BULLETIN №083Last updated · 09 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.1%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 23 Feb 2023 | Okmánymásolás és fényképek készítése és közzététele munkahelyenThe authority imposed a fine for copying applicants’ identity documents and for failing to provide adequate information to data subjects during the recruitment process. The case concerned breaches of information duties and personal data processing rules in the workplace. | HU | NAIH | GDPR | €524 | ↗ |
| 01 Jun 2023 | NH Italia S.p.A.NH Italia S.p.A. was fined EUR 200,000 by the Garante for failing to appoint specific data processors responsible for the installation and maintenance of video surveillance systems. The authority found this breached the GDPR principles of lawful, fair, and transparent processing of personal data. | IT | Garante | GDPR | €200,000 | ↗ |
| 21 Sept 2023 | Cover Appliance LtdCover Appliance Ltd made 511,499 marketing calls to individuals in breach of regulation 21 of PECR. The ICO imposed a fine of 200,000 GBP and issued an enforcement notice. | GB | ICO | ePrivacy | €230,000 | ↗ |
| 02 Feb 2023 | VODAFONE ESPAÑA, S.A.U.Vodafone España was fined by the AEPD for changing a customer's contract ownership and activating services without consent. The authority found a breach of Article 6(1) GDPR. | ES | AEPD | GDPR | €200,000 | ↗ |
| 26 Apr 2023 | Regionstyrelsen i Region SkåneRegionstyrelsen i Region Skåne was fined by IMY for storing unencrypted sensitive patient data on a USB drive that was lost. The authority found this to be a breach of Article 32 GDPR, which requires appropriate technical and organisational security measures. | SE | IMY | GDPR | €17,566 | ↗ |
| 16 Oct 2019 | Dane anonimowe (S. Sp. z o.o. z siedzibą w P., karę pieniężną w kwocie 201 559,50 PLN)UODO imposed a fine of PLN 201,559.50 on S. Sp. z o.o. for failing to implement appropriate technical and organizational measures. The authority also found that personal data were processed without a lawful basis, which led to the sanction. | PL | UODO | GDPR | €46,923 | ↗ |
| 01 Jan 2025 | Εθνική Τράπεζα της Ελλάδος Α.Ε.The data protection authority imposed a EUR 220,000 fine on Εθνική Τράπεζα της Ελλάδος Α.Ε. for a GDPR violation. The case concerned deficiencies in personal data protection and compliance with GDPR requirements. | GR | Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα | GDPR | €220,000 | ↗ |
| 01 Jan 2024 | GESTERNOVA, S.A.GESTERNOVA, S.A. was fined by the AEPD in the amount of 220,000 EUR for processing personal data without a valid legal basis. The authority also found that the company failed to provide the required information to the data subject, in breach of GDPR Articles 6(1), 13, and 14. | ES | AEPD | GDPR | €220,000 | ↗ |
| 26 Apr 2023 | CARTONAJES BAÑERES, S.A.CARTONAJES BAÑERES, S.A. was fined by the AEPD 220,000 EUR for processing biometric data without the required data protection impact assessment. The authority also found a failure to comply with data subjects’ access rights. | ES | AEPD | GDPR | €220,000 | ↗ |
| 21 Feb 2013 | Elettrodomestici Parise sncElettrodomestici Parise snc was fined 222,000 EUR by the Italian Garante. The company improperly registered numerous phone cards to unaware third parties and then sold them to phone centers, breaching data protection rules. | IT | Garante | GDPR | €222,000 | ↗ |
| 12 May 2021 | xy d.o.o.The company xy d.o.o. was fined by AZOP for failing to implement appropriate technical security measures. This resulted in unauthorized processing of personal data of 28,085 data subjects, indicating a data protection compliance failure. | HR | AZOP | GDPR | €30,553 | ↗ |
| 05 Apr 2018 | I Tel s.r.l.I Tel s.r.l. was fined EUR 230,000 by the Italian data protection authority, Garante. The case concerned the registration of phone cards to 23 individuals without their consent, in breach of data protection rules. | IT | Garante | GDPR | €230,000 | ↗ |
| 14 Apr 2023 | Green Network S.p.a.Green Network S.p.a. was fined by the Garante for illegal telemarketing practices in the energy sector. The authority found a breach of data protection principles. | IT | Garante | GDPR | €237,000 | ↗ |
| 24 Jun 2010 | Enterprise Group s.r.l.Enterprise Group s.r.l. was fined EUR 238,000 by the Garante. The authority found that the company failed to provide timely information to data subjects and sent unsolicited marketing communications without prior consent. | IT | Garante | GDPR | €238,000 | ↗ |
| 29 Apr 2024 | Dane anonimowe (A. Sp. k. z siedzibą w T.)UODO imposed a PLN 238,345 administrative fine on A. Sp. k. for failing to implement appropriate technical and organizational measures proportionate to the risk of data processing, including the use of external storage media. The authority also found a lack of regular testing, measurement, and evaluation of the effectiveness of the security measures in place. | PL | UODO | GDPR | €55,103 | ↗ |
| 27 Apr 2023 | Ama S.p.a.Ama S.p.a. was fined €239,000 by the Garante for the unlawful processing and dissemination of personal health data concerning women who had terminated pregnancies. The identities were displayed on crosses at a cemetery, resulting in an unlawful disclosure of sensitive data. | IT | Garante | GDPR | €239,000 | ↗ |
| 20 Oct 2023 | Outsource Strategies LtdOutsource Strategies Ltd made 1,346,503 unwanted marketing calls between 11 February 2021 and 22 March 2022 to numbers registered with the TPS. The ICO received 74 complaints, including reports of repeated calls despite requests to stop and aggressive caller behaviour. | GB | ICO | GDPR | €275,000 | ↗ |
| 05 Dec 2024 | SOCIETE DEVELOPPANT ET COMMERCIALISANT UNE EXTENSION POUR NAVIGATEURThe CNIL imposed an administrative fine of EUR 240,000 on SOCIETE DEVELOPPANT ET COMMERCIALISANT UNE EXTENSION POUR NAVIGATEUR and issued an injunction. The case concerns identified regulatory breaches. | FR | CNIL | GDPR | €240,000 | ↗ |
| 27 Apr 2023 | Benetton Group S.r.l.Benetton Group S.r.l. was fined €240,000 by the Italian data protection authority, Garante. The authority found violations in the processing of personal data for marketing and profiling purposes, including the retention of former customers’ data for more than 10 years without proper justification. | IT | Garante | GDPR | €240,000 | ↗ |
| 05 Dec 2024 | KASPRThe CNIL imposed an administrative fine of €240,000 on KASPR on 5 December 2024. The case concerned data scraping and multiple GDPR breaches, including lack of lawful basis, poor transparency, excessive retention, and failure to respect access rights. | FR | CNIL | GDPR | €240,000 | ↗ |