BULLETIN №084Last updated · 12 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 29 Jan 2025 | EDA TV CONSULTING, S.L.EDA TV CONSULTING, S.L. was fined by the AEPD 5,000 EUR for requiring a copy of the DNI when exercising data protection rights. The authority found this to breach the GDPR data minimization principle. | ES | AEPD | GDPR | €5,000 | ↗ |
| 30 Jan 2025 | Guru Nanak s.r.l.s.Guru Nanak s.r.l.s. was fined by the Garante EUR 1,000 for the non-compliant installation of a video surveillance system. The cameras captured areas beyond the company’s premises, creating a privacy and data protection breach. | IT | Garante | GDPR | €1,000 | ↗ |
| 30 Jan 2025 | Azienda Unità Sanitaria locale di ModenaAzienda Unità Sanitaria locale di Modena was fined by the Garante €10,000 for processing personal data concerning health and other sensitive information without a proper legal basis. The case involved unlawful processing of special-category data, which raises heightened compliance and privacy risks. | IT | Garante | GDPR | €10,000 | ↗ |
| 30 Jan 2025 | SOCIETE DE COURTAGE EN ENERGIE (procédure simplifiée)The CNIL used a simplified procedure against SOCIETE DE COURTAGE EN ENERGIE and ordered 4,000 EUR in connection with the liquidation of an astreinte. The case concerns failure to comply with a prior obligation subject to a coercive penalty. | FR | CNIL | GDPR | €4,000 | ↗ |
| 30 Jan 2025 | Azienda Ospedaliero - Universitaria Città della Salute e della Scienza di TorinoThe Garante fined Azienda Ospedaliero - Universitaria Città della Salute e della Scienza di Torino 6,000 EUR for unlawful processing of personal data, including health data. The authority found that the processing lacked an appropriate legal basis. The case concerned sensitive data handling in the healthcare sector. | IT | Garante | GDPR | €6,000 | ↗ |
| 31 Jan 2025 | SINDICAT CATAC-CTSCSINDICAT CATAC-CTSC was fined EUR 600 by the AEPD for failing to provide the required information. The authority found a breach of Article 58(1) of the GDPR. | ES | AEPD | GDPR | €600 | ↗ |
| 31 Jan 2025 | S.P.E.E.H. HIDROELECTRICA S.AThe company was fined for a data security breach during the launch of its application. The incident resulted from a technical error and insufficient testing, which did not ensure adequate data protection. | RO | ANSPDCP | GDPR | €15,000 | ↗ |
| 01 Feb 2025 | Automobilus International S.R.L.The Romanian data protection authority fined Automobilus International S.R.L. 24,885 RON after concluding its investigation in February 2025. It found breaches of GDPR Articles 32(1) and 32(2) due to inadequate technical and organizational security measures following a personal data breach. | RO | Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal | GDPR | €5,000 | ↗ |
| 01 Feb 2025 | Orange RomaniaThe Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP) fined Orange Romania EUR 40,000 for GDPR violations. The authority found improper handling of personal data deletion requests and excessive collection of identity document copies. | RO | Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal | GDPR | €40,000 | ↗ |
| 03 Feb 2025 | IBERMUTUA, MUTUA COLABORADORA CON LA SEGURIDAD SOCIAL NUM.274IBERMUTUA was fined EUR 1,000,000 by the AEPD for a data breach. Due to a computer error, personal data, including health information, was mistakenly sent to various companies. | ES | AEPD | GDPR | €1,000,000 | ↗ |
| 03 Feb 2025 | CENTRAL SINDICAL INDEPENDIENTE Y DE FUNCIONARIOS CSI-CSIFThe labor union CSI-CSIF was fined EUR 4,000 by the AEPD for failing to adequately protect personal data during a voting process. The authority found breaches of GDPR Articles 5(1)(f) and 32 relating to security and confidentiality. | ES | AEPD | GDPR | €4,000 | ↗ |
| 03 Feb 2025 | Unicredit Bank SAANSPDCP imposed a EUR 15,000 fine on Unicredit Bank SA for security breaches linked to an application used to create user names without prior testing. The sanction also covered a client communication solution implemented without adequate pre-testing, which led to unauthorized disclosure of personal data. | RO | ANSPDCP | GDPR | €15,000 | ↗ |
| 04 Feb 2025 | Bonnier NewsThe Swedish Authority for Privacy Protection (IMY) imposed an administrative fine of SEK 13 million on Bonnier News for unlawful personal data processing. The Administrative Court in Stockholm reviewed the case and confirmed that the company lacked a lawful basis and that the sanction was proportionate. | SE | Integritetsskyddsmyndigheten | GDPR | €1,138,000 | ↗ |
| 04 Feb 2025 | V&M Contab&Management SRLANSPDCP imposed a fine of EUR 2,000 on V&M Contab&Management SRL for GDPR violations. The case concerned non-compliance with personal data protection requirements. | RO | ANSPDCP | GDPR | €2,000 | ↗ |
| 04 Feb 2025 | V&M Contab&Management SRLANSPDCP imposed a fine of EUR 8,000 on V&M Contab&Management SRL for GDPR violations. The case concerns non-compliance with personal data protection requirements, creating regulatory risk for the controller. | RO | ANSPDCP | GDPR | €8,000 | ↗ |
| 04 Feb 2025 | LÍNEAS FINANCIERAS INTERNACIONALES, S.L.The entity was fined EUR 500 by the AEPD for sending unsolicited commercial communications by email without prior consent. This conduct breached Article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €500 | ↗ |
| 05 Feb 2025 | FARMEC SAThe National Supervisory Authority for Personal Data Processing completed an investigation in December 2024 at FARMEC SA and found a GDPR violation. As a result, the company was fined EUR 5,000. | RO | ANSPDCP | GDPR | €5,000 | ↗ |
| 05 Feb 2025 | FacharztThis case concerns a confirmed fine by the Austrian Federal Administrative Court (BVwG) against Facharzt for disclosing health data in an online review. The conduct indicates a breach of personal data protection rules involving medical information. | AT | Bundesverwaltungsgericht (BVwG) | GDPR | €4,500,000 | ↗ |
| 05 Feb 2025 | RESIDENTIAL QUALITY ENJOY, S.L.The company was fined EUR 2,000 by the AEPD for requesting and processing personal data, including minors' IDs, without proper consent or information. The authority found this to be a breach of data protection principles and transparency obligations. | ES | AEPD | GDPR | €2,000 | ↗ |
| 06 Feb 2025 | ALPHA BANK ANONYMI ETAIREIAAlpha Bank was fined by the HDPA for failing to implement adequate security measures. This led to unauthorized access to the personal data of 6,176 employees after a system administrator role was not revoked following an internal transfer. | GR | HDPA | GDPR | €3,000 | ↗ |