BULLETIN №081Last updated · 28 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -20.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 10 Dec 2025 | University of LimerickThe Irish DPC fined University of Limerick 98,000 EUR in inquiry IN-19-7-1. The record notes the status as not confirmed. | IE | DPC | GDPR | €98,000 | ↗ |
| 17 Dec 2020 | University College DublinThe Irish DPC imposed a fine of EUR 70,000 on University College Dublin in inquiry IN-19-7-4. The fine has been collected. | IE | DPC | GDPR | €70,000 | ↗ |
| 11 Sept 2024 | Universitetet i AgderThe Norwegian DPA, Datatilsynet, fined the University of Agder 150,000 NOK for failing to implement adequate measures to protect personal data in Microsoft Teams. The incident exposed sensitive information relating to around 16,000 individuals. | NO | Datatilsynet | GDPR | €12,566 | ↗ |
| 31 Dec 2025 | UNIVERSITE (procédure simplifiée)CNIL imposed an administrative fine of EUR 20,000 on UNIVERSITE (procédure simplifiée). The case concerned a confirmed breach of rules supervised by CNIL. | FR | CNIL | GDPR | €20,000 | ↗ |
| 29 Dec 2022 | UNIVERSITE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 10,000 on UNIVERSITE (procédure simplifiée). The record indicates a regulatory breach, but no further details are provided. | FR | CNIL | GDPR | €10,000 | ↗ |
| 02 Oct 2025 | UNIVERSITE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 15,000 on UNIVERSITE (procédure simplifiée). The case concerns a breach of rules supervised by the CNIL. | FR | CNIL | GDPR | €15,000 | ↗ |
| 14 Mar 2013 | Università Telematica San Raffaele RomaUniversità Telematica San Raffaele Roma was fined by the Garante EUR 6,000 for providing inadequate data protection information through its enrollment and information request forms on its website. The case concerned a breach of Article 13 of the Italian Privacy Code. | IT | Garante | GDPR | €6,000 | ↗ |
| 16 Dec 2021 | Università Telematica Internazionale UninettunoUniversità Telematica Internazionale Uninettuno was fined EUR 1,000 by the Italian supervisory authority Garante. The authority found breaches of lawfulness, fairness, transparency, and data minimization principles. | IT | Garante | GDPR | €1,000 | ↗ |
| 18 Jul 2023 | Università Telematica E-CampusUniversità Telematica E-Campus was fined EUR 75,000 by the Garante. The authority found that the university sent promotional SMS messages without consent and failed to respond to data deletion requests. These actions breached GDPR requirements. | IT | Garante | GDPR | €75,000 | ↗ |
| 29 Jan 2026 | Università Telematica e-CampusThe Garante fined Università Telematica e-Campus EUR 50,000 for violations related to biometric data processing. The authority also found that the university failed to carry out a proper Data Protection Impact Assessment (DPIA). | IT | Garante | GDPR | €50,000 | ↗ |
| 01 Jan 2024 | UNIVERSITAS NEBRISSENSIS, S.A.UNIVERSITAS NEBRISSENSIS, S.A. was fined by the AEPD EUR 50,000 for requesting a full copy of a student's ID. The authority found that this breached GDPR data minimization principles and security requirements. | ES | AEPD | GDPR | €50,000 | ↗ |
| 18 Sept 2008 | Universitalia s.r.l.Universitalia s.r.l. was fined €6,000 by the Italian data protection authority, Garante. The authority found that the company failed to provide adequate privacy information to data subjects as required by the Italian Data Protection Code. | IT | Garante | GDPR | €6,000 | ↗ |
| 11 Sept 2025 | Università degli Studi di VeronaUniversità degli Studi di Verona was fined by the Garante €9,000 for improperly handling personal data during a research project. The authority found a breach of GDPR requirements for lawful, fair, and transparent processing. | IT | Garante | GDPR | €9,000 | ↗ |
| 11 Mar 2021 | Università degli Studi di Napoli Federico IIUniversità degli Studi di Napoli Federico II was fined by the Garante in the amount of 10,000 EUR for breaches of data protection principles. The authority found violations of lawfulness, fairness, transparency, and data minimization in the processing of personal data. | IT | Garante | GDPR | €10,000 | ↗ |
| 22 Jul 2021 | Università degli Studi di Milano-BicoccaUniversità degli Studi di Milano-Bicocca was fined EUR 10,000 by the Garante for data protection violations linked to the publication of personal data on its institutional website. The case concerned the disclosure of information on the university’s website, which breached data processing rules. | IT | Garante | GDPR | €10,000 | ↗ |
| 17 Mar 2016 | Università degli studi di FoggiaUniversità degli studi di Foggia was fined 4,000 EUR by the Garante for unlawfully disclosing health-related data to third parties. The authority found that the disclosure lacked an appropriate legal basis and breached privacy rules. | IT | Garante | GDPR | €4,000 | ↗ |
| 10 Jul 2025 | Università degli Studi di Cassino e del Lazio MeridionaleThe University of Cassino and Southern Lazio was fined €8,000 by the Garante for failing to comply with data protection rules. The case concerned improper handling of personal data requests and deficiencies in administrative procedures. | IT | Garante | GDPR | €8,000 | ↗ |
| 27 Apr 2023 | Università degli studi di Cassino e del Lazio MeridionaleThe University of Cassino and Southern Lazio was fined EUR 4,000 by the Garante for improperly disclosing a complainant’s personal data to all Italian universities. The disclosure also included data relating to criminal offenses, breaching GDPR principles of lawfulness, fairness, and transparency. | IT | Garante | GDPR | €4,000 | ↗ |
| 16 Sept 2021 | Università Commerciale “Luigi Bocconi” di MilanoUniversità Commerciale “Luigi Bocconi” di Milano was fined EUR 150,000 by the Garante for data protection breaches during remote exams. The authority found an insufficient legal basis, inadequate transparency, and weak security measures for transfers of data to the USA. | IT | Garante | GDPR | €150,000 | ↗ |
| 01 Oct 2020 | Università Campus Bio-medico di RomaThe Garante fined Università Campus Bio-medico di Roma 20,000 EUR for a data protection breach. Online medical reports were accessible to other patients, resulting in unauthorized disclosure of sensitive information. | IT | Garante | GDPR | €20,000 | ↗ |