BULLETIN №081Last updated · 27 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -20.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 02 Oct 2025 | RETSINNAL GROUP, S.L.U.RETSINNAL GROUP, S.L.U. was fined 1,000 EUR by the AEPD for deficiencies in its website privacy policy. The authority found that the company did not provide adequate information about the data controller, in breach of Article 13 GDPR. | ES | AEPD | GDPR | €1,000 | ↗ |
| 02 Oct 2025 | UNIVERSITE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 15,000 on UNIVERSITE (procédure simplifiée). The case concerns a breach of rules supervised by the CNIL. | FR | CNIL | GDPR | €15,000 | ↗ |
| 25 Sept 2025 | JacksonsThe ODPA fined Jacksons £65,000 after finding that the company unlawfully changed customer marketing preferences. The investigation identified anomalies in customer records and direct marketing communications made against customers’ wishes. | GG | ODPA | GDPR | €74,302 | ↗ |
| 25 Sept 2025 | Officine Serena s.r.l.Green.mec. s.r.l. did not respond to a data subject’s request for training certificates and communications related to the termination of employment. The Garante imposed a fine of 1,000 EUR on Officine Serena s.r.l., the incorporating company. | IT | Garante | GDPR | €1,000 | ↗ |
| 25 Sept 2025 | Vimar S.p.A.Vimar S.p.A. was fined EUR 15,000 by the Garante for failing to provide adequate information to a complainant and for improper account handling. The account was accessible to unauthorized individuals, indicating weaknesses in access control and safeguards. | IT | Garante | GDPR | €15,000 | ↗ |
| 25 Sept 2025 | RCS MediaGroup S.p.a.RCS MediaGroup S.p.a. was fined by the Italian data protection authority, Garante, in the amount of EUR 100,000. The case concerned the publication of images of a person in a private setting without consent, which infringed privacy rights. | IT | Garante | GDPR | €100,000 | ↗ |
| 25 Sept 2025 | Provincia Autonoma di TrentoProvincia Autonoma di Trento was fined for processing personal data without a legal basis, lacking transparency, and failing to conduct a data protection impact assessment. The authority found breaches of several GDPR provisions. | IT | Garante | GDPR | €8,000 | ↗ |
| 25 Sept 2025 | S.C. PRIMONET RO S.R.L.The company was fined for a data security breach that enabled unauthorized transactions on affected cards. The incident caused financial losses to the data subjects. | RO | ANSPDCP | GDPR | €20,000 | ↗ |
| 25 Sept 2025 | Comune di Isola del Gran Sasso d’ItaliaThe Garante fined the Comune di Isola del Gran Sasso d’Italia EUR 3,000 for unlawfully publishing personal data on its institutional website, including information related to criminal proceedings. The authority found breaches of lawfulness, fairness, transparency, and data minimization. | IT | Garante | GDPR | €3,000 | ↗ |
| 25 Sept 2025 | Comune di PazzanoThe Garante imposed a fine of 3,960 EUR on Comune di Pazzano for failing to meet data protection obligations. The case concerned, among other issues, the improper provision of the Data Protection Officer’s contact details and other GDPR requirements. | IT | Garante | GDPR | €3,960 | ↗ |
| 25 Sept 2025 | La Prima SrlLa Prima Srl was fined EUR 10,000 by the Garante for sending unsolicited emails. The authority also found that the company failed to respond to a data deletion request, in breach of the GDPR. | IT | Garante | GDPR | €10,000 | ↗ |
| 25 Sept 2025 | E-Power S.r.l.E-Power S.r.l. was fined EUR 35,000 by the Garante for making promotional calls without a valid legal basis. The authority also found that the company failed to respond to data subject rights requests, which breaches GDPR requirements. | IT | Garante | GDPR | €35,000 | ↗ |
| 25 Sept 2025 | Azienda Ospedaliero Universitaria di FerraraAzienda Ospedaliero Universitaria di Ferrara was fined EUR 20,000 by the Garante for irregularities in the handling of personal data in its health dossier system. The authority found that the organization failed to implement adequate measures to protect data privacy. | IT | Garante | GDPR | €20,000 | ↗ |
| 18 Sept 2025 | SOCIETE EXPLOITANT UN GRAND MAGASINCNIL imposed an administrative fine of EUR 100,000 on SOCIETE EXPLOITANT UN GRAND MAGASIN. The case concerns a breach of rules supervised by CNIL. | FR | CNIL | GDPR | €100,000 | ↗ |
| 18 Sept 2025 | Dr.Max SRLIn August of the current year, ANSPDCP completed an investigation at Dr.Max SRL and found a breach of GDPR provisions. As a result, the operator was fined EUR 1,000. | RO | ANSPDCP | GDPR | €1,000 | ↗ |
| 16 Sept 2025 | Bharat Singh ChandBharat Singh Chand, a self-employed lead generator, sent or instigated the sending of 966,449 direct marketing SMS messages between 3 December 2023 and 3 July 2024. The activity breached regulations 22 and 23 of PECR and generated 19,138 complaints to the 7726 spam reporting service. He was fined £200,000 and issued with an enforcement notice. | GB | ICO | ePrivacy | €231,000 | ↗ |
| 12 Sept 2025 | Dane anonimowe (Q. Sp. z o.o.)The Polish DPA (UODO) imposed an administrative fine of PLN 11,365 on Q. Sp. z o.o. The authority found a breach of Article 38(6) GDPR because the data protection officer role was performed by the company’s president. | PL | UODO | GDPR | €2,669 | ↗ |
| 12 Sept 2025 | A Düsseldorf-based personnel recruitment companyOn 2025-09-12, the LDI NRW announced a data protection fine of over 35,000 EUR against a Düsseldorf-based personnel recruitment company. The authority said the company repeatedly ignored job seekers’ requests for access and deletion and failed to respond to the supervisory authority’s inquiries. | DE | Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen | GDPR | €35,000 | ↗ |
| 11 Sept 2025 | ISV Group SrlsISV Group Srls was fined €15,000 by the Garante for sending unsolicited promotional emails without consent. The authority also found that the company failed to properly control its partner Ismax, which carried out unlawful data processing activities. | IT | Garante | GDPR | €15,000 | ↗ |
| 11 Sept 2025 | Ministero dell’Interno - Dipartimento dei Vigili del Fuoco, del Soccorso Pubblico e della Difesa CivileThe Ministry of the Interior – Department of Firefighters was fined EUR 12,000 by the Garante. The case concerned personal data processing in breach of GDPR Articles 5, 6 and 9, as well as Articles 2-ter and 2-sexies of the Italian Privacy Code. | IT | Garante | GDPR | €12,000 | ↗ |