BULLETIN №083Last updated · 08 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.6%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 15 Dec 2022 | Assiteca S.p.A.Assiteca S.p.A. was fined EUR 120,000 by the Garante for violations related to the processing of personal data for marketing purposes. The authority also found inadequate responses to data subject requests. The case highlights the need for proper handling of individual rights and GDPR-compliant marketing practices. | IT | Garante | GDPR | €120,000 | ↗ |
| 04 Oct 2025 | OVH HISPANO, S.L.U.OVH HISPANO, S.L.U. was fined by the AEPD 120,000 EUR for a data protection breach. Confidential emails and documents of third parties were improperly shared due to inadequate data protection measures. | ES | AEPD | GDPR | €120,000 | ↗ |
| 16 Jan 2020 | VODAFONE ESPAÑA SAUVODAFONE ESPAÑA SAU was fined 120,000 EUR by the AEPD for unlawful processing of personal data. The case involved threatening to include a minor's data in a credit file over an alleged unpaid debt. | ES | AEPD | GDPR | €120,000 | ↗ |
| 18 Dec 2025 | Pioneer Hi-Bred Italia Sementi s.r.l.Pioneer Hi-Bred Italia Sementi s.r.l. was fined by the Garante 120,000 EUR for installing telematic devices in company vehicles to monitor employees' driving behavior. The authority found that the processing lacked proper data protection safeguards and privacy information. | IT | Garante | GDPR | €120,000 | ↗ |
| 20 Dec 2019 | Anonymizováno (ÚOOÚ UOOU-00136/19-31)The company was fined for disseminating commercial communications without a legal basis and without proper labeling. The authority found a breach of Czech rules on information society services. | CZ | UOOU | ePrivacy | €4,716 | ↗ |
| 23 Jun 2025 | City of Dublin Education and Training Board (CDETB)The Irish supervisory authority concluded an inquiry into City of Dublin Education and Training Board (CDETB) and found GDPR infringements linked to a personal data breach. It imposed administrative fines totaling EUR 125,000 and issued a reprimand on 23 June 2025. | IE | Data Protection Commission (Ireland) | GDPR | €125,000 | ↗ |
| 23 Jun 2025 | City of Dublin Education and Training Board (CDETB)The Irish DPC imposed a fine of EUR 125,000 on City of Dublin Education and Training Board (CDETB) in inquiry IN-19-7-3. The fine status is collected. | IE | DPC | GDPR | €125,000 | ↗ |
| 14 Dec 2022 | Monetise Media LimitedBetween 28 July 2020 and 28 July 2021, Monetise Media Limited sent 3,506,157 direct marketing emails and text messages. The recipients had not provided valid consent, which breached regulation 22 of PECR. | GB | ICO | ePrivacy | €145,000 | ↗ |
| 16 Mar 2023 | SOCIETE DE LOCATION DE SCOOTERS ELECTRIQUES EN LIBRE-SERVICEThe CNIL imposed a fine of EUR 125,000 on SOCIETE DE LOCATION DE SCOOTERS ELECTRIQUES EN LIBRE-SERVICE. The case concerns a confirmed breach of rules supervised by the data protection authority. | FR | CNIL | GDPR | €125,000 | ↗ |
| 18 Jun 2015 | Wind Telecomunicazioni SpaWind Telecomunicazioni Spa was fined EUR 130,000 by the Garante. The case concerned the unlawful disclosure of mobile phone numbers in the White Pages directory without proper consent. | IT | Garante | GDPR | €130,000 | ↗ |
| 02 Oct 2014 | Addressvitt s.r.l.Addressvitt s.r.l. was fined by the Garante in the amount of EUR 130,000 for processing personal data without providing adequate information or obtaining consent. The case also involved data taken from public telephone directories and used without proper authorization. | IT | Garante | GDPR | €130,000 | ↗ |
| 14 Apr 2023 | Join the Triboo LimitedBetween 1 August 2019 and 19 August 2020, Join the Triboo Limited sent a confirmed total of 107 million direct marketing messages, of which 437,324 were received by distinct individuals. On average, each person received 244 emails during the period, and the messages contained direct marketing material without valid subscriber consent. | GB | ICO | GDPR | €146,000 | ↗ |
| 08 Jun 2023 | Crown Glazing LtdThe case was part of Operation Tinago, which assessed complaint trends in the energy and home improvements sector. Crown Glazing Ltd made 503,445 unsolicited calls to TPS-registered numbers between 4 January and 11 November 2021, resulting in 37 complaints. | GB | ICO | GDPR | €150,000 | ↗ |
| 01 Jan 2013 | GOOGLE INCGoogle Inc. was fined by the AEPD EUR 130,000 for failing to provide adequate information on privacy and cookie policies on a website. The authority found a breach of the LSSI information requirements toward users. | ES | AEPD | ePrivacy | €130,000 | ↗ |
| 01 Jan 2024 | DIGI SPAIN TELECOM, S.L.DIGI SPAIN TELECOM, S.L. was fined by the AEPD 130,000 EUR for unauthorized SIM card duplication. The incident led to identity theft and fraudulent charges, and the authority found the data protection measures insufficient. | ES | AEPD | GDPR | €130,000 | ↗ |
| 18 Dec 2024 | Toyota Bank Polska S.A.The Polish supervisory authority imposed an administrative fine of EUR 132,000 on Toyota Bank Polska S.A. on 18 December 2024. The penalty concerned breaches of GDPR Articles 30, 35, and 38, including DPO independence, profiling documentation, and DPIA obligations. | PL | President of the Personal Data Protection Office (UODO) | GDPR | €132,000 | ↗ |
| 11 Jan 2021 | Dane anonimowe (M. S.A. z siedzibą w Z. przy ul.)The President of UODO imposed an administrative fine of PLN 136,437 on M. S.A. The penalty was issued because the company did not report a personal data breach to the supervisory authority without undue delay. | PL | UODO | GDPR | €30,123 | ↗ |
| 18 Apr 2023 | VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD 140,000 EUR for a data protection breach involving incorrect billing information. A customer's mobile line was charged under another person's name, indicating an error in the processing of personal data. | ES | AEPD | GDPR | €140,000 | ↗ |
| 12 Jan 2024 | Grocery Delivery E-Services UK Ltd t/a HelloFreshThe ICO fined Grocery Delivery E-Services UK Ltd t/a HelloFresh 140,000 GBP for sending 79 million spam emails and 1 million spam texts over seven months. The marketing consent was inadequate because it did not mention text messages and was bundled with an age confirmation statement that may have unfairly encouraged agreement. Customers were also not clearly told that their data would continue to be used for marketing for up to 24 months after cancelling subscriptions. | GB | ICO | GDPR | €162,000 | ↗ |
| 01 Mar 2022 | VODAFONE ESPAÑA, S.A.U.Vodafone España was fined by the AEPD for failing to adequately prevent unauthorized SIM card duplication. The incident enabled fraudulent access and transactions on a customer's accounts. | ES | AEPD | GDPR | €140,000 | ↗ |