BULLETIN №084Last updated · 12 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 27 Mar 2025 | Comune di PolinoComune di Polino was fined by the Garante for breaches of transparency and information obligations in data processing under GDPR Articles 6, 12, 13, and 14. The case concerned insufficient information provided to data subjects about how their personal data was processed. | IT | Garante | GDPR | €2,500 | ↗ |
| 27 Mar 2025 | Comune di MilazzoThe Garante fined the Comune di Milazzo €3,600 for failing to provide adequate data protection information on its website. The authority found a breach of GDPR principles of lawfulness, fairness, and transparency. | IT | Garante | GDPR | €3,600 | ↗ |
| 27 Mar 2025 | AFK Letters Co LtdBetween January and September 2023, AFK Letters Co Ltd made 95,277 spam calls, leading to multiple complaints to the ICO and TPS. The company did not provide evidence that the called numbers had consented to receiving calls. The ICO imposed a £90,000 fine. | GB | ICO | GDPR | €108,000 | ↗ |
| 27 Mar 2025 | Provvedimento del 27 marzo 2025 [10140216]The Garante fined Powerfit, Soleo, and Zero Due Villa for sending promotional SMS messages without the recipients’ consent. The messages also did not provide an opt-out mechanism, which breached GDPR requirements. | IT | Garante | GDPR | €6,000 | ↗ |
| 27 Mar 2025 | Corriere del Giorno 1947 Media Group Soc. Coop. ArlThe Garante imposed a fine of 6,000 EUR on Corriere del Giorno 1947 Media Group Soc. Coop. Arl for violations related to the right to be forgotten. The authority found that certain articles were no longer relevant and were not in the public interest. | IT | Garante | GDPR | €6,000 | ↗ |
| 27 Mar 2025 | Comune di Palma di MontechiaroThe Municipality of Comune di Palma di Montechiaro was fined EUR 3,000 by the Italian data protection authority, Garante. The sanction concerned the failure to communicate the contact details of its Data Protection Officer to the authority, as required by Article 37 GDPR. | IT | Garante | GDPR | €3,000 | ↗ |
| 27 Mar 2025 | SOCIETE DE CONSEILS POUR LES AFFAIRES ET AUTRES CONSEILS DE GESTION (procédure simplifiée)The CNIL imposed an administrative fine of EUR 6,000 on SOCIETE DE CONSEILS POUR LES AFFAIRES ET AUTRES CONSEILS DE GESTION. The case was handled under a simplified procedure. | FR | CNIL | GDPR | €6,000 | ↗ |
| 27 Mar 2025 | Istituto di Istruzione Superiore “P. 96012510796The Garante imposed a fine on an educational institution for breaches of GDPR Articles 5, 6, and 9 in connection with data processing activities. The case concerned deficiencies in the lawful basis and principles of processing, including special-category data. | IT | Garante | GDPR | €4,000 | ↗ |
| 30 Mar 2025 | MODEL REYNA, C.B.MODEL REYNA, C.B. was fined by the AEPD EUR 3,000 for failing to provide access to personal data and related information. The authority found a breach of Article 58.1 of the GDPR. | ES | AEPD | GDPR | €3,000 | ↗ |
| 31 Mar 2025 | BAR EL ANDÉN M. ROJO, S.L.The entity was fined for recording audio and video in the establishment without proper informational signage. The authority considered this a breach of data protection requirements. | ES | AEPD | GDPR | €1,000 | ↗ |
| 01 Apr 2025 | Dane anonimowe (G. M. prowadzącą działalność gospodarczą pod firmą)UODO imposed an administrative fine of PLN 29,043 on the business operator. The authority found that appropriate technical and organizational measures proportionate to the risk of personal data processing were not implemented, and that their effectiveness was not regularly tested, measured, and assessed. | PL | UODO | GDPR | €6,938 | ↗ |
| 01 Apr 2025 | BitdefenderBitdefender received a GDPR fine of EUR 10,000 from the Romanian data protection authority. The sanction followed an investigation completed in April 2025 after a data breach notification, with the authority citing inadequate technical and organizational security measures. | RO | Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal | — | €10,000 | ↗ |
| 01 Apr 2025 | EL LEÓN DE EL ESPAÑOL PUBLICACIONES, S.A.The AEPD fined EL LEÓN DE EL ESPAÑOL PUBLICACIONES, S.A. 20,000 EUR for publishing unnecessary personal data in a news article. A video in the article revealed the identity of a minor, which was considered disproportionate and unnecessary for the informational purpose. | ES | AEPD | GDPR | €20,000 | ↗ |
| 01 Apr 2025 | Anonymised (IDPC 0476_001)The IDPC imposed a EUR 20,000 fine on Anonymised (IDPC 0476_001) for breaches of several GDPR provisions. The case concerned lawfulness, fairness and transparency, purpose limitation, information duties, the right to rectification, and the appointment of a data protection officer. | MT | IDPC | GDPR | €20,000 | ↗ |
| 02 Apr 2025 | BINBOX GLOBAL SERVICES S.R.L.In March 2025, Romania’s data protection authority ANSPDCP completed an investigation into BINBOX GLOBAL SERVICES S.R.L. The authority found a GDPR violation and imposed a fine of EUR 3,000. | RO | ANSPDCP | GDPR | €3,000 | ↗ |
| 03 Apr 2025 | SOCIETE DE COURTAGE EN TRAVAUX, CONSULTING EN BATIMENT ET TRAVAUX PUBLICS, ACHAT ET REVENTE DE MATERIEL, TRANSACTION IMMOBILIERE ET MAITRISE D'ŒUVRE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 10,000 and issued an injunction. The case was handled under a simplified procedure. | FR | CNIL | GDPR | €10,000 | ↗ |
| 03 Apr 2025 | Banca Transilvania S.A.Banca Transilvania S.A. was fined EUR 5,000 by ANSPDCP for processing personal data without a legal basis. The authority found a breach of the GDPR principle of lawfulness, fairness, and transparency. | RO | ANSPDCP | GDPR | €5,000 | ↗ |
| 03 Apr 2025 | SOCIETE SPECIALISEE DANS LE SECTEUR D'ACTIVITE DES SUPERETTES (procédure simplifiée)The CNIL imposed an administrative fine of EUR 5,000 on SOCIETE SPECIALISEE DANS LE SECTEUR D'ACTIVITE DES SUPERETTES and issued an injunction. The case was handled under a simplified procedure. | FR | CNIL | GDPR | €5,000 | ↗ |
| 04 Apr 2025 | Unnamed bankThe Polish data protection authority imposed a fine of EUR 928,498.06 on a bank. The authority found that the bank failed to inform customers about a personal data breach. The case concerns post-incident notification obligations. | PL | Polish Data Protection Authority | GDPR | €928,000 | ↗ |
| 04 Apr 2025 | MEDCENTER SRLMEDCENTER SRL was fined EUR 30,000 by ANSPDCP for breaching GDPR requirements. The company failed to inform affected individuals about a personal data security breach. | RO | ANSPDCP | GDPR | €30,000 | ↗ |