BULLETIN №084Last updated · 12 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 08 Apr 2025 | Adatbiztonsági problémák ügyféladatbázis adatfeldolgozó általi költöztetése soránThe authority found that Ügyfél1 failed to implement appropriate security measures when processing data during the database migration. This breach of GDPR Article 32 resulted in a fine of 2,000,000 HUF. | HU | NAIH | GDPR | €4,920 | ↗ |
| 10 Apr 2025 | Tensa Art Design S.A.Tensa Art Design S.A. was fined by ANSPDCP EUR 10,000 for GDPR violations related to its website www.lensa.ro. The case concerned non-compliant processing of personal data under data protection requirements. | RO | ANSPDCP | GDPR | €10,000 | ↗ |
| 10 Apr 2025 | Ente di Patrocinio ed Assistenza per i Cittadini e l’Agricoltura (EPACA)EPACA was fined EUR 5,000 by the Italian Garante. The authority found that the organization retained personal data beyond the legally permitted period and accessed the INPS database without a valid mandate. | IT | Garante | GDPR | €5,000 | ↗ |
| 10 Apr 2025 | Yolo Group S.p.a.Yolo Group S.p.a. was fined by the Garante 30,000 EUR for a data breach involving personal and contact data of a large number of individuals. The authority found a violation of Article 33 of the GDPR, which concerns notification of personal data breaches. | IT | Garante | GDPR | €30,000 | ↗ |
| 10 Apr 2025 | Gioele MagaldiThe Garante fined Gioele Magaldi, the manager of a blog, EUR 4,000 for publishing defamatory articles. The authority found that the content contained false information and exceeded the limits of the right to report because it lacked social utility. | IT | Garante | GDPR | €4,000 | ↗ |
| 10 Apr 2025 | Undici S.r.l.s.Undici S.r.l.s. was fined 8,000 EUR by the Garante for making unsolicited telemarketing calls. The authority found that the company did not verify the lawfulness of the data used for contact, breaching GDPR requirements on consent and data processing. | IT | Garante | GDPR | €8,000 | ↗ |
| 10 Apr 2025 | Unione Montana Appennino Parma EstUnione Montana Appennino Parma Est was fined by the Italian supervisory authority, Garante, in the amount of EUR 8,000. The authority found a lack of required transparency in data processing and failure to carry out a data protection impact assessment for workplace video surveillance. | IT | Garante | GDPR | €8,000 | ↗ |
| 10 Apr 2025 | Aliseo s.r.l.Aliseo s.r.l. was fined by the Garante for operating a video surveillance system without proper notice and for monitoring employees, including audio recording. The authority found the monitoring disproportionate to the stated security purpose. | IT | Garante | GDPR | €5,000 | ↗ |
| 10 Apr 2025 | Azienda Ospedaliera Universitaria Integrata VeronaAzienda Ospedaliera Universitaria Integrata Verona was fined by the Garante for failing to adequately protect personal data. After a ransomware attack, 612 GB of data was published on the dark web, indicating serious security shortcomings. | IT | Garante | GDPR | €10,000 | ↗ |
| 10 Apr 2025 | Acea EnergiaAcea Energia was fined EUR 3,000,000 by the Garante. The authority found unauthorized telemarketing activities and insufficient protection of databases against access by unauthorized agents. | IT | Garante | GDPR | €3,000,000 | ↗ |
| 10 Apr 2025 | SOCIETE DE COMMERCE DE DETAIL D'ARTICLES DE SPORT EN MAGASIN SPECIALISE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 20,000 on SOCIETE DE COMMERCE DE DETAIL D'ARTICLES DE SPORT EN MAGASIN SPECIALISE. The case was handled under a simplified procedure. | FR | CNIL | GDPR | €20,000 | ↗ |
| 10 Apr 2025 | Luka Inc.The Italian data protection authority fined Luka Inc., the US company behind the Replika chatbot, EUR 5,000,000. The 2025-04-10 decision concerned inadequate age verification, an unlawful processing basis, and missing privacy notice information required under the GDPR. | IT | Garante per la protezione dei dati personali | GDPR | €5,000,000 | ↗ |
| 10 Apr 2025 | Provvedimento del 10 aprile 2025 [10144184]A healthcare organization was fined after an employee accessed a patient's health dossier without authorization. The case highlights a breach of data protection rules in the healthcare sector. | IT | Garante | GDPR | €18,000 | ↗ |
| 10 Apr 2025 | Agenzia Mobilità Ambiente e Territorio S.r.l.The Garante fined Agenzia Mobilità Ambiente e Territorio S.r.l. 9,000 EUR for failing to provide sufficient transparency to data subjects. The authority found a breach of the GDPR principles of lawfulness, fairness, and transparency. | IT | Garante | GDPR | €9,000 | ↗ |
| 10 Apr 2025 | Immobiliare Valdalpone S.r.l.Immobiliare Valdalpone S.r.l. was fined by the Garante 15,000 EUR for making unsolicited marketing calls without proper consent. The authority also found inadequate data protection measures. | IT | Garante | GDPR | €15,000 | ↗ |
| 10 Apr 2025 | Vogliocasa Holding & Servizi S.r.l.Vogliocasa Holding & Servizi S.r.l. was fined by the Garante EUR 5,000 for making unsolicited telemarketing calls promoting real estate brokerage services without valid consent. The company also failed to respond to the authority's information requests, which hindered the supervisory process. | IT | Garante | GDPR | €5,000 | ↗ |
| 10 Apr 2025 | Stefanelli FedericaThe Garante imposed a 45,000 EUR fine on Stefanelli Federica for processing personal data without proper consent in unauthorized call-center operations. The case also involved sensitive data, including payment method information, which could have led to unauthorized contract activations. | IT | Garante | GDPR | €45,000 | ↗ |
| 10 Apr 2025 | SOCIETE EXERCANT UNE ACTIVITE DE RESTAURATION (procédure simplifiée)The CNIL imposed an administrative fine of EUR 6,000 on SOCIETE EXERCANT UNE ACTIVITE DE RESTAURATION. The case was handled under a simplified procedure. | FR | CNIL | GDPR | €6,000 | ↗ |
| 10 Apr 2025 | Comune di Ponte nelle AlpiThe Garante fined Comune di Ponte nelle Alpi 4,000 EUR for breaches of GDPR Articles 5 and 6 and Article 2-ter of the Codice. The case concerned improper personal data processing activities. | IT | Garante | GDPR | €4,000 | ↗ |
| 10 Apr 2025 | Tensa Art Design S.A.Tensa Art Design S.A. was fined by ANSPDCP EUR 5,000 for GDPR violations related to its website www.lensa.ro. The case concerned non-compliant processing of personal data under data protection requirements. | RO | ANSPDCP | GDPR | €5,000 | ↗ |