BULLETIN №081Last updated · 28 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -20.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 30 May 2016 | UNION DISTRIBUIDORA DE EDICIONES DE ARAGON S.L.UNION DISTRIBUIDORA DE EDICIONES DE ARAGON S.L. was fined EUR 800 by the AEPD for sending unsolicited commercial emails. The authority found that the messages continued despite the recipient’s attempts to unsubscribe. | ES | AEPD | ePrivacy | €800 | ↗ |
| 09 Jun 2023 | UNIÓN DE RADIOS LIBRES Y COMUNITARIAS DE MADRIDThe entity did not comply with a data protection authority resolution concerning the right to erasure. As a result, AEPD imposed a fine for breaching Article 58.2 of the GDPR. | ES | AEPD | GDPR | €1,000 | ↗ |
| 01 Jan 2022 | Unión de Oficiales Guardia Civil ProfesionalThe entity was fined for sending a letter containing personal data without prior consent, in breach of Article 6(1) GDPR. The case concerned unauthorized processing of personal data through the dispatch of correspondence to the data subject. | ES | AEPD | GDPR | €6,000 | ↗ |
| 11 Mar 2025 | UNIÓN DE CRÉDITO PARA LA FINANC. MOB. E INMOB., CREDIFIMO, E.F.C., SAUCREDIFIMO was fined by the AEPD for unlawfully processing personal data by including an individual's data in a credit file without a lawful basis. The authority found a breach of Article 6 of the GDPR. | ES | AEPD | GDPR | €200,000 | ↗ |
| 21 Sept 2017 | Unidata s.p.a.Unidata s.p.a. was fined EUR 36,000 by the Garante for failing to implement adequate security measures for personal data processing. The authority noted, among other issues, the use of passwords shorter than eight characters, which breached data protection requirements. | IT | Garante | GDPR | €36,000 | ↗ |
| 13 May 2022 | UNIDAD EDITORIAL INFORMACIÓN GENERAL, S.L.U.The entity published an audio recording of a victim's court testimony without consent. AEPD found this to be a breach of data protection law and imposed a 50,000 EUR fine. | ES | AEPD | GDPR | €50,000 | ↗ |
| 10 Jun 2020 | UniCredit S.p.A.UniCredit S.p.A. was fined by Garante EUR 600,000 for a data breach. The incident involved unauthorized access to personal data of about 762,000 individuals after an intrusion using credentials of employees from an external partner. | IT | Garante | GDPR | €600,000 | ↗ |
| 09 May 2024 | Unicredit S.p.a.Unicredit S.p.a. was fined EUR 30,000 by the Garante for failing to respond to a personal data access request submitted by an heir. The authority found a breach of GDPR Article 15 and the Italian privacy code. | IT | Garante | GDPR | €30,000 | ↗ |
| 17 Dec 2024 | UNICREDIT CONSUMER FINANCING IFN S.A.UNICREDIT CONSUMER FINANCING IFN S.A. was fined EUR 5,000 by ANSPDCP for processing former employees’ personal data without a legal basis. The authority found breaches of legality, security, and protection against unauthorized or unlawful processing arising from operational errors. | RO | ANSPDCP | GDPR | €5,000 | ↗ |
| 03 Feb 2025 | Unicredit Bank SAANSPDCP imposed a EUR 15,000 fine on Unicredit Bank SA for security breaches linked to an application used to create user names without prior testing. The sanction also covered a client communication solution implemented without adequate pre-testing, which led to unauthorized disclosure of personal data. | RO | ANSPDCP | GDPR | €15,000 | ↗ |
| 29 May 2026 | Unicredit Bank SAUnicredit Bank SA was fined EUR 2,000 by ANSPDCP. The authority found that the bank failed to notify a personal data breach within the required 72-hour deadline. | RO | ANSPDCP | GDPR | €2,000 | ↗ |
| 29 May 2026 | Unicredit Bank SAUnicredit Bank SA was fined EUR 10,000 by ANSPDCP for violating GDPR provisions. The case concerns non-compliance with personal data protection requirements and should be considered in compliance risk assessments. | RO | ANSPDCP | GDPR | €10,000 | ↗ |
| 22 Feb 2024 | Unica s.r.l.s.Unica s.r.l.s. was fined by the Garante EUR 2,000 for using a facial recognition system to record employee attendance without a proper legal basis. The authority found that the processing of biometric data breached GDPR requirements. | IT | Garante | GDPR | €2,000 | ↗ |
| 24 Feb 2025 | UNICAJA BANCO, S.A.U.UNICAJA BANCO, S.A.U. was fined by the AEPD EUR 3,500,000 for inadequate security measures in its video surveillance system. The authority found a breach of data protection requirements. | ES | AEPD | GDPR | €3,500,000 | ↗ |
| 10 Apr 2025 | Undici S.r.l.s.Undici S.r.l.s. was fined 8,000 EUR by the Garante for making unsolicited telemarketing calls. The authority found that the company did not verify the lawfulness of the data used for contact, breaching GDPR requirements on consent and data processing. | IT | Garante | GDPR | €8,000 | ↗ |
| 10 Dec 2020 | Umeå universitetUmeå University was fined by IMY 550,000 SEK for sending sensitive personal data via unencrypted email and open networks. The authority found that this breached GDPR security requirements. | SE | IMY | GDPR | €53,713 | ↗ |
| 18 Oct 2012 | Umbra Acque S.p.a.Umbra Acque S.p.a. was fined by the Garante 10,000 EUR for breaches of data protection rules. The authority found that the company failed to designate data processing officers and did not adopt minimum security measures for its video surveillance system. | IT | Garante | GDPR | €10,000 | ↗ |
| 16 May 2023 | UK Direct Business Solutions LimitedUK Direct Business Solutions Limited was fined by the ICO for making 410,369 unsolicited marketing calls to businesses registered with the CTPS or TPS. The calls were made between 1 March 2020 and 31 October 2021 and breached rules on telephone marketing. | GB | ICO | GDPR | €115,000 | ↗ |
| 07 Jul 2021 | Uitvoeringsinstituut werknemersverzekeringen (UWV)UWV was fined by the AP for failing to ensure an adequate level of security for personal data. The deficiencies led to multiple breaches involving sensitive information of job seekers. | NL | AP | GDPR | €450,000 | ↗ |
| 21 Aug 2023 | Uipath SRLUipath SRL was fined by ANSPDCP EUR 70,000 for violations related to cross-border data processing. The case concerned compliance issues in the transfer or handling of data across borders. | RO | ANSPDCP | GDPR | €70,000 | ↗ |