowe (B. Sp. z o.o. z siedzibą w M. za naruszenie przepisu art. 33 ust. 1 rozporządzenia 2016/679)UODO imposed an administrative fine on B. Sp. z o.o. for failing to notify the President of the Personal Data Protection Office of a personal data breach without undue delay and, at the latest, within 72 hours of becoming aware of it. The case concerns the reporting obligation under Article 33(1) GDPR. | PL | UODO | GDPR | €9,519 | ↗ |
| 14 Oct 2025 | CORAL TRAVEL & TOURISM SERVICES S.R.L.The operator was fined for violating GDPR provisions. The case concerned non-compliance with personal data protection requirements. | RO | ANSPDCP | GDPR | €982 | ↗ |
| 13 Oct 2025 | BANKINTER, S.A.BANKINTER, S.A. was fined by the AEPD 400,000 EUR for failing to implement adequate technical and organizational measures to ensure data integrity and confidentiality. The deficiency resulted in unauthorized access to personal data. | ES | AEPD | GDPR | €400,000 | ↗ |
| 13 Oct 2025 | GLOBAL COAST INVESTMENTS, S.L.GLOBAL COAST INVESTMENTS, S.L. did not respond to a data access request. The AEPD found a breach of Article 15 GDPR and imposed a fine of 1,000 EUR. | ES | AEPD | GDPR | €1,000 | ↗ |
| 13 Oct 2025 | Vellea Home SRLIn September 2025, the National Supervisory Authority for Personal Data Processing completed an investigation at Vellea Home SRL and found violations of GDPR provisions. The operator was fined EUR 5,000. | RO | ANSPDCP | GDPR | €5,000 | ↗ |
| 10 Oct 2025 | Capita plc and Capita Pension Solutions LimitedThe Information Commissioner's Office imposed a £14 million fine on Capita plc and Capita Pension Solutions Limited for UK GDPR infringements linked to a March 2023 cyber security breach. The case concerned inadequate technical and organisational measures and a delayed response to security alerts. | GB | Information Commissioner's Office | GDPR | €16,074,000 | ↗ |
| 09 Oct 2025 | SOCIETE EXERCANT UNE ACTIVITE DE VENTE A DISTANCE SUR CATALOGUE GENERAL (procédure simplifiée)The CNIL imposed an administrative fine of EUR 4,000 on SOCIETE EXERCANT UNE ACTIVITE DE VENTE A DISTANCE SUR CATALOGUE GENERAL. The case was handled under a simplified procedure. | FR | CNIL | GDPR | €4,000 | ↗ |
| 09 Oct 2025 | Arienti & C. s.r.l. a socio unicoThe Garante fined Arienti & C. s.r.l. a socio unico EUR 8,000 for denying a former employee access to their email account after the employment contract ended. The authority found this breached GDPR Article 15 on the right of access to personal data. | IT | Garante | GDPR | €8,000 | ↗ |
| 09 Oct 2025 | EON ENERGIE ROMANIA S.A.ANSPDCP completed an investigation at EON ENERGIE ROMANIA S.A. and found a breach of GDPR provisions. As a result, an administrative fine of EUR 25,000 was imposed. | RO | ANSPDCP | GDPR | €25,000 | ↗ |
| 09 Oct 2025 | Ordine delle Professioni Infermieristiche di PisaOrdine delle Professioni Infermieristiche di Pisa was fined by the Garante 16,000 EUR for breaches of data protection principles. The authority cited non-compliance with lawfulness, fairness, transparency, and data minimization requirements. | IT | Garante | GDPR | €16,000 | ↗ |
| 09 Oct 2025 | AD Media S.r.l.AD Media S.r.l. was fined EUR 5,000 by the Garante for sending promotional emails without proper consent. The authority found a breach of the principles of lawfulness, fairness, and transparency in data processing. | IT | Garante | GDPR | €5,000 | ↗ |
| 09 Oct 2025 | Provvedimento del 9 ottobre 2025 [10184697]The Garante imposed a EUR 70,000 fine on a company managing a hospital for violations related to the processing of health data. The case also involved a change in the complainant's treatment path and a failure to notify the authority of a data breach. | IT | Garante | GDPR | €70,000 | ↗ |
| 09 Oct 2025 | Ordine Interprovinciale dei Tecnici Sanitari di Radiologia Medica e delle Professioni Sanitarie Tecniche della Riabilitazione e della Prevenzione di AQ - CH - PE - TEThe Garante fined Ordine Interprovinciale dei Tecnici Sanitari 6,000 EUR for keeping an online disciplinary suspension record available despite the suspension being contested. The authority found breaches of lawfulness, fairness, transparency, data minimization, and accuracy. | IT | Garante | GDPR | €6,000 | ↗ |
| 09 Oct 2025 | FT Solutions S.r.l.FT Solutions S.r.l. was fined by the Garante 5,000 EUR for processing personal data for marketing purposes without proper consent. The case involved more than 2 million records and resulted in unauthorized telemarketing activities. | IT | Garante | GDPR | €5,000 | ↗ |
| 09 Oct 2025 | Sicuritalia S.p.A.Sicuritalia S.p.A. was fined EUR 500,000 by the Italian supervisory authority Garante. The case concerned unauthorized access to a former employee's email account after employment ended, in breach of GDPR requirements. | IT | Garante | GDPR | €500,000 | ↗ |
| 07 Oct 2025 | Anonymisiert (DSB 2025-0.778.661)An individual unlawfully accessed and processed personal data from a secured hard drive without a legitimate purpose. The authority found this to be a breach of core GDPR principles, including lawfulness and purpose limitation. | AT | DSB | GDPR | €2,500 | ↗ |
| 04 Oct 2025 | OVH HISPANO, S.L.U.OVH HISPANO, S.L.U. was fined by the AEPD 120,000 EUR for a data protection breach. Confidential emails and documents of third parties were improperly shared due to inadequate data protection measures. | ES | AEPD | GDPR | €120,000 | ↗ |
| 03 Oct 2025 | INTEGRAL DE VIGILANCIA Y CONTROL, S.L.INTEGRAL DE VIGILANCIA Y CONTROL, S.L. was fined by the AEPD 5,000 EUR for sending emails to a personal email address without a proper legal basis. The authority treated this as a breach of data protection rules. | ES | AEPD | GDPR | €5,000 | ↗ |
| 02 Oct 2025 | TIGER MEDIA INC.TIGER MEDIA INC. was fined by the AEPD EUR 120,000 for processing personal data without a lawful basis. The authority also found that the company failed to appoint an EU representative, in breach of GDPR Articles 6 and 27. | ES | AEPD | GDPR | €120,000 | ↗ |
| 02 Oct 2025 | EMAGISTER SERVICIOS DE FORMACIÓN, S.L.EMAGISTER SERVICIOS DE FORMACIÓN, S.L. was fined EUR 80,000 by the AEPD for a data security incident involving unauthorized processes on its web servers. The authority found a breach of data protection principles. | ES | AEPD | GDPR | €80,000 | ↗ |