BULLETIN №084Last updated · 13 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -24%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 16 Oct 2025 | SOCIETE EXERCANT UNE ACTIVITE DE VENTE A DISTANCE SUR CATALOGUE SPECIALISE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 3,000 on SOCIETE EXERCANT UNE ACTIVITE DE VENTE A DISTANCE SUR CATALOGUE SPECIALISE. The case concerns a breach of rules supervised by the CNIL. | FR | CNIL | GDPR | €3,000 | ↗ |
| 17 Oct 2025 | Experian Nederland B.V.Experian Nederland B.V. was fined by the AP €2,700,000 for failing to adequately inform data subjects and for processing personal data without a valid legal basis. The case concerns breaches of the GDPR principles of transparency and lawful processing. | NL | AP | GDPR | €2,700,000 | ↗ |
| 20 Oct 2025 | The Medical Specialist GroupThe Medical Specialist Group LLP reported a personal data breach after suspicious emails indicated that cyber criminals had accessed its mail server. An internal investigation found the server had been compromised in August 2021 through multiple vulnerabilities, allowing access to and theft of stored emails containing personal data. | GG | ODPA | GDPR | €115,000 | ↗ |
| 20 Oct 2025 | S.P.E.E.H. HIDROELECTRICA SAS.P.E.E.H. HIDROELECTRICA SA was fined by ANSPDCP EUR 5,000 for failing to notify a personal data breach. The incident involved customer data, including names, contract details, and billing information. | RO | ANSPDCP | GDPR | €5,000 | ↗ |
| 22 Oct 2025 | SPRINTER MEGACENTROS DEL DEPORTE, S.L.SPRINTER MEGACENTROS DEL DEPORTE, S.L. experienced a data breach affecting approximately 6.2 million individuals, involving unauthorized access and encryption of critical systems. The incident was intentional and involved data from multiple EU member states. | ES | AEPD | GDPR | €2,600,000 | ↗ |
| 22 Oct 2025 | AXARNET COMUNICACIONES, S.L.AXARNET COMUNICACIONES, S.L. suffered a data breach caused by a vulnerability in a third-party program. The incident exposed personal data of 50,250 clients, including names, email addresses, and bank account details, leading to a fine by the AEPD. | ES | AEPD | GDPR | €20,000 | ↗ |
| 22 Oct 2025 | Agency for Control of Outstanding Debts S.R.L.The company was fined EUR 2,000 by ANSPDCP for breaching multiple GDPR provisions. The case followed a complaint alleging deficiencies in personal data protection compliance. | RO | ANSPDCP | GDPR | €2,000 | ↗ |
| 22 Oct 2025 | εκδοτικός οίκοςThe Greek Data Protection Authority fined a publishing house EUR 9,000 for disclosing an author's personal and special-category data in an email sent to 55 recipients. It also found failures to implement data protection by design and to notify both the authority and the data subject of the breach. | GR | Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα | GDPR | €9,000 | ↗ |
| 23 Oct 2025 | Provvedimento del 23 ottobre 2025 [10195910]A fine of EUR 1,000 was imposed for the unlawful online publication of personal data by a local authority. The conduct breached core data protection principles. | IT | Garante | GDPR | €1,000 | ↗ |
| 23 Oct 2025 | Istituto d'Istruzione Superiore “Statista Aldo Moro” di Fara SabinaThe school published on its website a document containing personal data related to a student's disciplinary proceeding. Garante found that this breached the GDPR principles of lawfulness, fairness, and transparency. | IT | Garante | GDPR | €4,000 | ↗ |
| 23 Oct 2025 | Hearst Magazines Italia S.p.A.Hearst Magazines Italia S.p.A. was fined EUR 20,000 by the Garante for publishing personal data relating to an individual's health without a legal basis. The authority found a breach of the principles of lawfulness and fairness in processing. | IT | Garante | GDPR | €20,000 | ↗ |
| 23 Oct 2025 | Ordine degli Avvocati di LatinaOrdine degli Avvocati di Latina was fined EUR 15,000 by the Garante for unlawful, incorrect, and non-transparent processing of personal data. The authority also found a failure to ensure data minimization. | IT | Garante | GDPR | €15,000 | ↗ |
| 23 Oct 2025 | Azzurra Sport s.r.l.Azzurra Sport s.r.l. was fined EUR 4,000 by the Garante for unlawful processing of personal data through a video surveillance system. The breach concerned the absence of appropriate informational signage for individuals subject to the monitoring. | IT | Garante | GDPR | €4,000 | ↗ |
| 23 Oct 2025 | Comune di AvolaThe Garante fined Comune di Avola 2,000 EUR for failing to provide the Authority with the Data Protection Officer’s contact details. The breach concerned the obligation under Article 37(7) GDPR. | IT | Garante | GDPR | €2,000 | ↗ |
| 23 Oct 2025 | Comune di CurtaroloComune di Curtarolo was fined EUR 15,000 by the Garante for using surveillance footage for disciplinary purposes without proper legal justification. The authority also found that adequate privacy information was not provided to the individuals concerned. | IT | Garante | GDPR | €15,000 | ↗ |
| 23 Oct 2025 | Multimedia News Società CooperativaThe Garante fined Multimedia News Società Cooperativa EUR 20,000 for failing to provide a privacy notice and contact details for data requests on its website. The authority found this breached transparency obligations and data subject rights. | IT | Garante | GDPR | €20,000 | ↗ |
| 23 Oct 2025 | Franco SpellecchiaFranco Spellecchia was fined by the Garante for installing a video surveillance system around his residence without the required legal basis. The authority found that the setup breached GDPR rules, including the absence of a legitimate interest or authorization. | IT | Garante | GDPR | €500 | ↗ |
| 23 Oct 2025 | Zephiromedia S.r.l.Zephiromedia S.r.l. was fined EUR 30,000 by the Garante for sending unsolicited promotional emails. The authority also found that recipients were not given an effective way to unsubscribe or exercise their rights. | IT | Garante | GDPR | €30,000 | ↗ |
| 23 Oct 2025 | Geturhotels SrlGeturhotels Srl was fined EUR 6,000 by the Garante for sending unsolicited SMS messages to a complainant despite their objection. The authority found that the company’s conduct breached GDPR rules on processing personal data for promotional purposes. | IT | Garante | GDPR | €6,000 | ↗ |
| 23 Oct 2025 | Comune di Arcinazzo RomanoThe Garante fined Comune di Arcinazzo Romano 4,500 EUR for unlawfully processing personal data through a video system. The system was used to verify tax compliance for waste disposal, in breach of the principles of lawfulness, fairness, transparency, and purpose limitation. | IT | Garante | GDPR | €4,500 | ↗ |