BULLETIN №084Last updated · 13 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -24%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 17 Jul 2025 | Juna S.r.l.Juna S.r.l. was fined €25,000 by the Garante for making repeated unwanted and fraudulent promotional calls to individuals. The conduct breached data protection principles, including lawful and fair processing requirements. | IT | Garante | GDPR | €25,000 | ↗ |
| 17 Jul 2025 | Comune di Tocco da CasauriaComune di Tocco da Casauria was fined EUR 2,000 by the Garante for publishing personal data on its institutional website. The authority found that the processing did not comply with the principles of lawfulness, fairness, transparency, and data minimization. | IT | Garante | GDPR | €2,000 | ↗ |
| 17 Jul 2025 | Associazione Il Cavallo Rosa/ChangeTheGame ODVThe Garante fined Associazione Il Cavallo Rosa/ChangeTheGame ODV 10,000 EUR for publishing a minor’s personal data on its Facebook page without anonymization. The authority found a breach of the data subject’s rights under the GDPR. | IT | Garante | GDPR | €10,000 | ↗ |
| 17 Jul 2025 | Poliambulatorio San Liberale S.r.l.The Garante imposed a EUR 12,500 fine on Poliambulatorio San Liberale S.r.l. for failing to meet information and transparency obligations in the processing of personal data, including health data. The company also did not respond to a data access request, adding a further breach of data subject rights. | IT | Garante | GDPR | €12,500 | ↗ |
| 17 Jul 2025 | AVOCAT (procédure simplifiée)The CNIL imposed an administrative fine of 3,000 EUR on AVOCAT and issued an injunction. The case was handled under a simplified procedure. | FR | CNIL | GDPR | €3,000 | ↗ |
| 18 Jul 2025 | ***COMUNIDAD.1The entity was fined for including personal data in community meeting minutes distributed to residents and for inadequate security measures on its community website. The authority found that these failures breached Article 32 of the GDPR on processing security. | ES | AEPD | GDPR | €1,000 | ↗ |
| 18 Jul 2025 | LUXURY ANGELS, S.L.LUXURY ANGELS, S.L. was fined EUR 500 by the AEPD for sending a client a form that contained a third party’s personal data. The authority treated this as a breach of data protection principles. | ES | AEPD | GDPR | €500 | ↗ |
| 18 Jul 2025 | EUROPEAN ENERGY TRADE S.L.EUROPEAN ENERGY TRADE S.L. was fined 600 EUR by the AEPD. The company failed to provide access to data and information requested by the data protection authority, breaching Article 58.1 of the GDPR. | ES | AEPD | GDPR | €600 | ↗ |
| 18 Jul 2025 | LEIVA BUS, S.L.LEIVA BUS, S.L. was fined by the AEPD 3,000 EUR for disclosing the personal data of a claimant and a third party in a damage assessment document. The case concerned a breach of data protection rules and unauthorized disclosure of information. | ES | AEPD | GDPR | €3,000 | ↗ |
| 21 Jul 2025 | VIVLIOPOLEION TIS ESTIAS, I.D. KOLLAROU & SIA A.E.The company was fined by the HDPA 3,000 EUR for failing to implement appropriate technical and organizational measures to secure personal data. The deficiency resulted in unauthorized disclosure of personal data. | GR | HDPA | GDPR | €3,000 | ↗ |
| 21 Jul 2025 | VIVLIOPOLEION TIS ESTIAS, I.D. KOLLAROU & SIA A.E.The company was fined by the HDPA 4,000 EUR for failing to notify the data breach to the supervisory authority and the affected data subjects in a timely manner. The case indicates non-compliance with the statutory notification deadlines following a security incident. | GR | HDPA | GDPR | €4,000 | ↗ |
| 21 Jul 2025 | VIVLIOPOLEION TIS ESTIAS, I.D. KOLLAROU & SIA A.E.The company was fined by the HDPA in the amount of €2,000 for failing to build data protection into the design of its processing and for not applying privacy by default. The authority treated this as a breach of GDPR requirements on privacy by design and by default. | GR | HDPA | GDPR | €2,000 | ↗ |
| 22 Jul 2025 | KVIKU SPAIN, S.L.KVIKU SPAIN, S.L. was fined by the AEPD in the amount of EUR 4,000 for sending unsolicited messages and processing personal data without a legal basis. The authority found a breach of Article 6(1) GDPR. | ES | AEPD | GDPR | €4,000 | ↗ |
| 22 Jul 2025 | Anonimizirano (IP-RS 0609-101/2024/5)A legal entity was fined by IP-RS for a GDPR breach involving the unauthorized disclosure of personal data, including hospital treatment details, via email. The case concerned processing that failed to meet confidentiality and access-control requirements. | SI | IP-RS | GDPR | €2,000 | ↗ |
| 23 Jul 2025 | Agricola International SAAgricola International SA was fined EUR 5,000 by ANSPDCP for a data security breach. The incident was reported by the company itself, indicating an internally detected event that required compliance review. | RO | ANSPDCP | GDPR | €5,000 | ↗ |
| 23 Jul 2025 | ING Bank Śląski SAThe Polish supervisory authority imposed an administrative fine on ING Bank Śląski SA for scanning the identity documents of customers and prospective customers without properly assessing whether this was necessary under AML rules. The decision became final on 23 July 2025 and concerns breaches of Articles 5(1)(a), (b) and (c) and 6(1) of the GDPR. | PL | President of the Personal Data Protection Office | GDPR | €4,375,000 | ↗ |
| 23 Jul 2025 | Dane anonimowe (K.)UODO imposed an administrative fine of PLN 18,416,400 for processing personal data without a lawful basis. The case concerned copying and scanning customers’ identity documents without properly verifying whether this was justified by AML obligations. | PL | UODO | GDPR | €4,328,000 | ↗ |
| 24 Jul 2025 | CURENERGÍACURENERGÍA was fined by the AEPD EUR 1,000,000 for a data protection breach involving improper handling of personal data due to human error. The issue was corrected after notification. | ES | AEPD | GDPR | €1,000,000 | ↗ |
| 24 Jul 2025 | Követeléskezeléssel összefüggő jogalap nélküli adatkezelés és törlési kérelem nem teljesítéseThe authority imposed a fine for a negligent GDPR breach involving the processing of personal data without a legal basis in connection with debt collection. It also found that deletion requests from the data subject were not fulfilled. | HU | NAIH | GDPR | €25,100 | ↗ |
| 25 Jul 2025 | Anonimizirano (IP-RS 0609-34/2025/8)The legal entity did not establish a valid contract with a data processor. This breaches Article 28 GDPR, which requires processing by a processor to be governed by a contract. | SI | IP-RS | GDPR | €5,610 | ↗ |