BULLETIN №084Last updated · 12 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 04 Jun 2025 | Istituto d’Istruzione Superiore “Carlo e Nello Rosselli”The Garante imposed a EUR 4,000 fine on Istituto d’Istruzione Superiore “Carlo e Nello Rosselli” for failing to appoint a Data Protection Officer and for delaying notification of the DPO’s contact details to the authority. The authority also found that transparency obligations toward data subjects were not met. | IT | Garante | GDPR | €4,000 | ↗ |
| 05 Jun 2025 | 23andMeThe UK ICO imposed a GBP 2,310,000 fine on 23andMe for personal data protection breaches. The case concerned inadequate safeguards and processing failures that increased the risk of unauthorized access to user data. | GB | ICO | GDPR | €2,743,000 | ↗ |
| 05 Jun 2025 | SOCIETE AYANT POUR ACTIVITE PRINCIPALE L'EDITION (procédure simplifiée)CNIL imposed an administrative fine of EUR 10,000 on SOCIETE AYANT POUR ACTIVITE PRINCIPALE L'EDITION and issued an injunction. The case was handled under a simplified procedure. | FR | CNIL | GDPR | €10,000 | ↗ |
| 05 Jun 2025 | SOCIETE AYANT POUR ACTIVITE LA FABRICATION ET LE COMMERCE DE PRODUITS PHARMACEUTIQUES DESTINES AU SECTEUR ALIMENTAIRE (procédure simplifiée)The CNIL imposed an administrative fine of 5,000 EUR on the company. The decision was issued under a simplified procedure. | FR | CNIL | GDPR | €5,000 | ↗ |
| 05 Jun 2025 | SOCIETE EXERCANT UNE ACTIVITE HOSPITALIERE A BUT LUCRATIF EN MEDECINE-CHIRURGIE-OBSTETRIQUE (procédure simplifiée)The CNIL imposed an administrative fine of 5,000 EUR on SOCIETE EXERCANT UNE ACTIVITE HOSPITALIERE A BUT LUCRATIF EN MEDECINE-CHIRURGIE-OBSTETRIQUE under a simplified procedure. The decision concerns a confirmed compliance breach and was issued by the French data protection authority. | FR | CNIL | GDPR | €5,000 | ↗ |
| 09 Jun 2025 | Department of Social ProtectionThe Irish DPC imposed a fine of €550,000 on the Department of Social Protection in inquiry IN-21-7-3. The matter is currently pending appeal (TBC). | IE | DPC | GDPR | €550,000 | ↗ |
| 10 Jun 2025 | Accounting Audit SRLAccounting Audit SRL was fined by ANSPDCP for a data security breach caused by a cyber attack. The incident led to unauthorized disclosure of personal data, including identification data and financial documents, affecting a large number of data subjects, mainly employees of the company’s clients. | RO | ANSPDCP | GDPR | €10,000 | ↗ |
| 12 Jun 2025 | Krajowa Szkoła Sądownictwa i Prokuratury (KSSiP)The President of the Polish data protection authority imposed a PLN 100,000 fine on the National School of Judiciary and Public Prosecution for breaching data protection rules during a data migration. The Supreme Administrative Court upheld the decision, making the sanction final. | PL | Urząd Ochrony Danych Osobowych | GDPR | €23,425 | ↗ |
| 13 Jun 2025 | GRUPO BONATEL SLGRUPO BONATEL SL was fined by the AEPD after an incident in which its database was encrypted and a ransom was demanded to prevent public disclosure. The authority found a breach of Article 5(1)(f) GDPR on integrity and confidentiality of personal data. | ES | AEPD | GDPR | €30,000 | ↗ |
| 13 Jun 2025 | Anonymised (HDPA 21/2025)A fine of EUR 1,000 was imposed for violating the data subject’s right of access. The entity did not provide the requested video footage. | GR | HDPA | GDPR | €1,000 | ↗ |
| 13 Jun 2025 | HEP - Toplinarstvo d.o.o.HEP - Toplinarstvo d.o.o. was fined EUR 320,000 for failing to implement appropriate technical and organizational measures to protect data in its “Moj račun” application. The authority also found a lack of cooperation with the supervisory authority, including refusal to provide required information. | HR | AZOP | GDPR | €320,000 | ↗ |
| 13 Jun 2025 | Anonymised (HDPA 21/2025)A fine was imposed for breaching the principles of lawfulness, fairness, and transparency in data processing in connection with a video surveillance system. The case concerned improper processing of personal data through video monitoring. | GR | HDPA | GDPR | €2,000 | ↗ |
| 16 Jun 2025 | SC Kashto Concept SRLANSPDCP completed an investigation at SC Kashto Concept SRL and found a breach of the GDPR. The operator was fined 5,000 RON. | RO | ANSPDCP | GDPR | €995 | ↗ |
| 16 Jun 2025 | Υφυπουργείο Κοινωνικής ΠρόνοιαςThe Cypriot Data Protection Commissioner imposed an administrative fine of EUR 5,000 on Υφυπουργείο Κοινωνικής Πρόνοιας on 16 June 2025. The case concerned CCTV cameras at the ministry’s headquarters, including three cameras that recorded audio without a legal basis and without the required GDPR safeguards. | CY | Επίτροπος Προστασίας Δεδομένων Προσωπικού Χαρακτήρα | GDPR | €5,000 | ↗ |
| 17 Jun 2025 | Szpital, za naruszenie przepisów art. 5 ust. 1 lit. f) i ust. 2, art. 25 ust. 1 oraz art. 32 ust. 1 i 2 rozporządzenia 2016/679,UODO imposed an administrative fine of PLN 66,500 on the hospital. The authority found that the hospital failed to implement appropriate technical and organizational measures to secure personal data and protect data subjects' rights. It also failed to regularly test, measure, and assess the effectiveness of those safeguards. | PL | UODO | GDPR | €15,546 | ↗ |
| 18 Jun 2025 | Dincă Viorel GeorgeThe operator was fined for failing to respond to prior requests from the National Supervisory Authority for Personal Data Processing. The authority also found that a previously imposed corrective measure had not been implemented. | RO | ANSPDCP | GDPR | €200 | ↗ |
| 18 Jun 2025 | SOCIETE AYANT POUR ACTIVITE LA VENTE A DISTANCE SUR CATALOGUE GENERAL (procédure simplifiée)The CNIL imposed an administrative fine of 3,000 EUR on SOCIETE AYANT POUR ACTIVITE LA VENTE A DISTANCE SUR CATALOGUE GENERAL. The case was handled under a simplified procedure. | FR | CNIL | GDPR | €3,000 | ↗ |
| 18 Jun 2025 | SUNERIS, S.A.SUNERIS, S.A. was fined by the AEPD in the amount of 9,000 EUR for improper handling of personal data. The case involved copying a guest’s information without consent and leaving a master key card accessible, which breached data protection principles. | ES | AEPD | GDPR | €9,000 | ↗ |
| 18 Jun 2025 | Waxholms Ångfartygs AB (WÅAB)IMY fined Waxholms Ångfartygs AB SEK 75,000 for processing personal data without a lawful basis. The authority also found processing of sensitive personal data without an applicable exception, in breach of GDPR Articles 6 and 9. | SE | IMY | GDPR | €6,802 | ↗ |
| 18 Jun 2025 | Aktiebolaget Storstockholms Lokaltrafik (SL)Aktiebolaget Storstockholms Lokaltrafik (SL) was fined 75,000 SEK by IMY for processing personal data without a legal basis and special-category data without a valid exception. The authority found breaches of GDPR Articles 6 and 9. | SE | IMY | GDPR | €6,802 | ↗ |