BULLETIN №084Last updated · 13 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -24%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 21 Nov 2025 | Anonimizirano (IP-RS 0609-114/2025/9)A legal entity was fined by IP-RS for failing to implement adequate organizational and technical measures to secure personal data processing on a publicly accessible web server. This led to unauthorized access to the personal data of 12 individuals. | SI | IP-RS | GDPR | €16,250 | ↗ |
| 24 Nov 2025 | SIA "EUROPARK LATVIA"A fine of EUR 25,000 was imposed. The decision has been appealed. | LV | DVI | GDPR | €25,000 | ↗ |
| 25 Nov 2025 | Dane anonimowe (D. C., prowadzącego działalność gospodarczą pod firmą W.)UODO imposed a fine of PLN 7,577 on an anonymous entrepreneur for failing to implement adequate technical and organizational measures to secure data processing. The authority also found that processing was not properly limited to the controller’s instructions and that no record of processing activities was maintained. | PL | UODO | GDPR | €1,794 | ↗ |
| 26 Nov 2025 | Cucina di Fabio S.R.L.ANSPDCP imposed a fine of EUR 1,000 on Cucina di Fabio S.R.L. for a GDPR violation. The case concerns a confirmed breach of personal data protection rules. | RO | ANSPDCP | GDPR | €1,000 | ↗ |
| 26 Nov 2025 | Cucina di Fabio S.R.L.ANSPDCP imposed a fine of EUR 2,000 on Cucina di Fabio S.R.L. for a GDPR violation. The case concerned non-compliance with personal data protection requirements. | RO | ANSPDCP | GDPR | €2,000 | ↗ |
| 26 Nov 2025 | Anonimizirano (IP-RS 0609-104/2025/18)The entity was fined EUR 6,000 for systematically and indiscriminately collecting employees’ location data through GPS devices in company vehicles without a legal basis. The authority found a breach of the lawfulness principle under Article 5 GDPR. | SI | IP-RS | GDPR | €6,000 | ↗ |
| 27 Nov 2025 | InfobelThe Belgian Data Protection Authority (APD) imposed a EUR 40,000 fine on Infobel on 2025-11-27. The authority found that the company resold telecom-derived personal data for marketing purposes without valid consent and ordered it to inform its business customers of the decision. | BE | Autorité de protection des données (APD) | GDPR | €40,000 | ↗ |
| 27 Nov 2025 | PFA Nițu A. Cleopatra – Expert contabilThe National Supervisory Authority for Personal Data Processing fined PFA Nițu A. Cleopatra – Expert contabil EUR 2,000 for GDPR violations. The case concerned non-compliant processing of personal data. | RO | ANSPDCP | GDPR | €2,000 | ↗ |
| 27 Nov 2025 | SOCIETE DE VENTE A DISTANCECNIL imposed an administrative fine of EUR 500,000 on SOCIETE DE VENTE A DISTANCE and issued an injunction. The case concerns a breach of rules supervised by CNIL. | FR | CNIL | GDPR | €500,000 | ↗ |
| 27 Nov 2025 | AMERICAN EXPRESS CARTE FRANCEOn 27 November 2025, CNIL fined AMERICAN EXPRESS CARTE FRANCE EUR 1.5 million for breaches of cookie and tracker rules. The authority found that trackers were placed without consent, despite refusal, and continued to be read after consent was withdrawn. | FR | CNIL | GDPR | €1,500,000 | ↗ |
| 27 Nov 2025 | SOCIETE EDITANT ET COMMERCIALISANT DES CARTES DE PAIEMENT A DEBIT DIFFERECNIL imposed an administrative fine of 1 500 000 EUR on SOCIETE EDITANT ET COMMERCIALISANT DES CARTES DE PAIEMENT A DEBIT DIFFERE. The case concerns a breach of rules supervised by CNIL. | FR | CNIL | GDPR | €1,500,000 | ↗ |
| 27 Nov 2025 | Conde NastThe French data protection authority CNIL fined Conde Nast EUR 750,000 over cookie practices on the Vanity Fair website. The authority found that the company placed cookies without valid consent, did not provide sufficient information about necessary cookies, and made refusal and withdrawal mechanisms ineffective. | FR | CNIL | GDPR | €750,000 | ↗ |
| 27 Nov 2025 | Istituto Comprensivo “G. Falcone” Rende-Quattromiglia (CS)The Garante fined Istituto Comprensivo “G. Falcone” EUR 2,000 for breaches of data processing principles, including lawfulness, fairness, and transparency. The authority also found non-compliance with data processing agreements. | IT | Garante | GDPR | €2,000 | ↗ |
| 27 Nov 2025 | CANDIDAT AUX ELECTIONS AU PARLEMENT EUROPEEN DE 2024 (procédure simplifiée)The CNIL imposed an administrative fine of €8,000 on CANDIDAT AUX ELECTIONS AU PARLEMENT EUROPEEN DE 2024 and issued an injunction. The case concerns a breach of rules supervised by the CNIL. | FR | CNIL | GDPR | €8,000 | ↗ |
| 27 Nov 2025 | Logika Group s.r.l.Logika Group s.r.l. was fined EUR 5,000 by the Italian supervisory authority, Garante. The authority found that the company sent unsolicited commercial communications and failed to respond to a data access request, in breach of GDPR requirements. | IT | Garante | GDPR | €5,000 | ↗ |
| 27 Nov 2025 | Verisure Italy s.r.l.Verisure Italy s.r.l. was fined by the Garante EUR 400,000 for breaches of data retention and information obligations in connection with marketing activities. The case concerned customer and former customer data processed without proper consent and notice. | IT | Garante | GDPR | €400,000 | ↗ |
| 27 Nov 2025 | Infobel NVInfobel NV was fined by the APD in the amount of 5,000 EUR for unlawfully processing personal data for direct marketing purposes without a valid legal basis. The authority found breaches of GDPR Articles 5(1)(a), 6(1), and 24. | BE | APD | GDPR | €5,000 | ↗ |
| 01 Dec 2025 | Anonimizirano (IP-RS 0609-128/2025/6)A legal entity was fined by IP-RS for failing to implement appropriate technical and organizational measures to secure personal data processing. This failure led to unauthorized access to data stored on a company laptop. | SI | IP-RS | GDPR | €1,000 | ↗ |
| 02 Dec 2025 | Bende IstvánBende István and Berencsi Béla Miklós were fined for processing personal data without a legal basis and for failing to provide required information. The authority found breaches of GDPR principles of fair processing, purpose limitation, and transparency. | HU | NAIH | GDPR | €1,315 | ↗ |
| 03 Dec 2025 | AVATEL TELECOM, S.A.AVATEL TELECOM, S.A. was fined 500,000 EUR by the AEPD for unauthorized duplication of SIM cards and their fraudulent use. The case concerns breaches of data protection principles and controls over access to telecommunications services. | ES | AEPD | GDPR | €500,000 | ↗ |