BULLETIN №083Last updated · 09 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.1%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 29 Feb 2024 | WATIUM S.L.WATIUM S.L. was fined by the Spanish Data Protection Agency (AEPD) in the amount of EUR 160,000. The case concerned the failure to provide the required information, which constitutes a breach of Article 58.1 of the GDPR. | ES | AEPD | GDPR | €160,000 | ↗ |
| 21 Dec 2011 | Edreams s.r.l.Edreams s.r.l. was fined €160,000 by the Garante for sending unsolicited commercial emails without obtaining the required consent. The case concerned breaches of data protection rules and direct marketing requirements. | IT | Garante | GDPR | €160,000 | ↗ |
| 08 Mar 2018 | Yahoo! Emea Limited oggi Oath (Emea) LimitedYahoo! Emea Limited, now Oath (Emea) Limited, was fined 160,000 EUR by the Garante. The authority found that the company failed to comply with a request to remove specific URLs containing personal information from Yahoo! Search. | IT | Garante | GDPR | €160,000 | ↗ |
| 12 Dec 2024 | Breathe Services LtdBreathe Services Ltd, a debt advice company based in Bolton, was investigated by the ICO following complaints about unsolicited calls to potentially vulnerable individuals. The ICO found that the company spoofed outbound numbers and made 4,376,037 unsolicited direct marketing calls to numbers registered with the Telephone Preference Service, generating multiple complaints. | GB | ICO | GDPR | €206,000 | ↗ |
| 03 Feb 2021 | MERCADONA S.A.MERCADONA S.A. was fined EUR 170,000 by the AEPD for failing to respond to a data access request within the required timeframe and for deleting security camera footage. The authority found that these actions breached GDPR obligations, including Articles 12 and 6. | ES | AEPD | GDPR | €170,000 | ↗ |
| 28 May 2015 | El Dom S.a.s.El Dom S.a.s. was fined EUR 174,000 by the Garante for activating 185 phone cards under the names of 58 individuals without their knowledge. The case involved a breach of data protection rules and the unauthorized use of personal identification data. | IT | Garante | GDPR | €174,000 | ↗ |
| 17 Dec 2025 | Stichting Hogeschool van Arnhem en NijmegenThe Autoriteit Persoonsgegevens imposed a fine of €175,000 on Stichting Hogeschool van Arnhem en Nijmegen for failing to implement adequate technical and organizational measures appropriate to the risk. These deficiencies resulted in a data breach. | NL | AP | GDPR | €175,000 | ↗ |
| 20 Mar 2025 | FAVORIT SPORTSKA KLADIONICA d.o.o.FAVORIT SPORTSKA KLADIONICA d.o.o. was fined by AZOP EUR 175,000 for failing to store personal data only as long as necessary and for not implementing appropriate technical safeguards. The case concerned breaches of Articles 5 and 32 of the GDPR. | HR | AZOP | GDPR | €175,000 | ↗ |
| 08 Oct 2020 | Anonymizováno (ÚOOÚ UOOU-00179/19-38)The entity was fined for retaining personal data of financial service applicants longer than necessary, failing to inform them about potential data recipients, and lacking internal data protection measures. The authority found these practices inconsistent with data protection obligations. | CZ | UOOU | GDPR | €6,459 | ↗ |
| 07 Jul 2022 | SOCIETE DE LOCATION DE VEHICULESCNIL imposed a fine of EUR 175,000 on SOCIETE DE LOCATION DE VEHICULES. The case concerned a breach of personal data protection rules. | FR | CNIL | GDPR | €175,000 | ↗ |
| 10 Oct 2023 | Hogeschool van Arnhem en Nijmegen (HAN)The Autoriteit Persoonsgegevens imposed a fine of EUR 175,000 on Hogeschool van Arnhem en Nijmegen (HAN). The authority found that the institution did not provide sufficient protection for students’ personal data. | NL | Autoriteit Persoonsgegevens | GDPR | €175,000 | ↗ |
| 27 Apr 2023 | Roma CapitaleRoma Capitale was fined EUR 176,000 by the Garante for the unlawful processing and dissemination of personal health data relating to women who had terminated pregnancies. The sensitive information was displayed on crosses at a cemetery, creating a serious data protection breach. | IT | Garante | GDPR | €176,000 | ↗ |
| 18 Jan 2018 | KRI S.p.A.KRI S.p.A. was fined by the Italian data protection authority, Garante, for failing to notify the cessation of certain personal data processing activities. The case involved geolocation data and profiling, and the required notification was not made under the Italian data protection code. | IT | Garante | GDPR | €180,000 | ↗ |
| 21 Feb 2019 | Anonymizováno (ÚOOÚ UOOU-05185/14-53)The entity was fined by UOOU for publishing information about wiretaps and telecommunications records without consent. The authority treated this as a breach of privacy and personal data protection rules. | CZ | UOOU | GDPR | €7,018 | ↗ |
| 14 May 2026 | EmiratesEmirates was fined by the Italian Garante €180,000 for breaching data protection rules. The airline required passengers with reduced mobility to complete a medical form without providing adequate information about how their data would be processed. | IT | Garante | GDPR | €180,000 | ↗ |
| 31 Mar 2016 | avv. Gioacchino GenchiAvv. Gioacchino Genchi was fined by the Italian Garante for creating a database containing personal data, including phone traffic data. The database was accessible to his collaborators, which breached data protection rules. | IT | Garante | GDPR | €192,000 | ↗ |
| 21 Sept 2023 | F12 Management LtdF12 Management Ltd made 1,346,019 marketing calls to individuals in breach of regulation 21 of PECR. The ICO imposed a £200,000 fine and issued an enforcement notice. | GB | ICO | ePrivacy | €230,000 | ↗ |
| 15 Feb 2023 | It's OK LimitedBetween 1 July 2019 and 1 June 2020, It's OK Limited made 1,752,149 unsolicited direct marketing calls to subscribers who had been registered with the TPS for at least 28 days. The company had no evidence that the recipients had not objected to receiving such calls, breaching regulation 21 of PECR. | GB | ICO | ePrivacy | €225,000 | ↗ |
| 08 Jun 2020 | Volt munkavállaló munkavégzési célú elektronikus leveleihez való hozzáféréseThe controller unlawfully denied access to the complainant's archived personal emails from 2018. It also failed to provide transparent information about the actions taken in response to the data subject's request. | HU | NAIH | GDPR | €582 | ↗ |
| 01 Jan 2024 | DIGI SPAIN TELECOM, S.L.DIGI SPAIN TELECOM, S.L. was fined by the AEPD 200,000 EUR for issuing a duplicate SIM card to a third party without the original user's consent. The incident led to unauthorized access to personal and banking data. | ES | AEPD | GDPR | €200,000 | ↗ |