BULLETIN №084Last updated · 13 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -24%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 28 Jul 2025 | KINYO, S.L.KINYO, S.L. was fined by the AEPD in the amount of 15,000 EUR for sending unsolicited commercial emails. The authority also found that recipients were not provided with an effective mechanism to opt out of future communications. | ES | AEPD | ePrivacy | €15,000 | ↗ |
| 29 Jul 2025 | Anonimizirano (IP-RS 0609-18/2025/7)The legal entity was fined by IP-RS for unlawfully processing personal data by redirecting emails without a legal basis. The authority found a breach of the GDPR principle of lawfulness. | SI | IP-RS | GDPR | €10,614 | ↗ |
| 30 Jul 2025 | ONEY SERVICIOS FINANCIEROS EFC, S.A.The AEPD fined ONEY Servicios Financieros EFC, S.A. 150,000 EUR for failing to adequately protect personal data. The breach led to a security incident in which a third party accessed a customer's account through a vishing attack. | ES | AEPD | GDPR | €150,000 | ↗ |
| 01 Aug 2025 | društvo XThe company failed to implement appropriate organizational and technical security measures, which led to the unauthorized disclosure of personal data of clients involved in credit financing. AZOP imposed a fine of 17,500 EUR. | HR | AZOP | GDPR | €17,500 | ↗ |
| 01 Aug 2025 | Dr. Max SRLANSPDCP fined Dr. Max SRL EUR 1,000 after an investigation concluded in August 2025. The authority found breaches of GDPR Articles 12 and 17, including failure to respond to a deletion request and unlawful retention of an identity card copy without consent. | RO | Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal | GDPR | €1,000 | ↗ |
| 04 Aug 2025 | Azienda Ospedaliero-UniversitariaThe Italian data protection authority fined Azienda Ospedaliero-Universitaria EUR 80,000 for improperly configuring its health dossier. It found that staff could access patients’ clinical histories without proper profiling, alerts, or access logging, and that patients were not adequately informed or able to consent or object. | IT | Garante per la protezione dei dati personali | GDPR | €80,000 | ↗ |
| 04 Aug 2025 | Linea Stampalibera Società Cooperativa r.l.The Garante imposed a EUR 2,000 fine on Linea Stampalibera Società Cooperativa r.l. for unlawfully disseminating personal data, including health information, on its online news site. The authority found a breach of data protection rules. | IT | Garante | GDPR | €2,000 | ↗ |
| 04 Aug 2025 | Azienda Ospedaliero Universitaria CareggiAzienda Ospedaliero Universitaria Careggi was fined by the Garante EUR 20,000 for violations related to the management of electronic health records. The authority found non-compliance with data protection requirements. | IT | Garante | GDPR | €20,000 | ↗ |
| 05 Aug 2025 | Ordinul Biochimiștilor, Biologilor și Chimiștilor în Sistemul Sanitar din RomâniaANSPDCP imposed a EUR 1,000 fine on the Order of Biochemists, Biologists and Chemists in the Romanian Healthcare System for breaching Article 15 of the GDPR. The case concerned improper handling of a data subject access request. | RO | ANSPDCP | GDPR | €1,000 | ↗ |
| 06 Aug 2025 | GOHIPOTECA, S.L.GOHIPOTECA, S.L. processed personal data without consent, using an individual's data to apply for a mortgage without authorization. The AEPD imposed a fine of EUR 2,000 for this violation. | ES | AEPD | GDPR | €2,000 | ↗ |
| 06 Aug 2025 | SERVICIOS FINANCIEROS CARREFOUR, E.F.C., S.ASERVICIOS FINANCIEROS CARREFOUR, E.F.C., S.A suffered a data breach involving unauthorized access to and exfiltration of customer personal data, including payment information. The incident was linked to phishing and account compromise, resulting in the loss of sensitive data. | ES | AEPD | GDPR | €2,500,000 | ↗ |
| 06 Aug 2025 | ORNITOLÓGICA DE ANDALUCÍA FOAORNITOLÓGICA DE ANDALUCÍA FOA was fined EUR 1,500 by the AEPD for sending a mass email that contained personal data, including names and DNI numbers, without adequate security measures. The authority found this to be a breach of data protection rules. | ES | AEPD | GDPR | €1,500 | ↗ |
| 06 Aug 2025 | YUNEXPRESS SPAIN, S.L.YUNEXPRESS SPAIN, S.L. was fined EUR 9,000 by the AEPD for failing to formalize a data processing agreement and for inaccuracies in data handling. The authority found breaches of GDPR Articles 28(3) and 5(1)(d). | ES | AEPD | GDPR | €9,000 | ↗ |
| 11 Aug 2025 | APARELLS ORTOPEDICS CURTO, S.L.APARELLS ORTOPEDICS CURTO, S.L. did not provide complete personal data and medical records in response to an access request. The AEPD found this to be a breach of data protection rules and imposed a fine of 10,000 EUR. | ES | AEPD | GDPR | €10,000 | ↗ |
| 11 Aug 2025 | FUNDACIÓN PARA EL DESARROLLO DE LA ENFERMERÍA y SINDICATO DE ENFERMERÍA, SATSESATSE and FUDEN were fined by the AEPD EUR 15,000 after a ransomware incident affected personal data. The authority also found that the parties had not properly formalized a joint controllership agreement under the GDPR. | ES | AEPD | GDPR | €15,000 | ↗ |
| 12 Aug 2025 | Asociația Casa de Ajutor Reciproc „FLEXICREDIT”In June 2025, ANSPDCP completed an investigation at Asociația Casa de Ajutor Reciproc „FLEXICREDIT” and found violations of GDPR provisions. The entity was fined EUR 3,000. | RO | ANSPDCP | GDPR | €3,000 | ↗ |
| 13 Aug 2025 | TELECONTACT LIST S.L.TELECONTACT LIST S.L. was fined by the AEPD €1,000 for failing to respond to a data subject’s requests to exercise the rights of access and erasure. The authority found a breach of GDPR obligations, including Article 17. | ES | AEPD | GDPR | €1,000 | ↗ |
| 13 Aug 2025 | Anonimizirano (IP-RS 0609-97/2024/2)A sole proprietor was fined for failing to respond to a request from the Information Commissioner within the specified 10-day period. The authority treated this as a breach of Article 31 GDPR. | SI | IP-RS | GDPR | €500 | ↗ |
| 14 Aug 2025 | ALIQUAM SOFTWARE DEVELOPMENT, S.R.L.UALIQUAM SOFTWARE DEVELOPMENT, S.R.L.U was fined by the AEPD 1,400 EUR for sending unsolicited marketing emails despite requests to stop. The case concerns a breach of the LSSI rules on commercial communications. | ES | AEPD | ePrivacy | €1,400 | ↗ |
| 18 Aug 2025 | SC Elite Conta SRLThe National Supervisory Authority for Personal Data Processing completed an investigation in July 2025 at SC Elite Conta SRL and found a GDPR violation. The company was fined for failing to properly notify a personal data security breach. | RO | ANSPDCP | GDPR | €3,000 | ↗ |