BULLETIN №081Last updated · 27 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -20.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 06 Aug 2025 | GOHIPOTECA, S.L.GOHIPOTECA, S.L. processed personal data without consent, using an individual's data to apply for a mortgage without authorization. The AEPD imposed a fine of EUR 2,000 for this violation. | ES | AEPD | GDPR | €2,000 | ↗ |
| 06 Aug 2025 | SERVICIOS FINANCIEROS CARREFOUR, E.F.C., S.ASERVICIOS FINANCIEROS CARREFOUR, E.F.C., S.A suffered a data breach involving unauthorized access to and exfiltration of customer personal data, including payment information. The incident was linked to phishing and account compromise, resulting in the loss of sensitive data. | ES | AEPD | GDPR | €2,500,000 | ↗ |
| 06 Aug 2025 | ORNITOLÓGICA DE ANDALUCÍA FOAORNITOLÓGICA DE ANDALUCÍA FOA was fined EUR 1,500 by the AEPD for sending a mass email that contained personal data, including names and DNI numbers, without adequate security measures. The authority found this to be a breach of data protection rules. | ES | AEPD | GDPR | €1,500 | ↗ |
| 06 Aug 2025 | YUNEXPRESS SPAIN, S.L.YUNEXPRESS SPAIN, S.L. was fined EUR 9,000 by the AEPD for failing to formalize a data processing agreement and for inaccuracies in data handling. The authority found breaches of GDPR Articles 28(3) and 5(1)(d). | ES | AEPD | GDPR | €9,000 | ↗ |
| 05 Aug 2025 | Ordinul Biochimiștilor, Biologilor și Chimiștilor în Sistemul Sanitar din RomâniaANSPDCP imposed a EUR 1,000 fine on the Order of Biochemists, Biologists and Chemists in the Romanian Healthcare System for breaching Article 15 of the GDPR. The case concerned improper handling of a data subject access request. | RO | ANSPDCP | GDPR | €1,000 | ↗ |
| 04 Aug 2025 | Azienda Ospedaliero-UniversitariaThe Italian data protection authority fined Azienda Ospedaliero-Universitaria EUR 80,000 for improperly configuring its health dossier. It found that staff could access patients’ clinical histories without proper profiling, alerts, or access logging, and that patients were not adequately informed or able to consent or object. | IT | Garante per la protezione dei dati personali | GDPR | €80,000 | ↗ |
| 04 Aug 2025 | Linea Stampalibera Società Cooperativa r.l.The Garante imposed a EUR 2,000 fine on Linea Stampalibera Società Cooperativa r.l. for unlawfully disseminating personal data, including health information, on its online news site. The authority found a breach of data protection rules. | IT | Garante | GDPR | €2,000 | ↗ |
| 04 Aug 2025 | Azienda Ospedaliero Universitaria CareggiAzienda Ospedaliero Universitaria Careggi was fined by the Garante EUR 20,000 for violations related to the management of electronic health records. The authority found non-compliance with data protection requirements. | IT | Garante | GDPR | €20,000 | ↗ |
| 01 Aug 2025 | društvo XThe company failed to implement appropriate organizational and technical security measures, which led to the unauthorized disclosure of personal data of clients involved in credit financing. AZOP imposed a fine of 17,500 EUR. | HR | AZOP | GDPR | €17,500 | ↗ |
| 01 Aug 2025 | Dr. Max SRLANSPDCP fined Dr. Max SRL EUR 1,000 after an investigation concluded in August 2025. The authority found breaches of GDPR Articles 12 and 17, including failure to respond to a deletion request and unlawful retention of an identity card copy without consent. | RO | Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal | GDPR | €1,000 | ↗ |
| 30 Jul 2025 | ONEY SERVICIOS FINANCIEROS EFC, S.A.The AEPD fined ONEY Servicios Financieros EFC, S.A. 150,000 EUR for failing to adequately protect personal data. The breach led to a security incident in which a third party accessed a customer's account through a vishing attack. | ES | AEPD | GDPR | €150,000 | ↗ |
| 29 Jul 2025 | Anonimizirano (IP-RS 0609-18/2025/7)The legal entity was fined by IP-RS for unlawfully processing personal data by redirecting emails without a legal basis. The authority found a breach of the GDPR principle of lawfulness. | SI | IP-RS | GDPR | €10,614 | ↗ |
| 28 Jul 2025 | KINYO, S.L.KINYO, S.L. was fined by the AEPD in the amount of 15,000 EUR for sending unsolicited commercial emails. The authority also found that recipients were not provided with an effective mechanism to opt out of future communications. | ES | AEPD | ePrivacy | €15,000 | ↗ |
| 25 Jul 2025 | Anonimizirano (IP-RS 0609-34/2025/8)The legal entity did not establish a valid contract with a data processor. This breaches Article 28 GDPR, which requires processing by a processor to be governed by a contract. | SI | IP-RS | GDPR | €5,610 | ↗ |
| 24 Jul 2025 | CURENERGÍACURENERGÍA was fined by the AEPD EUR 1,000,000 for a data protection breach involving improper handling of personal data due to human error. The issue was corrected after notification. | ES | AEPD | GDPR | €1,000,000 | ↗ |
| 24 Jul 2025 | Követeléskezeléssel összefüggő jogalap nélküli adatkezelés és törlési kérelem nem teljesítéseThe authority imposed a fine for a negligent GDPR breach involving the processing of personal data without a legal basis in connection with debt collection. It also found that deletion requests from the data subject were not fulfilled. | HU | NAIH | GDPR | €25,100 | ↗ |
| 23 Jul 2025 | Agricola International SAAgricola International SA was fined EUR 5,000 by ANSPDCP for a data security breach. The incident was reported by the company itself, indicating an internally detected event that required compliance review. | RO | ANSPDCP | GDPR | €5,000 | ↗ |
| 23 Jul 2025 | ING Bank Śląski SAThe Polish supervisory authority imposed an administrative fine on ING Bank Śląski SA for scanning the identity documents of customers and prospective customers without properly assessing whether this was necessary under AML rules. The decision became final on 23 July 2025 and concerns breaches of Articles 5(1)(a), (b) and (c) and 6(1) of the GDPR. | PL | President of the Personal Data Protection Office | GDPR | €4,375,000 | ↗ |
| 23 Jul 2025 | Dane anonimowe (K.)UODO imposed an administrative fine of PLN 18,416,400 for processing personal data without a lawful basis. The case concerned copying and scanning customers’ identity documents without properly verifying whether this was justified by AML obligations. | PL | UODO | GDPR | €4,328,000 | ↗ |
| 22 Jul 2025 | KVIKU SPAIN, S.L.KVIKU SPAIN, S.L. was fined by the AEPD in the amount of EUR 4,000 for sending unsolicited messages and processing personal data without a legal basis. The authority found a breach of Article 6(1) GDPR. | ES | AEPD | GDPR | €4,000 | ↗ |