BULLETIN №083Last updated · 08 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.6%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 11 Apr 2023 | SOCIEDAD VASCONGADA DE PUBLICACIONES, S.A.The entity published a video containing personal data of 56 women registered as victims of gender-based violence. AEPD found that this breached the data minimization principle. | ES | AEPD | GDPR | €150,000 | ↗ |
| 04 Nov 2019 | Coöperatie VGZ U.A.The Autoriteit Persoonsgegevens imposed a EUR 150,000 penalty on Coöperatie VGZ U.A. for failing to implement appropriate technical measures to protect personal data from unauthorized access. The authority found a breach of data protection law. | NL | AP | GDPR | €150,000 | ↗ |
| 01 Jan 2025 | RaiItaly’s data protection authority fined Rai EUR 150,000 over a Report broadcast on 8 December 2024 that disclosed a private conversation. The case concerns unlawful processing of personal data in a television report. | IT | Garante per la protezione dei dati personali | GDPR | €150,000 | ↗ |
| 04 Mar 2021 | Anonymizováno (ÚOOÚ UOOU-02022/20-24)The entity was fined for unauthorized publication of personal data of thirty individuals on a website. The authority found a breach of the basic principles of personal data processing under GDPR. | CZ | UOOU | GDPR | €5,724 | ↗ |
| 11 Jan 2024 | DIGI SPAIN TELECOM, S.L.DIGI SPAIN TELECOM, S.L. was fined by the AEPD EUR 150,000 for processing personal data without proper authorization. The case involved a fraudulent contract created using the complainant’s identity, and the authority found that the company did not adequately verify the identity of the person entering into the contract. | ES | AEPD | GDPR | €150,000 | ↗ |
| 16 Sept 2021 | Università Commerciale “Luigi Bocconi” di MilanoUniversità Commerciale “Luigi Bocconi” di Milano was fined EUR 150,000 by the Garante for data protection breaches during remote exams. The authority found an insufficient legal basis, inadequate transparency, and weak security measures for transfers of data to the USA. | IT | Garante | GDPR | €150,000 | ↗ |
| 09 Aug 2013 | General Secretariat for Information SystemsThe General Secretariat for Information Systems was fined EUR 150,000 by the HDPA for failing to implement appropriate security measures. The breach led to unauthorized processing of Greek taxpayers’ personal tax data from 2000 to 2012. | GR | HDPA | GDPR | €150,000 | ↗ |
| 09 Oct 2018 | OTEThe Hellenic Data Protection Authority imposed a fine of EUR 150,000 on OTE. The case concerned unsolicited promotional calls made to subscribers who had previously opted out of such contact. | GR | HDPA | ePrivacy | €150,000 | ↗ |
| 08 Jun 2023 | SOCIÉTÉ DE VOYANCECNIL imposed a fine of EUR 150,000 on SOCIÉTÉ DE VOYANCE. The case concerns a regulatory breach, with no further details provided on the specific nature of the violation. | FR | CNIL | GDPR | €150,000 | ↗ |
| 11 Sept 2024 | Universitetet i AgderThe Norwegian DPA, Datatilsynet, fined the University of Agder 150,000 NOK for failing to implement adequate measures to protect personal data in Microsoft Teams. The incident exposed sensitive information relating to around 16,000 individuals. | NO | Datatilsynet | GDPR | €12,566 | ↗ |
| 16 Jan 2024 | International Card Services B.V.International Card Services B.V. was fined by the Dutch AP in the amount of EUR 150,000. The company failed to carry out a Data Protection Impact Assessment (DPIA) before implementing a customer identification and verification process, in breach of Article 35 GDPR. | NL | AP | GDPR | €150,000 | ↗ |
| 22 Feb 2024 | Sigma s.r.l.Sigma s.r.l. was fined EUR 150,000 by the Garante for unauthorized activation of paid services and devices using customer data without consent. The authority found that the company’s conduct breached GDPR rules on personal data processing. | IT | Garante | GDPR | €150,000 | ↗ |
| 22 Jun 2021 | VirksomhetenThe Norwegian DPA fined Virksomheten NOK 150,000 for accessing a former employee’s email account without a legal basis and for failing to close the account. The authority found breaches of GDPR rules on information duties, data deletion, and handling objections. | NO | Datatilsynet | GDPR | €14,678 | ↗ |
| 26 Sept 2024 | SOCIETE AYANT POUR ACTIVITE LE DEVELOPPEMENT ET LA FOURNITURE DE SERVICES INFORMATIQUES ET NUMERIQUESCNIL imposed an administrative fine of EUR 150,000 on SOCIETE AYANT POUR ACTIVITE LE DEVELOPPEMENT ET LA FOURNITURE DE SERVICES INFORMATIQUES ET NUMERIQUES. The decision was issued on 26 September 2024. | FR | CNIL | GDPR | €150,000 | ↗ |
| 09 Oct 2018 | CosmoteCosmote was fined EUR 150,000 by the HDPA for making unsolicited promotional calls to subscribers who had opted out of such contact. The authority found that this conduct breached privacy and personal data protection rules. | GR | HDPA | ePrivacy | €150,000 | ↗ |
| 01 Nov 2018 | UWVThe Dutch Data Protection Authority imposed a penalty on UWV for failing to implement multi-factor authentication in its employer portal. The authority found this breached Article 32 GDPR on appropriate data security measures. | NL | AP | GDPR | €150,000 | ↗ |
| 04 Aug 2020 | PrivatBo A.M.B.A. af 1993PrivatBo was reported to the police, and Datatilsynet recommended a fine of 150,000 DKK for inadequate data security measures. The incident led to the unintended disclosure of tenants' confidential information on USB drives. | DK | Datatilsynet | GDPR | €20,145 | ↗ |
| 06 Mar 2024 | Sectorul 1 al Municipiului BucureștiSectorul 1 of Bucharest was fined 159,000 RON by ANSPDCP for failing to comply with a remediation measure. The authority had required the requested information to be provided within 10 days, but the obligation was not met. | RO | ANSPDCP | GDPR | €31,988 | ↗ |
| 21 Jun 2021 | DKN.5131.3.2021StatusprawomocnaTytuUODO imposed an administrative fine of PLN 159,176 on an insurance company. The authority found that the company failed to notify the President of UODO of a personal data breach within the required timeframe. | PL | UODO | GDPR | €35,116 | ↗ |
| 30 Mar 2026 | Energy Prices Direct LimitedThe ICO fined Energy Prices Direct Limited, an energy switching services provider, for breaches of the PECR. The company obtained data from public sources and list providers, but failed to screen it against the TPS/CTPS registers before making marketing calls. | GB | ICO | ePrivacy | €184,000 | ↗ |