BULLETIN №083Last updated · 09 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.1%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 27 Nov 2025 | Verisure Italy s.r.l.Verisure Italy s.r.l. was fined by the Garante EUR 400,000 for breaches of data retention and information obligations in connection with marketing activities. The case concerned customer and former customer data processed without proper consent and notice. | IT | Garante | GDPR | €400,000 | ↗ |
| 21 May 2025 | Autostrade per l'Italia SpaThe Italian data protection authority fined Autostrade per l'Italia Spa EUR 420,000 for unlawfully processing an employee's personal data. The company used content from her Facebook profile and private Messenger and WhatsApp chats to support disciplinary proceedings and justify her dismissal. | IT | Garante per la protezione dei dati personali | GDPR | €420,000 | ↗ |
| 06 Dec 2011 | Tiscali Italia SpATiscali Italia SpA was fined €420,000 by the Garante for retaining customer traffic data beyond the legal retention period. The authority also found that Amdocs accessed the data without being properly designated as a data processor or obtaining customer consent. | IT | Garante | GDPR | €420,000 | ↗ |
| 11 Feb 2021 | Stichting OLVGStichting OLVG was fined by the AP 440,000 EUR for failing to implement two-factor authentication and for not regularly reviewing log files. The authority found that the organization did not maintain appropriate security measures required under Article 32 GDPR. | NL | AP | GDPR | €440,000 | ↗ |
| 01 Oct 2024 | TRIVE CREDIT SPAIN, S.L.TRIVE CREDIT SPAIN, S.L. failed to properly handle a data subject access request, which constitutes a breach of Article 15 GDPR. The AEPD imposed a fine for non-compliance with a prior resolution. | ES | AEPD | GDPR | €450,000 | ↗ |
| 07 Jul 2021 | Uitvoeringsinstituut werknemersverzekeringen (UWV)UWV was fined by the AP for failing to ensure an adequate level of security for personal data. The deficiencies led to multiple breaches involving sensitive information of job seekers. | NL | AP | GDPR | €450,000 | ↗ |
| 09 Dec 2020 | Twitter International CompanyThe Irish DPC imposed a fine of EUR 450,000 on Twitter International Company in inquiry IN-19-1-1. The fine was collected. | IE | DPC | GDPR | €450,000 | ↗ |
| 16 Jul 2019 | Stichting HagaZiekenhuisStichting HagaZiekenhuis was fined by the AP for failing to implement two-factor authentication and for not regularly reviewing log files. The authority found these shortcomings breached Article 32 GDPR on appropriate security measures. | NL | AP | GDPR | €460,000 | ↗ |
| 23 Feb 2023 | Centric Health Ltd. (“Centric”)The Irish DPC imposed a fine of EUR 460,000 on Centric Health Ltd. in inquiry IN-21-2-4. The fine has been collected. | IE | DPC | GDPR | €460,000 | ↗ |
| 14 Mar 2022 | Bank of Ireland Group plcThe Irish DPC fined Bank of Ireland Group plc EUR 463,000 in inquiry IN-19-9-5. The penalty status is recorded as collected. | IE | DPC | GDPR | €463,000 | ↗ |
| 31 Mar 2021 | Booking.com B.V.Booking.com B.V. was fined for failing to report a personal data breach to the Dutch Data Protection Authority within 72 hours of becoming aware of it, as required by GDPR Article 33. The case concerns the controller’s obligation to notify the supervisory authority without undue delay. | NL | AP | GDPR | €475,000 | ↗ |
| 06 Jan 2025 | Anonymisé (CNPD decision-01-fr-2025)The entity failed to comply with the response time requirements for data subject requests, which constitutes a breach of Article 12 GDPR. CNPD imposed a fine of EUR 493,560. | LU | CNPD | GDPR | €493,000 | ↗ |
| 01 Jan 2024 | SANTANDER CONSUMER FINANCE, S.A.Santander Consumer Finance, S.A. was fined by the AEPD 500,000 EUR for a data protection breach. The incident affected personal identification and contact data of 28,120 individuals. | ES | AEPD | GDPR | €500,000 | ↗ |
| 22 Mar 2021 | Tájékoztatási kötelezettség elmulasztása, hozzáférési jog és adatkezelés korlátozásához való jogThe controller did not inform the data subject within the required timeframe about actions taken on their requests. It also delayed access to the requested footage and failed to block the camera recording, resulting in a data protection fine. | HU | NAIH | GDPR | €1,365 | ↗ |
| 25 Mar 2021 | Kamerák üzemeltetése idősek otthonábanThe authority imposed a fine for using video surveillance for unlawful purposes. It also found that the data subjects were not adequately informed and that there was no proper legal basis for processing. | HU | NAIH | GDPR | €1,370 | ↗ |
| 27 Apr 2021 | Diszpécseri munkakört betöltő munkavállalóval folytatott telefonhívás rögzítéseThe decision concerned the unlawful recording and use of phone calls without a proper legal basis and without adequate transparency. The authority found breaches of GDPR accountability, lawful processing, and transparency principles. | HU | NAIH | GDPR | €1,380 | ↗ |
| 03 Dec 2025 | AVATEL TELECOM, S.A.AVATEL TELECOM, S.A. was fined 500,000 EUR by the AEPD for unauthorized duplication of SIM cards and their fraudulent use. The case concerns breaches of data protection principles and controls over access to telecommunications services. | ES | AEPD | GDPR | €500,000 | ↗ |
| 31 Jan 2024 | MARINA SALUD, S.A.MARINA SALUD, S.A. was fined by the AEPD 500,000 EUR for failing to comply with data processing agreement obligations under Article 28 GDPR. The case involved the handling of sensitive health data, which increased the compliance risk. | ES | AEPD | GDPR | €500,000 | ↗ |
| 24 Nov 2023 | Pitagorasz Oktatási Stúdió Kft.Pitagorasz Oktatási Stúdió Kft. was fined by NAIH for processing minors' personal data without a valid legal basis. The authority found breaches of GDPR principles, including accountability, purpose limitation, and transparency. | HU | NAIH | GDPR | €1,315 | ↗ |
| 20 Dec 2019 | Hozzáférési jog terjedelmeThe controller did not inform the data subject about actions taken on their requests within the required timeframe. It also failed to provide access to certain data, which constitutes a GDPR breach. | HU | NAIH | GDPR | €1,515 | ↗ |