BULLETIN №083Last updated · 08 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.6%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 27 Sept 2018 | Anonymizováno (ÚOOÚ UOOU-05291/17-44)The entity was fined for repeatedly sending commercial communications to specified electronic addresses without consent and without proper labeling. The authority found a breach of Czech rules on information society services. | CZ | UOOU | ePrivacy | €3,111 | ↗ |
| 10 Oct 2024 | WerepairUK LtdWerepairUK Ltd made 42,688 marketing calls to individuals in breach of regulation 21 of PECR. The ICO fined the company 80,000 GBP and issued an enforcement notice. | GB | ICO | ePrivacy | €95,592 | ↗ |
| 07 Mar 2025 | SENDING TRANSPORTE Y COMUNICACIÓN, S.A.SENDING TRANSPORTE Y COMUNICACIÓN, S.A. was fined EUR 80,000 by the AEPD for breaching GDPR Articles 28(2) and 28(4). The company subcontracted data processing without the required authorization. | ES | AEPD | GDPR | €80,000 | ↗ |
| 13 May 2021 | Comune di BolzanoThe Municipality of Bolzano was fined 84,000 EUR by the Garante for improper handling of employee internet navigation data. The authority found that personal data were systematically collected without adequate safeguards and in breach of data protection principles. | IT | Garante | GDPR | €84,000 | ↗ |
| 02 Sept 2024 | Prokuraturę KrajowąUODO imposed an administrative fine of 85,000 PLN on the National Prosecutor's Office for breaches of Article 6(1), Article 9(1), Article 33(1), and Article 34(1) and (2) of the GDPR. The authority also ordered notification of the affected data subjects. | PL | UODO | GDPR | €19,883 | ↗ |
| 12 Aug 2020 | TuslaThe Irish DPC fined Tusla EUR 85,000 in inquiry IN-18-11-4. The fine has been collected. | IE | DPC | GDPR | €85,000 | ↗ |
| 17 Apr 2026 | The European House - Ambrosetti S.p.A.The European House - Ambrosetti S.p.A. was fined by Garante 85,000 EUR for a data breach. The incident involved unauthorized access and exfiltration of personal and authentication data affecting an unspecified number of individuals. | IT | Garante | GDPR | €85,000 | ↗ |
| 21 May 2026 | The European House – Ambrosetti spaThe Italian data protection authority fined The European House – Ambrosetti spa EUR 85,000 for security shortcomings following a data breach affecting 61,670 people. The company notified affected individuals too late, only after intervention by the authority. | IT | Garante per la protezione dei dati personali | GDPR | €85,000 | ↗ |
| 05 Jan 2021 | Dane anonimowe (Panią M. Z. prowadzącą działalność gospodarczą pod firmą K.)The President of UODO imposed a fine of PLN 85,588 on an individual conducting business under the name K. The authority found that an order contained in an administrative decision on personal data protection had not been complied with. | PL | UODO | GDPR | €18,822 | ↗ |
| 01 Nov 2025 | Właścicielka lecznicy stomatologicznejThe owner of a dental clinic was fined 85,588 PLN by UODO for failing to notify affected patients in time after a personal data breach. The WSA and then the NSA upheld the penalty, finding that the required notices were sent too late. | PL | President of the Personal Data Protection Office (UODO) | GDPR | €20,110 | ↗ |
| 09 Dec 2020 | DKN.5131.5.2020StatusprawomocnaTytuA monetary penalty was imposed for failing to report a personal data breach to the President of UODO and for failing to notify the affected individuals. The case concerns non-compliance with breach notification obligations after a data security incident. | PL | UODO | GDPR | €19,344 | ↗ |
| 31 May 2018 | Mingardi Medical Center s.r.l.Mingardi Medical Center s.r.l. was fined by the Garante in the amount of EUR 86,000 for making unsolicited promotional calls. The conduct breached data protection rules governing telemarketing activities. | IT | Garante | GDPR | €86,000 | ↗ |
| 31 May 2018 | IDEASORRISO S.R.L.IDEASORRISO S.R.L. was fined by the Garante EUR 86,000 for making unsolicited promotional calls without the recipients’ consent. The case concerned data protection rules applicable to telemarketing activities. | IT | Garante | GDPR | €86,000 | ↗ |
| 14 Sept 2023 | GFB One s.r.l.GFB One s.r.l. was fined EUR 90,000 by the Italian Garante. The case concerned its failure to respond to requests for information relating to the unauthorized activation of SIM cards and the misuse of personal identification documents. | IT | Garante | GDPR | €90,000 | ↗ |
| 01 Jan 2023 | MASLUZ ENERGY POWER, S.L.MASLUZ ENERGY POWER, S.L. was fined EUR 90,000 by the AEPD for changing a customer's energy provider without authorization. The authority also found a failure to provide the required information, constituting breaches of GDPR Articles 13 and 6(1). | ES | AEPD | GDPR | €90,000 | ↗ |
| 22 Feb 2024 | Coop Italia Società CooperativaCoop Italia Società Cooperativa was fined by the Garante 90,000 EUR for unlawfully processing personal data for marketing purposes without proper consent. The authority found a breach of GDPR principles, including Article 5. | IT | Garante | GDPR | €90,000 | ↗ |
| 27 Mar 2025 | AFK Letters Co LtdBetween January and September 2023, AFK Letters Co Ltd made 95,277 spam calls, leading to multiple complaints to the ICO and TPS. The company did not provide evidence that the called numbers had consented to receiving calls. The ICO imposed a £90,000 fine. | GB | ICO | GDPR | €108,000 | ↗ |
| 29 Aug 2018 | Anonymizováno (ÚOOÚ UOOU-08277/18-40)The entity was fined for sending unsolicited commercial communications by electronic means without recipients' consent. This breached Czech rules on information society services. | CZ | UOOU | ePrivacy | €3,496 | ↗ |
| 23 Mar 2021 | Irish Credit Bureau DACThe Irish Data Protection Commission (DPC) fined Irish Credit Bureau DAC EUR 90,000 in inquiry IN-19-7-2. The fine has been collected. | IE | DPC | GDPR | €90,000 | ↗ |
| 09 Nov 2023 | DPG Professional Services LtdBetween 3 August 2021 and 3 August 2022, DPG made 74,119 unsolicited calls for direct marketing purposes, breaching Reg 21 of PECR. The activity resulted in 13 complaints and came to the Commissioner’s attention through an operation focused on life insurance and later life planning marketing. | GB | ICO | ePrivacy | €103,000 | ↗ |