BULLETIN №083Last updated · 09 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.1%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 13 Nov 2024 | Illumia S.p.A.Illumia S.p.A. was fined by the Italian data protection authority, Garante, for violations related to the processing of personal data for telemarketing purposes. The authority cited inadequate contractual arrangements with sub-processors and insufficient oversight of commercial partners. | IT | Garante | GDPR | €678,000 | ↗ |
| 17 Jan 2025 | Dane anonimowe (X. z siedzibą w K.)The UODO imposed administrative fines on X. based in K. for breaches of Article 6(1), Article 9(1), Article 13(1) and (2), Article 25(1), and Article 32(1) and (2) of the GDPR. These breaches also resulted in violations of the principles in Article 5(1)(a) and (f) and Article 5(2) of the GDPR. | PL | UODO | GDPR | €161,000 | ↗ |
| 31 May 2019 | Kamerafelvételek kiadásának elmulasztásaThe controller did not inform the data subject about the actions taken on their requests within the required timeframe. It also failed to provide access to certain data, which constituted a GDPR breach. | HU | NAIH | GDPR | €2,156 | ↗ |
| 14 Oct 2020 | Munkahelyi kamerás megfigyelés célhoz kötöttséggel, adattakarékossággal és az érintettek tájékoztatásával kapcsolatos hiányosságaiThe entity was fined by NAIH in the amount of HUF 700,000 for improperly implementing camera surveillance of employees. The authority also found that employees were not adequately informed about the scope and rules of the video monitoring. | HU | NAIH | GDPR | €1,925 | ↗ |
| 30 Apr 2020 | vingerafdrukken personeelThe Autoriteit Persoonsgegevens imposed a fine for the unlawful processing of employees' biometric data, specifically fingerprints, for time registration purposes. The authority found this to be a breach of Article 9 of the GDPR. | NL | AP | GDPR | €725,000 | ↗ |
| 20 Nov 2025 | SOCIETE AYANT POUR ACTIVITE L'EDITION DE REVUES ET PERIODIQUES ET LA REGIE PUBLICITAIRECNIL imposed an administrative fine of EUR 750,000 on SOCIETE AYANT POUR ACTIVITE L'EDITION DE REVUES ET PERIODIQUES ET LA REGIE PUBLICITAIRE. The case concerns a confirmed breach of rules supervised by the CNIL. | FR | CNIL | GDPR | €750,000 | ↗ |
| 27 Feb 2023 | Bank of Ireland 365 (‘BOI’)The Irish DPC fined Bank of Ireland 365 (‘BOI’) €750,000 in inquiry IN-20-7-2. The fine has been collected. | IE | DPC | GDPR | €750,000 | ↗ |
| 27 Nov 2025 | Conde NastThe French data protection authority CNIL fined Conde Nast EUR 750,000 over cookie practices on the Vanity Fair website. The authority found that the company placed cookies without valid consent, did not provide sufficient information about necessary cookies, and made refusal and withdrawal mechanisms ineffective. | FR | CNIL | GDPR | €750,000 | ↗ |
| 03 Oct 2024 | Police Service of Northern IrelandThe Police Service of Northern Ireland was fined £750,000 by the ICO for breaches of Articles 5(1)(f), 32(1) and (2) of the UK GDPR between 25 May 2018 and 14 June 2024. The case concerned insufficient protection of personal data and inadequate security of processing. The decision indicates a failure to implement appropriate technical and organisational safeguards. | GB | ICO | GDPR | €890,000 | ↗ |
| 10 Oct 2024 | SOCIETE COMMERCIALISANT DES PORTEFEUILLES DE CRYPTOMONNAIEThe CNIL imposed an administrative fine of EUR 750,000 on SOCIETE COMMERCIALISANT DES PORTEFEUILLES DE CRYPTOMONNAIE. The record indicates a regulatory breach, but no further details are provided. | FR | CNIL | GDPR | €750,000 | ↗ |
| 22 Jul 2021 | TikTok Inc.TikTok Inc. was fined 750,000 EUR by the Dutch authority AP for providing its privacy policy to users in the Netherlands, including children, only in English. The authority found this breached Article 12 GDPR, which requires information to be provided in a clear and easily accessible form. | NL | AP | GDPR | €750,000 | ↗ |
| 13 Apr 2023 | Arnia società cooperativaThe Garante imposed a fine of 800,000 EUR on Arnia società cooperativa for unauthorized data processing and telemarketing activities. The case concerned a breach of GDPR Article 5. | IT | Garante | GDPR | €800,000 | ↗ |
| 05 Sept 2024 | SOCIETE SPECIALISEE DANS L’EDITION ET LA VENTE DE LOGICIELS DE GESTION AUX MEDECINSThe CNIL imposed an administrative fine of EUR 800,000 on SOCIETE SPECIALISEE DANS L’EDITION ET LA VENTE DE LOGICIELS DE GESTION AUX MEDECINS. The case concerns a breach of rules supervised by the CNIL. | FR | CNIL | GDPR | €800,000 | ↗ |
| 18 Apr 2018 | Anonymizováno (ÚOOÚ UOOU-09774/17-25)The entity was fined for processing personal data of hundreds of thousands of individuals without consent or another legal basis. The authority found this to be a breach of § 5(2) of the Czech Data Protection Act. | CZ | UOOU | GDPR | €31,616 | ↗ |
| 01 Jan 2021 | ORANGE ESPAGNE, S.A.U.ORANGE ESPAGNE, S.A.U. was fined 800,000 EUR by the AEPD for failing to adequately protect personal data. The breach enabled identity fraud and unauthorized access to banking information through SIM card duplication. | ES | AEPD | GDPR | €800,000 | ↗ |
| 16 May 2018 | Telecom Italia S.p.A.Telecom Italia S.p.A. was fined by the Garante €800,000 for the unauthorized activation of numerous residential phone lines in a citizen's name. The case involved processing and disclosing personal data without a legal basis, as well as failing to notify data breaches. | IT | Garante | GDPR | €800,000 | ↗ |
| 09 Dec 2020 | Ítélet a NAIH/2019/3633/10 sz. ügyben (Fővárosi Törvényszék 106.K.700.561/2019/16) - 2020. december 9.The case concerned a HUF 800,000 fine imposed by the NAIH for unlawful camera surveillance. The authority found that the processing breached GDPR principles of lawfulness, fairness, transparency, purpose limitation, and data minimization. | HU | NAIH | GDPR | €2,240 | ↗ |
| 10 Nov 2022 | SOCIETE DEVELOPPANT UN LOGICIEL DE VOIX SUR IP ET UNE MESSAGERIE INSTANTANEECNIL imposed a fine of 800,000 EUR on SOCIETE DEVELOPPANT UN LOGICIEL DE VOIX SUR IP ET UNE MESSAGERIE INSTANTANEE. The decision concerns a breach of rules covered by the authority’s enforcement action. | FR | CNIL | GDPR | €800,000 | ↗ |
| 09 Jul 2020 | Iliad Italia S.p.A.Iliad Italia S.p.A. was fined EUR 800,000 by the Garante for irregularities in the processing of customer data. The violations concerned SIM card activation, promotional use of data, inadequate security measures, and improper data retention. | IT | Garante | GDPR | €800,000 | ↗ |
| 22 Jul 2021 | Roma CapitaleRoma Capitale was fined EUR 800,000 by the Garante for failing to adequately protect the personal data of motorists using parking meters. The authority also found improper data retention practices, increasing the risk to data subjects. | IT | Garante | GDPR | €800,000 | ↗ |