BULLETIN №083Last updated · 09 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.1%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 24 Jun 2025 | PROCONO SAPROCONO SA was fined EUR 300,000 by the AEPD for a data breach. The incident exposed customer data on the internet, including names, addresses, email addresses, and possibly bank account details. | ES | AEPD | GDPR | €300,000 | ↗ |
| 27 Feb 2025 | Energia Pulita S.r.l.Energia Pulita S.r.l. was fined EUR 300,000 by the Garante for making unsolicited marketing calls without a valid legal basis. The authority found a breach of GDPR Article 5. | IT | Garante | GDPR | €300,000 | ↗ |
| 30 Nov 2022 | OPERATEUR DE TELECOMMUNICATION FIXECNIL imposed a fine of EUR 300,000 on OPERATEUR DE TELECOMMUNICATION FIXE and issued an injunction subject to penalty payments. The case concerns a compliance breach in the area of data protection. | FR | CNIL | GDPR | €300,000 | ↗ |
| 19 Aug 2022 | Fidesz-Magyar Polgári SzövetségFidesz-Magyar Polgári Szövetség was fined by NAIH 300,000 HUF for unlawfully processing personal data, including phone numbers, without a legal basis. The authority also found violations of the rights to erasure and access, as well as inadequate information provided during phone campaigns. | HU | NAIH | GDPR | €735 | ↗ |
| 08 Feb 2024 | Medtronic Italia S.p.a.Medtronic Italia S.p.a. was fined by the Garante in the amount of €300,000 for a data protection breach. The authority found inadequate technical and organizational measures that led to unauthorized disclosure of data. | IT | Garante | GDPR | €300,000 | ↗ |
| 23 May 2019 | Alkotmányjogi panasz elbírálása a NAIH/2019/1189/11. sz. ügyben (IV/1561/2020.)The controller did not comply with a data subject access request under the GDPR. NAIH imposed a fine of HUF 300,000 for unlawful data processing. | HU | NAIH | GDPR | €918 | ↗ |
| 18 Oct 2012 | Fastweb S.p.A.Fastweb S.p.A. was fined by the Garante in the amount of EUR 300,000 for violations related to unsolicited telemarketing calls and improper data processing. The case indicates deficiencies in marketing compliance and personal data protection controls. | IT | Garante | GDPR | €300,000 | ↗ |
| 26 Jan 2022 | Region Uppsala, personuppgiftsincidenterRegionstyrelsen i Region Uppsala was fined for sending sensitive personal data and personal identification numbers by email without encrypting the content. The authority found a breach of Article 32 GDPR because appropriate security measures were not in place. | SE | IMY | GDPR | €28,710 | ↗ |
| 14 Dec 2020 | Uppsalahem ABUppsalahem AB was fined for unlawful video surveillance in a residential building. The authority found that the company did not properly balance its surveillance interests against residents’ privacy rights under GDPR Article 6(1)(f). | SE | IMY | GDPR | €29,433 | ↗ |
| 18 Apr 2024 | H&M Hennes & MauritzH&M Hennes & Mauritz GBC AB was fined for conducting camera surveillance without a legal basis and for failing to provide required information to data subjects. The authority found breaches of GDPR Articles 6(1) and 13. | SE | IMY | GDPR | €25,779 | ↗ |
| 31 May 2024 | MAPFRE INVERSIÓN SOCIEDAD DE VALORES, S.AMAPFRE INVERSIÓN SOCIEDAD DE VALORES, S.A was fined EUR 300,000 by the AEPD. The authority found that the company carried out unauthorized investment transactions using personal data without consent, in breach of data protection rules. | ES | AEPD | GDPR | €300,000 | ↗ |
| 09 Jul 2025 | SOCIEDAD DE GESTIÓN DE ACTIVOS PROCEDENTES DE LA REESTRUCTURACIÓN BANCARIA, S.A. (SAREB)SAREB was fined €300,000 by the AEPD for breaches of GDPR Articles 5(1)(f) and 28. The case concerned data protection failures and insufficient contractual oversight of data processing activities. | ES | AEPD | GDPR | €300,000 | ↗ |
| 08 Sept 2025 | SIA "ZZ Dats"DVI imposed a fine of 300,000 EUR on SIA "ZZ Dats". The decision has been appealed. | LV | DVI | GDPR | €300,000 | ↗ |
| 28 Oct 2025 | SIA ZZ DatsThe Latvian Data State Inspectorate found that SIA ZZ Dats failed to meet GDPR Article 32 requirements for appropriate technical and organizational measures. The case involved a major personal data leak affecting nearly all Latvian municipalities, and the authority imposed an administrative fine of EUR 300,000. The company has appealed the decision. | LV | Datu valsts inspekcija | GDPR | €300,000 | ↗ |
| 07 Aug 2023 | Anonymizováno (ÚOOÚ UOOU-00414.23-30)The decision confirms a fine for a healthcare entity for failing to notify data subjects and document a personal data breach after a cyberattack. The authority found breaches of GDPR transparency and notification obligations. | CZ | UOOU | GDPR | €12,756 | ↗ |
| 31 Jan 2024 | SOCIETE AYANT POUR ACTIVITE LA COMMERCIALISATION ET GESTION DE PROGRAMMES ET CARTES DE FIDELITECNIL imposed an administrative fine of EUR 310,000 on SOCIETE AYANT POUR ACTIVITE LA COMMERCIALISATION ET GESTION DE PROGRAMMES ET CARTES DE FIDELITE. The case concerns identified breaches of rules supervised by CNIL. | FR | CNIL | GDPR | €310,000 | ↗ |
| 13 Jun 2025 | HEP - Toplinarstvo d.o.o.HEP - Toplinarstvo d.o.o. was fined EUR 320,000 for failing to implement appropriate technical and organizational measures to protect data in its “Moj račun” application. The authority also found a lack of cooperation with the supervisory authority, including refusal to provide required information. | HR | AZOP | GDPR | €320,000 | ↗ |
| 05 Apr 2018 | Broker & Broker s.r.l.Broker & Broker s.r.l. was fined EUR 340,000 by the Italian authority Garante. The case concerned the registration of numerous phone cards to third parties without their knowledge or consent, which breached data protection rules. | IT | Garante | GDPR | €340,000 | ↗ |
| 12 Dec 2024 | Wind Tre S.p.A.Wind Tre S.p.A. was fined €347,520 by the Garante for violations related to processing personal data for promotional purposes and for inadequate technical and organizational measures. The case concerned telemarketing activities and the protection of the data involved. | IT | Garante | GDPR | €347,000 | ↗ |
| 17 Oct 2023 | H&M Hennes & MauritzH&M Hennes & Mauritz GBC AB was fined for processing personal data for direct marketing without a lawful basis. The authority also found that the company failed to stop processing after objections were raised, breaching GDPR Articles 6, 12, and 21. | SE | IMY | GDPR | €30,356 | ↗ |