BULLETIN №084Last updated · 12 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 26 Jun 2025 | SC Piramida Trade Invest SRLSC Piramida Trade Invest SRL was fined EUR 2,000 by ANSPDCP. The case concerned a violation of Article 21 of the GDPR, which governs the right to object to data processing. | RO | ANSPDCP | GDPR | €2,000 | ↗ |
| 27 Jun 2025 | YDAIL CONSTRUCT SRLANSPDCP completed an investigation at YDAIL CONSTRUCT SRL in June 2025 and found a violation of applicable legal provisions. As a result, the company was fined 20,000 RON. | RO | ANSPDCP | GDPR | €3,936 | ↗ |
| 01 Jul 2025 | Bolnica XBolnica X did not provide data subjects with the required information about data processing. The hospital also failed to implement adequate security measures and did not report the data breach to the supervisory authority and affected individuals within the required timeframe. | HR | AZOP | GDPR | €3,000 | ↗ |
| 01 Jul 2025 | HAMMERHOJ DESIGN, S.L.HAMMERHOJ DESIGN, S.L. was fined EUR 4,000 by the AEPD for publishing images of minors on Facebook without consent. The authority found this conduct to be in breach of Article 6(1) GDPR. | ES | AEPD | GDPR | €4,000 | ↗ |
| 02 Jul 2025 | Hrvatski ured za osiguranjeAZOP imposed a 101,000 euro fine on Hrvatski ured za osiguranje (HUO) after finding that it had not implemented adequate technical and organizational measures to protect personal data. The decision followed an investigation into a major data leak affecting about 1.2 million vehicle owners in Croatia. | HR | AZOP | GDPR | €101,000 | ↗ |
| 03 Jul 2025 | WALLAPOP, S.L.WALLAPOP, S.L. was fined by the AEPD in the amount of 5,000 EUR for using cookies without properly informing users or obtaining their consent. The authority found this conduct to be in breach of the LSSI. | ES | AEPD | ePrivacy | €5,000 | ↗ |
| 03 Jul 2025 | MEDECIN (procédure simplifiée)The CNIL imposed an administrative fine of 3,000 EUR on MEDECIN and issued an injunction. The case was handled under a simplified procedure. | FR | CNIL | GDPR | €3,000 | ↗ |
| 03 Jul 2025 | SOCIETE AYANT POUR ACTIVITE LA VENTE A DISTANCE DE MOBILIER, DECORATION ET D'EQUIPEMENTS DOMESTIQUESThe CNIL imposed an administrative fine of 600,000 EUR on a company engaged in distance selling of furniture, decoration, and household equipment. The case concerns a breach of rules supervised by the CNIL. | FR | CNIL | GDPR | €600,000 | ↗ |
| 03 Jul 2025 | BANCO INVERSIS, S.A.Banco Inversis, S.A. was fined by the AEPD in the amount of 10,000 EUR for a personal data breach. The case involved unauthorized access to personal data, which breached Article 5(1)(f) of the GDPR. | ES | AEPD | GDPR | €10,000 | ↗ |
| 04 Jul 2025 | Niepubliczny Zakład Opieki ZdrowotnejUODO imposed a PLN 32,832 administrative fine on Niepubliczny Zakład Opieki Zdrowotnej for failing to conduct a risk analysis for processing patient data during home visits. The authority also found that appropriate technical and organizational measures to secure the data had not been implemented. | PL | UODO | GDPR | €7,733 | ↗ |
| 07 Jul 2025 | Partidul Alianța pentru Unirea Românilor (AUR)Partidul Alianța pentru Unirea Românilor (AUR) was fined €10,000 for violations related to data security breaches reported by the party. The case concerned shortcomings in the protection and safeguarding of personal data. | RO | ANSPDCP | GDPR | €10,000 | ↗ |
| 07 Jul 2025 | AURThe Romanian data protection authority imposed two fines on AUR totaling EUR 25,000. The sanctions concerned unauthorized access to supporters' personal data in the AUR app and unlawful collection of personal data on campaign platforms. | RO | Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal | GDPR | €25,000 | ↗ |
| 07 Jul 2025 | Partidul Alianța pentru Unirea Românilor (AUR)Partidul Alianța pentru Unirea Românilor (AUR) was fined EUR 15,000 by ANSPDCP for violations related to data security breaches. The case concerned reported data security incidents within the political party. | RO | ANSPDCP | GDPR | €15,000 | ↗ |
| 08 Jul 2025 | Stichting Oud LemmerStichting Oud Lemmer was fined by the AP 500 EUR for processing personal data without a legal basis. The case concerned live streaming camera footage of public spaces, which breached GDPR Articles 5 and 6. | NL | AP | GDPR | €500 | ↗ |
| 08 Jul 2025 | Selgros Cash & Carry SRLIn June 2025, ANSPDCP completed an investigation at Selgros Cash & Carry SRL and found a GDPR violation. The operator was fined EUR 3,000. | RO | ANSPDCP | GDPR | €3,000 | ↗ |
| 09 Jul 2025 | KAFFA KOFFEE ORGANISATION, S.L.KAFFA KOFFEE ORGANISATION, S.L. was fined EUR 900 by the AEPD for failing to implement appropriate technical and organizational measures. The deficiency led to email addresses being visible to multiple recipients, in breach of GDPR requirements. | ES | AEPD | GDPR | €900 | ↗ |
| 09 Jul 2025 | DISTRIBUTED ENERGY ASSETS, S.L.DISTRIBUTED ENERGY ASSETS, S.L. was fined by the AEPD 5,000 EUR for obstructing the exercise of data subject rights. The breach concerned in particular the right to erasure under Article 17 of the GDPR. | ES | AEPD | GDPR | €5,000 | ↗ |
| 09 Jul 2025 | SC Tremend Software Consulting SRLSC Tremend Software Consulting SRL was fined by ANSPDCP for GDPR violations. The penalty amounted to EUR 3,000. | RO | ANSPDCP | GDPR | €3,000 | ↗ |
| 09 Jul 2025 | EDICIONES CATÓLICOS Y VIDA PÚBLICA, S.L.U.The entity was fined for using non-essential cookies without obtaining prior user consent. This conduct breached the LSSI requirements on obtaining consent before activating such tracking tools. | ES | AEPD | ePrivacy | €5,000 | ↗ |
| 09 Jul 2025 | VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD 150,000 EUR for issuing a SIM card duplicate without proper consent. The incident led to unauthorized bank transfers and involved processing personal data without a lawful basis. | ES | AEPD | GDPR | €150,000 | ↗ |