BULLETIN №081Last updated · 27 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -20.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 12 Nov 2021 | Transavia Airlines C.V.Transavia Airlines C.V. was fined by the AP 400,000 EUR for failing to implement appropriate security measures to protect personal data. The Article 32 GDPR breach led to unauthorized access to systems containing data of approximately 25 million individuals. | NL | AP | GDPR | €400,000 | ↗ |
| 10 May 2024 | EUSKALTEL, S.A.EUSKALTEL, S.A. was fined 400,000 EUR by the AEPD for failing to comply with a resolution requiring access to geolocation data. The authority found a breach of Article 58.2 of the GDPR. | ES | AEPD | GDPR | €400,000 | ↗ |
| 27 Nov 2025 | Verisure Italy s.r.l.Verisure Italy s.r.l. was fined by the Garante EUR 400,000 for breaches of data retention and information obligations in connection with marketing activities. The case concerned customer and former customer data processed without proper consent and notice. | IT | Garante | GDPR | €400,000 | ↗ |
| 18 Jan 2017 | Anonymizováno (ÚOOÚ UOOU-01178/17-265)The company was fined for repeatedly sending unsolicited commercial communications without a legal basis. The case concerned a breach of the Czech law on certain information society services. | CZ | UOOU | ePrivacy | €14,064 | ↗ |
| 11 May 2023 | SOCIETE EDITANT UN SITE INTERNET PROPOSANT DES ARTICLES, TESTS, QUIZ ET FORUMS DE DISCUSSION EN LIEN AVEC LA SANTE ET LE BIEN-ETRECNIL imposed a fine of 380,000 EUR on SOCIETE EDITANT UN SITE INTERNET PROPOSANT DES ARTICLES, TESTS, QUIZ ET FORUMS DE DISCUSSION EN LIEN AVEC LA SANTE ET LE BIEN-ETRE. The case concerns data processing breaches in connection with a health and wellness website. | FR | CNIL | GDPR | €380,000 | ↗ |
| 14 Oct 2021 | Dane anonimowe (Bank Z. S.A.)The Polish DPA (UODO) imposed an administrative fine of PLN 363,832 on Bank Z. S.A. The authority found that the bank failed to notify the supervisory authority of a personal data breach and did not inform the affected individuals. | PL | UODO | GDPR | €79,625 | ↗ |
| 16 Dec 2020 | [...].Kft.The company breached GDPR by failing to provide accessible information about data processing and by not responding to access requests within one month. It also gave incomplete responses to access requests, photographed guests’ ID documents, and uploaded those photos to a WhatsApp group. | HU | NAIH | GDPR | €1,012 | ↗ |
| 09 Oct 2024 | Pana AB, prowadzącego działalność gospodarczą pod firmą X, ul.The Polish DPA (UODO) imposed a fine of PLN 353,589 on Pana AB, operating under the name X, for breaches of the GDPR. The authority also ordered the company to bring its processing operations into compliance with Regulation (EU) 2016/679. | PL | UODO | GDPR | €82,273 | ↗ |
| 17 Oct 2023 | H&M Hennes & MauritzH&M Hennes & Mauritz GBC AB was fined for processing personal data for direct marketing without a lawful basis. The authority also found that the company failed to stop processing after objections were raised, breaching GDPR Articles 6, 12, and 21. | SE | IMY | GDPR | €30,356 | ↗ |
| 09 Jun 2021 | Räddningstjänsten Östra SkaraborgIMY found that Räddningstjänsten Östra Skaraborg breached the GDPR by improperly using surveillance cameras in changing areas. The authority also identified excessive personal data processing and inadequate security measures. | SE | IMY | GDPR | €34,794 | ↗ |
| 26 Feb 2024 | Ministry of DefenceThe UK Ministry of Defence sent emails using the “To” field instead of “BCC”, which disclosed 265 unique email addresses. The ICO found this breached GDPR Article 5(1)(f) and imposed a fine of 350,000 GBP. | GB | ICO | GDPR | €409,000 | ↗ |
| 08 Dec 2022 | Danske Shoppingcentre P/SDanske Shoppingcentre P/S was fined by Datatilsynet for unlawful CCTV surveillance of a toilet area in City2. The authority found a breach of the GDPR data minimization principle. | DK | Datatilsynet | GDPR | €47,054 | ↗ |
| 16 Dec 2025 | Bank MillenniumThe Polish Supreme Administrative Court upheld a PLN 350,000 administrative fine imposed on Bank Millennium by the President of the Personal Data Protection Office. The sanction concerned failure to report a personal data breach and failure to notify affected individuals after a courier shipment containing customer data was lost. | PL | Urząd Ochrony Danych Osobowych | GDPR | €82,922 | ↗ |
| 11 Feb 2021 | Roma CapitaleRoma Capitale was fined EUR 350,000 by the Garante for breaches of GDPR principles, including data minimization and security. The violations resulted in unauthorized access to personal data over an extended period. | IT | Garante | GDPR | €350,000 | ↗ |
| 12 Dec 2024 | Wind Tre S.p.A.Wind Tre S.p.A. was fined €347,520 by the Garante for violations related to processing personal data for promotional purposes and for inadequate technical and organizational measures. The case concerned telemarketing activities and the protection of the data involved. | IT | Garante | GDPR | €347,000 | ↗ |
| 05 Apr 2018 | Broker & Broker s.r.l.Broker & Broker s.r.l. was fined EUR 340,000 by the Italian authority Garante. The case concerned the registration of numerous phone cards to third parties without their knowledge or consent, which breached data protection rules. | IT | Garante | GDPR | €340,000 | ↗ |
| 13 Jun 2025 | HEP - Toplinarstvo d.o.o.HEP - Toplinarstvo d.o.o. was fined EUR 320,000 for failing to implement appropriate technical and organizational measures to protect data in its “Moj račun” application. The authority also found a lack of cooperation with the supervisory authority, including refusal to provide required information. | HR | AZOP | GDPR | €320,000 | ↗ |
| 31 Jan 2024 | SOCIETE AYANT POUR ACTIVITE LA COMMERCIALISATION ET GESTION DE PROGRAMMES ET CARTES DE FIDELITECNIL imposed an administrative fine of EUR 310,000 on SOCIETE AYANT POUR ACTIVITE LA COMMERCIALISATION ET GESTION DE PROGRAMMES ET CARTES DE FIDELITE. The case concerns identified breaches of rules supervised by CNIL. | FR | CNIL | GDPR | €310,000 | ↗ |
| 07 Aug 2023 | Anonymizováno (ÚOOÚ UOOU-00414.23-30)The decision confirms a fine for a healthcare entity for failing to notify data subjects and document a personal data breach after a cyberattack. The authority found breaches of GDPR transparency and notification obligations. | CZ | UOOU | GDPR | €12,756 | ↗ |
| 08 Jun 2023 | La Rinascente S.p.A.La Rinascente S.p.A. was fined by the Garante for unauthorized access to customer data and its modification. The breach led to the issuance of a new loyalty card containing incorrect personal details. | IT | Garante | GDPR | €300,000 | ↗ |