BULLETIN №083Last updated · 08 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.6%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 21 Mar 2018 | Ordinanza ingiunzione - 21 marzo 2018 [9004702]The Garante imposed a EUR 92,000 fine on a medical professional for processing the personal data of 23 patients without the required consent. The authority found a breach of privacy and data protection rules. | IT | Garante | GDPR | €92,000 | ↗ |
| 15 Oct 2015 | Ordinanza ingiunzione - 15 ottobre 2015 [4703503]A fine was imposed for activating 85 SIM cards in the names of 31 people without their knowledge. The conduct breached data protection rules. | IT | Garante | GDPR | €93,000 | ↗ |
| 23 Jun 2025 | Dane anonimowe (U.)UODO imposed a PLN 94,286 administrative fine on an anonymous entity for improperly vetting a processor before entering into a data processing agreement. The authority also found inadequate technical and organizational safeguards, insufficient testing of their effectiveness, and failure to properly involve the data protection officer in privacy matters. | PL | UODO | GDPR | €22,053 | ↗ |
| 24 Jan 2024 | CAJA RURAL DE GIJÓN, S.C.A.C.CAJA RURAL DE GIJÓN was fined by the AEPD 95,000 EUR for breaching data protection principles, specifically confidentiality and integrity. The incident resulted in unauthorized access to personal data and indicates a significant compliance failure. | ES | AEPD | GDPR | €95,000 | ↗ |
| 26 Mar 2026 | Eni S.p.A.Eni S.p.A. was fined 96,000 EUR by the Garante for publishing personal data on its website, including dates of birth and addresses, without proper masking. The authority found this breached GDPR principles of lawfulness, fairness, and transparency. | IT | Garante | GDPR | €96,000 | ↗ |
| 09 Nov 2017 | GSG Enterprise società cooperativa edileGSG Enterprise was fined EUR 96,000 by the Garante for using the personal data of car owners to demand payment for services that were neither performed nor requested. The case concerns unlawful processing of personal data for debt-collection style demands. | IT | Garante | GDPR | €96,000 | ↗ |
| 10 Dec 2025 | University of LimerickThe Irish DPC fined University of Limerick 98,000 EUR in inquiry IN-19-7-1. The record notes the status as not confirmed. | IE | DPC | GDPR | €98,000 | ↗ |
| 31 Jan 2024 | EDITEUR DE SITE WEB PROPOSANT AUX PARTICULIERS DE PUBLIER OU CONSULTER DES ANNONCES IMMOBILIERES ET AUTRES SERVICESCNIL imposed an administrative fine of EUR 100,000 on EDITEUR DE SITE WEB PROPOSANT AUX PARTICULIERS DE PUBLIER OU CONSULTER DES ANNONCES IMMOBILIERES ET AUTRES SERVICES. The case concerns identified breaches of rules supervised by the CNIL. | FR | CNIL | GDPR | €100,000 | ↗ |
| 16 May 2023 | UK Direct Business Solutions LimitedUK Direct Business Solutions Limited was fined by the ICO for making 410,369 unsolicited marketing calls to businesses registered with the CTPS or TPS. The calls were made between 1 March 2020 and 31 October 2021 and breached rules on telephone marketing. | GB | ICO | GDPR | €115,000 | ↗ |
| 17 Aug 2021 | BANCO BILBAO VIZCAYA ARGENTARIA, S.A.Banco Bilbao Vizcaya Argentaria, S.A. was fined by the AEPD for sending unsolicited SMS messages to the complainant's mobile phone. The company also failed to remove the number from its database after the request, which constituted a data protection breach. | ES | AEPD | GDPR | €100,000 | ↗ |
| 17 Apr 2024 | BANCO BILBAO VIZCAYA ARGENTARIA, S.A.BBVA was fined EUR 100,000 by the AEPD for processing a payment to a new account without the account holder’s explicit consent. The authority found this conduct to be a breach of GDPR Article 6. | ES | AEPD | GDPR | €100,000 | ↗ |
| 04 Mar 2020 | Fotó készítése és közzététele Facebookon hozzájárulás nélkülThe authority found unlawful processing and publication of personal data without a valid legal basis. A fine was imposed and the image had to be deleted from Facebook. | HU | NAIH | GDPR | €299 | ↗ |
| 12 Jun 2015 | ALPHA BANKThe HDPA imposed a fine of EUR 100,000 on ALPHA BANK for the unlawful provision of data from the TIRESIAS databases. The case concerned a breach of rules on the processing and disclosure of personal data. | GR | HDPA | GDPR | €100,000 | ↗ |
| 11 Apr 2024 | Facile.Energy S.r.l.Facile.Energy S.r.l. was fined EUR 100,000 by the Garante for making unsolicited promotional calls without prior consent and activating energy supplies without a request from the customer. The authority found that these practices breached GDPR rules on data protection and security measures. | IT | Garante | GDPR | €100,000 | ↗ |
| 14 May 2021 | SIA "SS"DVI imposed a fine of EUR 100,000 on SIA "SS". According to the record, the sanction was later annulled. | LV | DVI | GDPR | €100,000 | ↗ |
| 05 Oct 2017 | Regione autonoma Valle d'AostaRegione autonoma Valle d'Aosta was fined by the Garante 100,000 EUR for publishing a regional council resolution on its institutional website that contained an employee’s personal data. The document included professional evaluations and transfer details. | IT | Garante | GDPR | €100,000 | ↗ |
| 25 Jun 2025 | Vodafone-PanafonVodafone-Panafon was fined by the HDPA for failing to notify a data breach in a timely manner. The authority cited a violation of Article 12 of Law L.3471/2006. | GR | HDPA | ePrivacy | €100,000 | ↗ |
| 16 Dec 2021 | Ubi Banca S.p.a., ora Intesa Sanpaolo S.p.a.Ubi Banca S.p.a., now Intesa Sanpaolo S.p.a., was fined EUR 100,000 by the Italian Garante. The breach involved sending a letter with the phrase “credito anomalo Chieti” visible on the envelope, which could disclose the recipient’s financial information to third parties. | IT | Garante | GDPR | €100,000 | ↗ |
| 15 Dec 2022 | Altroconsumo Edizioni S.r.lAltroconsumo Edizioni S.r.l was fined EUR 100,000 by the Garante for making unsolicited promotional calls without a proper legal basis. The authority also found that the company failed to provide adequate information and to obtain free and specific consent from data subjects. | IT | Garante | GDPR | €100,000 | ↗ |
| 28 Jul 2022 | Intesa Sanpaolo S.p.a.Intesa Sanpaolo S.p.a. was fined EUR 100,000 by Garante after an employee accessed a customer's financial data without authorization. The data was then used in judicial proceedings. The authority found that the bank had not implemented adequate data protection measures. | IT | Garante | GDPR | €100,000 | ↗ |