BULLETIN №084Last updated · 12 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 09 Jan 2025 | SOCIETE REALISANT DES TRAVAUX D'ISOLATION, DE RENOVATION ENERGETIQUE ET DE CHAUFFAGE (procédure simplifiée)The CNIL imposed an administrative fine of 15,000 EUR on SOCIETE REALISANT DES TRAVAUX D'ISOLATION, DE RENOVATION ENERGETIQUE ET DE CHAUFFAGE and issued an injunction. The case was handled under simplified proceedings. | FR | CNIL | GDPR | €15,000 | ↗ |
| 09 Jan 2025 | National Bank of GreeceNational Bank of Greece was fined €20,000 by the HDPA. The authority found that the bank failed to provide data subjects with timely access to their personal data, breaching GDPR Articles 15 and 12. | GR | HDPA | GDPR | €20,000 | ↗ |
| 10 Jan 2025 | CRUZ ROJA ESPAÑOLACRUZ ROJA ESPAÑOLA was fined EUR 50,000 by the AEPD for a personal data protection breach. The case involved the unauthorized disclosure of patient data in a communication about a change in embryo bank management. | ES | AEPD | GDPR | €50,000 | ↗ |
| 10 Jan 2025 | Stowarzyszenie „Maraton” z GorlicThe President of the Personal Data Protection Office imposed an administrative fine of PLN 916.71 on Stowarzyszenie „Maraton” z Gorlic. The penalty concerned failure to notify a personal data breach within the required 72-hour deadline, together with related compliance shortcomings. | PL | Prezes Urzędu Ochrony Danych Osobowych | GDPR | €215 | ↗ |
| 13 Jan 2025 | Centrul Medical Unirea S.R.L.The National Supervisory Authority for Personal Data Processing completed an investigation at Centrul Medical Unirea S.R.L. and found a breach of Article 32 of the GDPR. A fine of EUR 2,000 was imposed. | RO | ANSPDCP | GDPR | €2,000 | ↗ |
| 13 Jan 2025 | OrangeCNIL imposed a EUR 50 million fine on Orange for displaying commercial ads in email inboxes without prior user consent. The authority also found that advertising and statistical cookies continued to be read after consent had been withdrawn, in breach of the GDPR. | FR | Commission Nationale de l'Informatique et des Libertés | GDPR | €50,000,000 | ↗ |
| 13 Jan 2025 | BLEISOR SOLUTIONS, S.A.S.BLEISOR SOLUTIONS, S.A.S. was fined 600 EUR by the AEPD. The authority found that the company failed to provide access to personal data and information requested by the supervisory authority, in breach of Article 58(1) GDPR. | ES | AEPD | GDPR | €600 | ↗ |
| 16 Jan 2025 | Comune di PaternòThe Garante fined Comune di Paternò EUR 6,000 for failing to communicate the Data Protection Officer’s contact details to the Authority. The breach concerned the obligation under Article 37(7) GDPR. | IT | Garante | GDPR | €6,000 | ↗ |
| 16 Jan 2025 | CENTRE DE FORMATION A DISTANCE D'APPRENTIS (procédure simplifiée)The CNIL imposed an administrative fine of EUR 10,000 on CENTRE DE FORMATION A DISTANCE D'APPRENTIS and issued an injunction. The case was handled under a simplified procedure. | FR | CNIL | GDPR | €10,000 | ↗ |
| 16 Jan 2025 | Comune di CoriThe Garante fined Comune di Cori EUR 2,000 for violations related to the processing of personal data in connection with the issuance of the “Dedicata a te” card. The case involved electronic payment cards provided by Poste Italiane. | IT | Garante | GDPR | €2,000 | ↗ |
| 17 Jan 2025 | Dane anonimowe (X. z siedzibą w K.)The UODO imposed administrative fines on X. based in K. for breaches of Article 6(1), Article 9(1), Article 13(1) and (2), Article 25(1), and Article 32(1) and (2) of the GDPR. These breaches also resulted in violations of the principles in Article 5(1)(a) and (f) and Article 5(2) of the GDPR. | PL | UODO | GDPR | €161,000 | ↗ |
| 17 Jan 2025 | DELIVERY SOLUTIONS S.A.The company was fined for failing to implement adequate technical and organizational measures to ensure a level of security appropriate to the risk. The authority also found insufficient safeguards to ensure data confidentiality. | RO | ANSPDCP | GDPR | €2,000 | ↗ |
| 17 Jan 2025 | OLALA MNG, S.L.OLALA MNG, S.L. was fined by the AEPD EUR 1,600 for requesting excessive personal data from guests booking through a website. The authority found that asking for images of identity documents constituted a data protection breach. | ES | AEPD | GDPR | €1,600 | ↗ |
| 20 Jan 2025 | Vodafone Romania S.A.Vodafone Romania S.A. was fined EUR 15,000 by ANSPDCP for violations of GDPR provisions. The case concerns non-compliance with personal data protection requirements. | RO | ANSPDCP | GDPR | €15,000 | ↗ |
| 23 Jan 2025 | Softtehnica S.R.LIn December 2024, ANSPDCP completed an investigation at Softtehnica S.R.L. The authority found a GDPR violation and imposed a fine of EUR 5,000. | RO | ANSPDCP | GDPR | €5,000 | ↗ |
| 23 Jan 2025 | SOCIETE DE TRANSPORT ROUTIER DE MARCHANDISES (procédure simplifiée)CNIL imposed an administrative fine of 8,000 EUR on SOCIETE DE TRANSPORT ROUTIER DE MARCHANDISES. The case was handled under a simplified procedure. | FR | CNIL | GDPR | €8,000 | ↗ |
| 23 Jan 2025 | XFERA MÓVILES, S.A.XFERA MÓVILES, S.A. was fined 100,000 EUR by the AEPD for inaccuracies in data retention relating to SIM card purchasers. The authority found a breach of the GDPR data accuracy obligation. | ES | AEPD | GDPR | €100,000 | ↗ |
| 27 Jan 2025 | Orange România SAOrange România SA was fined EUR 20,000 by ANSPDCP for GDPR violations. The case concerns non-compliance with personal data protection requirements. | RO | ANSPDCP | GDPR | €20,000 | ↗ |
| 27 Jan 2025 | Orange România SAOrange România SA was fined EUR 20,000 by ANSPDCP for GDPR violations. The case concerns non-compliance with personal data protection requirements, creating regulatory risk for organizations processing data in Romania. | RO | ANSPDCP | GDPR | €20,000 | ↗ |
| 29 Jan 2025 | SINDICATO DE LA ADMON. PÚBLICA DE LA CGT EN JEREZ Y COSTA NOROESTE DE CÁDIZThe union was fined by the AEPD for failing to comply with data protection principles and for not informing individuals about the processing of their personal data. The case indicates shortcomings in transparency and GDPR compliance obligations. | ES | AEPD | GDPR | €2,000 | ↗ |