BULLETIN №084Last updated · 12 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 19 Jun 2025 | SC Diamir SRLIn May 2025, ANSPDCP completed an investigation at SC Diamir SRL and found violations of GDPR provisions. The company received a warning and a fine of EUR 1,000. | RO | ANSPDCP | GDPR | €1,000 | ↗ |
| 23 Jun 2025 | City of Dublin Education and Training Board (CDETB)The Irish supervisory authority concluded an inquiry into City of Dublin Education and Training Board (CDETB) and found GDPR infringements linked to a personal data breach. It imposed administrative fines totaling EUR 125,000 and issued a reprimand on 23 June 2025. | IE | Data Protection Commission (Ireland) | GDPR | €125,000 | ↗ |
| 23 Jun 2025 | Vodafone Romania S.A.Vodafone Romania S.A. was fined EUR 4,000 by ANSPDCP for GDPR violations. The investigation was completed in May 2025. | RO | ANSPDCP | GDPR | €4,000 | ↗ |
| 23 Jun 2025 | City of Dublin Education and Training Board (CDETB)The Irish DPC imposed a fine of EUR 125,000 on City of Dublin Education and Training Board (CDETB) in inquiry IN-19-7-3. The fine status is collected. | IE | DPC | GDPR | €125,000 | ↗ |
| 23 Jun 2025 | Dane anonimowe (Pana A. Z., prowadzącego działalność gospodarczą pod firmą „W.” z siedzibą w T. przy ul.)The President of UODO imposed an administrative fine of PLN 18,941 on an entrepreneur operating under the name “W.”. The sanction concerned failure to provide information and failure to grant access to personal data and other information necessary for the authority to perform its duties. | PL | UODO | GDPR | €4,430 | ↗ |
| 23 Jun 2025 | Ordine delle Professioni Infermieristiche di ViterboThe Garante imposed a fine of EUR 10,000 on the Ordine delle Professioni Infermieristiche di Viterbo for breaches of data protection rules. The case concerned non-compliance with requirements governing the processing of personal data. | IT | Garante | GDPR | €10,000 | ↗ |
| 23 Jun 2025 | Società Autocooperative Trasporti Italiani S.p.A.The company was fined by the Garante for unlawfully disclosing sensitive personal data about employee absences, including the reasons for absence. The information was posted on company notice boards and sent by email to employees. | IT | Garante | GDPR | €10,000 | ↗ |
| 23 Jun 2025 | Piraeus Bank S.A.Piraeus Bank S.A. was fined by the HDPA 50,000 EUR for unlawfully transferring personal data to third parties without the data subject's consent. The authority found breaches of GDPR principles of lawfulness and accuracy. | GR | HDPA | GDPR | €50,000 | ↗ |
| 23 Jun 2025 | McDonald's Polska sp. z o.o.The President of the Personal Data Protection Office imposed an administrative fine of PLN 16,932,657 on McDonald's Polska sp. z o.o. and a separate fine on its processor. The decision of 2025-06-23 concerned inadequate processor verification, insufficient risk analysis, and failure to implement appropriate GDPR security measures. | PL | President of the Personal Data Protection Office | GDPR | €3,960,000 | ↗ |
| 23 Jun 2025 | Dane anonimowe (U.)UODO imposed a PLN 94,286 administrative fine on an anonymous entity for improperly vetting a processor before entering into a data processing agreement. The authority also found inadequate technical and organizational safeguards, insufficient testing of their effectiveness, and failure to properly involve the data protection officer in privacy matters. | PL | UODO | GDPR | €22,053 | ↗ |
| 24 Jun 2025 | I ASPIDA TOU DAVIDThe entity did not inform data subjects about the processing of their personal data. The authority treated this as a GDPR breach and imposed a monetary fine. | GR | HDPA | GDPR | €3,000 | ↗ |
| 24 Jun 2025 | BirthlinkThe UK Information Commissioner’s Office (ICO) fined Scottish charity Birthlink GBP 18,000. The case involved the destruction of about 4,800 personal records, up to 10% of which may have been irreplaceable. | GB | ICO | GDPR | €21,109 | ↗ |
| 24 Jun 2025 | I ASPIDA TOU DAVIDThe entity failed to provide the required information and to implement adequate data protection measures. HDPA imposed a fine of EUR 3,000 for breach of GDPR principles. | GR | HDPA | GDPR | €3,000 | ↗ |
| 24 Jun 2025 | PROCONO SAPROCONO SA was fined EUR 300,000 by the AEPD for a data breach. The incident exposed customer data on the internet, including names, addresses, email addresses, and possibly bank account details. | ES | AEPD | GDPR | €300,000 | ↗ |
| 24 Jun 2025 | OLXUOKiK imposed a PLN 28.4 million fine on OLX for irregularities in its ratings system that could mislead consumers. The decision was not yet final, as OLX could appeal. | PL | Urząd Ochrony Konkurencji i Konsumentów | Omnibus | €6,676,000 | ↗ |
| 24 Jun 2025 | I ASPIDA TOU DAVIDThe entity did not satisfy a minor's request to access personal data, which constitutes a breach of GDPR principles. HDPA imposed a fine of EUR 3,000. | GR | HDPA | GDPR | €3,000 | ↗ |
| 24 Jun 2025 | I ASPIDA TOU DAVIDThe HDPA imposed a EUR 1,000 fine on I ASPIDA TOU DAVID. The authority found that the entity failed to cooperate, which breaches GDPR requirements. | GR | HDPA | GDPR | €1,000 | ↗ |
| 25 Jun 2025 | Vodafone-PanafonVodafone-Panafon was fined EUR 150,000 by the HDPA for inadequate technical and organizational security measures. The authority found a violation of Article 12 of Law 3471/2006. | GR | HDPA | ePrivacy | €150,000 | ↗ |
| 25 Jun 2025 | Vodafone-PanafonVodafone-Panafon was fined by the HDPA for failing to notify a data breach in a timely manner. The authority cited a violation of Article 12 of Law L.3471/2006. | GR | HDPA | ePrivacy | €100,000 | ↗ |
| 26 Jun 2025 | SC Piramida Trade Invest SRLSC Piramida Trade Invest SRL received a fine of EUR 1,000 from ANSPDCP. The sanction concerns a breach of Article 6 GDPR, meaning personal data were processed without a valid legal basis. | RO | ANSPDCP | GDPR | €1,000 | ↗ |