BULLETIN №083Last updated · 09 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.1%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 11 Jul 2022 | Anonymizováno (ÚOOÚ UOOU-04856/21-13)The entity was fined by the UOOU 250,000 CZK for sending unsolicited commercial communications by email to approximately 266,607 recipients without their consent. This conduct violated Czech rules on certain information society services. | CZ | UOOU | ePrivacy | €10,165 | ↗ |
| 09 Jan 2024 | Det Kongelige TeaterThe Danish DPA reported Det Kongelige Teater to the police and recommended a fine of 250,000 DKK. The case concerned the absence of deletion rules for customer data used for marketing, affecting about 520,000 individuals. | DK | Datatilsynet | GDPR | €33,523 | ↗ |
| 15 Mar 2012 | Ammiro Partners s.r.l.Ammiro Partners s.r.l. was fined for violations related to the processing of personal data. The authority cited failure to comply with a prior injunction and failure to respond to requests from the Garante. | IT | Garante | GDPR | €250,000 | ↗ |
| 29 Oct 2024 | Grue kommuneGrue kommune was fined 250,000 NOK by Datatilsynet after personal data was made accessible in its public journal. The authority found breaches of confidentiality requirements and GDPR rules on legal basis and security. | NO | Datatilsynet | GDPR | €21,113 | ↗ |
| 25 Mar 2019 | Taxa 4x35The Danish data protection authority recommended a fine for Taxa 4x35 for failing to delete customer data. The company retained personal data from taxi rides without a legitimate purpose, and the court ultimately imposed a fine of DKK 250,000. | DK | Datatilsynet | GDPR | €33,493 | ↗ |
| 24 Jan 2024 | CAJA RURAL DE ASTURIAS, S.C.C.CAJA RURAL DE ASTURIAS was fined by the AEPD EUR 250,000 for breaching the confidentiality and integrity principles of personal data. The incident allowed unauthorized access to personal data, indicating a failure to protect data appropriately. | ES | AEPD | GDPR | €250,000 | ↗ |
| 23 Jan 2024 | CAJA RURAL DE SALAMANCA, S.C.C.CAJA RURAL DE SALAMANCA, S.C.C. was fined by the AEPD 250,000 EUR for failing to ensure the confidentiality and integrity of personal data. The breach resulted in unauthorized access following a data security incident. | ES | AEPD | GDPR | €250,000 | ↗ |
| 26 Sept 2024 | SOCIETE PROPOSANT DES SERVICES A DISTANCE D'ART DIVINATOIRECNIL imposed an administrative fine of EUR 250,000 on SOCIETE PROPOSANT DES SERVICES A DISTANCE D'ART DIVINATOIRE. The case concerns a breach of rules supervised by CNIL. | FR | CNIL | GDPR | €250,000 | ↗ |
| 28 Aug 2025 | Green Spark Energy LtdThe ICO investigated Green Spark Energy Ltd as part of a wider operation focused on complaint trends in the energy and home improvements sector. It found that between May 2023 and May 2024 the company initiated 9,587,050 automated recorded marketing calls in breach of regulation 19 of PECR, leading to 497 complaints. The recordings used misleading claims to pressure homeowners, and some recipients believed the calls were a scam. | GB | ICO | ePrivacy | €289,000 | ↗ |
| 08 Sept 2022 | GROUPEMENT D'INTÉRÊT ÉCONOMIQUE DES GREFFES DE TRIBUNAUX DE COMMERCE DE FRANCECNIL imposed a fine of 250,000 EUR on GROUPEMENT D'INTÉRÊT ÉCONOMIQUE DES GREFFES DE TRIBUNAUX DE COMMERCE DE FRANCE. The record states that the sanction concerns a violation, but no further details are provided. | FR | CNIL | GDPR | €250,000 | ↗ |
| 18 Dec 2024 | Dane anonimowe (C. S.A. z siedzibą w D. przy ul.)UODO imposed an administrative fine of PLN 261,918 on C. S.A. for breaches of GDPR obligations. The case concerned, among others, Article 38(3), Article 30(1), and Article 35(1) and (7) of Regulation 2016/679. | PL | UODO | GDPR | €61,514 | ↗ |
| 29 Dec 2025 | SOCIETE EDITANT UNE APPLICATION MOBILECNIL imposed an administrative fine of EUR 270,000 on SOCIETE EDITANT UNE APPLICATION MOBILE. The case concerns a breach of personal data protection rules and should be considered in compliance assessments. | FR | CNIL | GDPR | €270,000 | ↗ |
| 21 Mar 2024 | LAZIOcrea S.p.a.LAZIOcrea S.p.a. was fined by the Garante for failing to implement adequate technical and organizational measures to ensure data security. The deficiencies led to unauthorized access attempts and temporary unavailability of regional services. | IT | Garante | GDPR | €271,000 | ↗ |
| 05 Aug 2021 | Anonymisé (CNPD decision-31-fr-2021)The company sent emails containing sensitive medical data to incorrect recipients. The authority also found a breach of data protection duties due to improper documentation of the incidents. | LU | CNPD | GDPR | €275,000 | ↗ |
| 08 May 2026 | Permanent TSBPermanent TSB was fined EUR 277,500 by Ireland's Data Protection Commission. The case involved fraudsters impersonating customers at a contact centre, resulting in three GDPR breaches and financial loss to three customers. | IE | Data Protection Commission | GDPR | €277,000 | ↗ |
| 01 Mar 2018 | Massimo FarinaMassimo Farina was fined EUR 280,000 by the Garante. The case concerned the use of prepaid credit cards under false names without obtaining consent, which breached data protection rules. | IT | Garante | GDPR | €280,000 | ↗ |
| 30 Nov 2023 | Dane anonimowe (V. S.A. z siedzibą w P. ul.)UODO imposed an administrative fine of PLN 282,960 on the controller for failing to report a personal data breach to the supervisory authority. The authority also found that the affected data subject was not notified of the breach. | PL | UODO | GDPR | €65,064 | ↗ |
| 08 Jun 2023 | La Rinascente S.p.A.La Rinascente S.p.A. was fined by the Garante for unauthorized access to customer data and its modification. The breach led to the issuance of a new loyalty card containing incorrect personal details. | IT | Garante | GDPR | €300,000 | ↗ |
| 20 May 2026 | KRA Consultancy LtdKRA Consultancy Ltd was fined £300,000 by the ICO for sending more than 5.5 million unsolicited direct marketing texts and fake bailiff messages. The conduct breached regulations 22 and 23 of PECR and generated over 60,000 complaints to the 7726 spam reporting service. | GB | ICO | ePrivacy | €346,000 | ↗ |
| 29 Aug 2024 | EDITEUR DE SITE WEB DANS LE DOMAINE DES TRANSPORTSEDITEUR DE SITE WEB DANS LE DOMAINE DES TRANSPORTS was fined EUR 300,000 by the CNIL. The case concerns a breach of personal data protection rules. | FR | CNIL | GDPR | €300,000 | ↗ |