BULLETIN №083Last updated · 08 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.6%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 22 Feb 2024 | Italiaonline S.p.A.Italiaonline S.p.A. was fined by the Garante 100,000 EUR for conducting direct email marketing campaigns without proper consent. The authority also found inadequate information about data processing activities shared with Google LLC. | IT | Garante | GDPR | €100,000 | ↗ |
| 25 Sept 2025 | RCS MediaGroup S.p.a.RCS MediaGroup S.p.a. was fined by the Italian data protection authority, Garante, in the amount of EUR 100,000. The case concerned the publication of images of a person in a private setting without consent, which infringed privacy rights. | IT | Garante | GDPR | €100,000 | ↗ |
| 12 Jun 2023 | Piraeus Bank S.A.Piraeus Bank S.A. was fined by the HDPA in the amount of 100,000 EUR for failing to implement appropriate technical and organizational measures. The authority found that the bank did not ensure data protection by design and by default. | GR | HDPA | GDPR | €100,000 | ↗ |
| 02 Jul 2020 | Głównego Geodetę Kraju z siedzibą w Warszawie przy ul.UODO imposed a fine of PLN 100,000 on the Chief Surveyor of Poland based in Warsaw. The sanction concerned failure to provide access during an inspection to rooms, equipment and tools used for personal data processing, as well as access to personal data and information. | PL | UODO | GDPR | €22,351 | ↗ |
| 07 Jul 2021 | Nordbornholms Byggeforretning ApSNordbornholms Byggeforretning ApS was fined 100,000 DKK by Datatilsynet. The company unlawfully disclosed information about a former employee's criminal activities to customers without a legal basis. | DK | Datatilsynet | GDPR | €13,448 | ↗ |
| 28 Jan 2022 | IBERCAJA BANCO, S.A.IBERCAJA BANCO, S.A. was fined by the AEPD EUR 100,000 for unlawfully processing personal data linked to a family inheritance matter. The breach included opening a bank account for a minor without consent and disclosing personal data to third parties without authorization. | ES | AEPD | GDPR | €100,000 | ↗ |
| 06 May 2019 | ENDESA ENERGÍA XXI, S.L.U.ENDESA ENERGÍA XXI, S.L.U. was fined by the AEPD 100,000 EUR for a data protection breach. An agent mistakenly altered a contract, replacing the complainant’s data with that of a third party. | ES | AEPD | GDPR | €100,000 | ↗ |
| 17 Mar 2025 | Ministra CyfryzacjiUODO imposed an administrative fine of 100,000 PLN on the Minister of Digital Affairs. The breach concerned Article 6(1) and Article 5(1)(a) of Regulation 2016/679. | PL | UODO | GDPR | €23,887 | ↗ |
| 18 Jul 2023 | Tiscali Italia S.p.A.Tiscali Italia S.p.A. was fined EUR 100,000 by the Garante for sending promotional SMS messages to existing customers without their consent. The authority also found inadequate data retention policies and insufficient transparency in the privacy notices. | IT | Garante | GDPR | €100,000 | ↗ |
| 09 Feb 2012 | Banca popolare Sant'Angelo S.C.P.A.The bank was fined for deploying a biometric data collection system without proper notification and without complying with data protection principles. The authority found that the processing did not meet privacy compliance requirements. | IT | Garante | GDPR | €100,000 | ↗ |
| 29 Apr 2025 | Energia Verde S.p.A.Energia Verde S.p.A. was fined EUR 100,000 by the Garante for making unsolicited promotional calls without a legal basis. The authority also found that the company did not adequately respond to data subjects' requests, indicating failures in data protection compliance. | IT | Garante | GDPR | €100,000 | ↗ |
| 20 Dec 2023 | Ministra ZdrowiaThe President of the Personal Data Protection Office imposed an administrative fine of 100,000 PLN on Ministra Zdrowia. The authority found unlawful processing of personal data, including special-category data without a legal basis, and a failure to implement technical and organizational measures appropriate to the processing risk. The affected individual was also not provided with the information required under Article 33(3)(c) and (d) of the GDPR. | PL | UODO | GDPR | €23,035 | ↗ |
| 16 Jan 2024 | Skean Homes LtdSkean Homes Ltd was fined by the ICO after it was found to have instigated 614,342 unsolicited direct marketing calls between 2 March 2022 and 31 May 2022. The calls promoted energy grants for resin driveways and generated 31 complaints through the ICO and TPS reporting tools. The ICO found breaches of regulations 21 and 24 of PECR. | GB | ICO | ePrivacy | €116,000 | ↗ |
| 31 May 2024 | MEDIOS DE PREVENCIÓN EXTERNOS, S.L.MEDIOS DE PREVENCIÓN EXTERNOS, S.L. was fined by the AEPD for leaving medical documentation of police and civil guard agents in a public place. The authority found this to be a breach of data protection rules. | ES | AEPD | GDPR | €100,000 | ↗ |
| 24 Aug 2020 | Głównego Geodetę KrajuUODO imposed a fine of PLN 100,000 on the Chief Surveyor of Poland. The authority found a breach of the lawfulness principle in personal data processing due to the intentional disclosure, without a legal basis, of land and mortgage register numbers obtained from the land and building records. | PL | UODO | GDPR | €22,735 | ↗ |
| 01 Jan 2025 | STRATESYS TECHNOLOGY SOLUTIONS, S.L.STRATESYS TECHNOLOGY SOLUTIONS, S.L. was fined EUR 100,000 by the AEPD for breaching Article 5(1)(f) of the GDPR. The case concerned a failure to protect the integrity and confidentiality of personal data. | ES | AEPD | GDPR | €100,000 | ↗ |
| 18 Sept 2025 | SOCIETE EXPLOITANT UN GRAND MAGASINCNIL imposed an administrative fine of EUR 100,000 on SOCIETE EXPLOITANT UN GRAND MAGASIN. The case concerns a breach of rules supervised by CNIL. | FR | CNIL | GDPR | €100,000 | ↗ |
| 11 Dec 2018 | Anonymizováno (ÚOOÚ UOOU-00313/19-23)The supervisory authority found that the entity failed to implement adequate technical and organizational measures to secure personal data processing and did not properly inform data subjects. Personal data of loan applicants were retained longer than necessary, in breach of the GDPR. | CZ | UOOU | GDPR | €3,869 | ↗ |
| 11 Apr 2013 | PLD srlPLD srl was fined €100,000 by the Italian Garante. The company registered numerous phone cards to unaware third parties without providing the required data protection information. | IT | Garante | GDPR | €100,000 | ↗ |
| 13 May 2021 | Artemisia s.p.a.Artemisia s.p.a. was fined EUR 100,000 by the Garante for GDPR breaches in data processing. The violations concerned consent, information notices, and the handling of health data. | IT | Garante | GDPR | €100,000 | ↗ |