BULLETIN №084Last updated · 13 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -24%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 29 Dec 2025 | SOCIETE EDITANT UNE APPLICATION MOBILECNIL imposed an administrative fine of EUR 270,000 on SOCIETE EDITANT UNE APPLICATION MOBILE. The case concerns a breach of personal data protection rules and should be considered in compliance assessments. | FR | CNIL | GDPR | €270,000 | ↗ |
| 29 Dec 2025 | SOCIETE EXERCANT UNE ACTIVITE D'EDITION DE JOURNAUX (procédure simplifiée)The CNIL imposed an administrative fine of EUR 7,000 on SOCIETE EXERCANT UNE ACTIVITE D'EDITION DE JOURNAUX and issued an injunction. The case concerns a breach of rules supervised by the CNIL. | FR | CNIL | GDPR | €7,000 | ↗ |
| 30 Dec 2025 | SOCIETE DU SECTEUR TERTIAIREThe CNIL imposed an administrative fine of EUR 3,500,000 on SOCIETE DU SECTEUR TERTIAIRE. The case concerns a breach of personal data protection rules. | FR | CNIL | GDPR | €3,500,000 | ↗ |
| 30 Dec 2025 | SOCIETE EXERCANT UNE ACTIVITE DE FRET AEROPORTUAIRE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 10,000 on SOCIETE EXERCANT UNE ACTIVITE DE FRET AEROPORTUAIRE. The case was handled under a simplified procedure. | FR | CNIL | GDPR | €10,000 | ↗ |
| 30 Dec 2025 | Roumasport S.R.LRoumasport S.R.L was fined EUR 10,000 by ANSPDCP for violating GDPR provisions. The case concerns non-compliant processing of personal data. | RO | ANSPDCP | GDPR | €10,000 | ↗ |
| 30 Dec 2025 | SOCIETE AYANT POUR ACTIVITE L'ACQUISITION ET LA GESTION D'HOTELS/RESIDENCES HOTELIERES (procédure simplifiée)The CNIL imposed an administrative fine of 5,000 EUR on the company engaged in the acquisition and management of hotels and hotel residences. The case was handled under a simplified procedure. | FR | CNIL | GDPR | €5,000 | ↗ |
| 31 Dec 2025 | UNIVERSITE (procédure simplifiée)CNIL imposed an administrative fine of EUR 20,000 on UNIVERSITE (procédure simplifiée). The case concerned a confirmed breach of rules supervised by CNIL. | FR | CNIL | GDPR | €20,000 | ↗ |
| 01 Jan 2026 | Telekommunikationsunternehmen aus NRWThe Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen imposed a total fine of EUR 300,000 on a telecommunications company from North Rhine-Westphalia. The authority found breaches of transparency obligations and data subject rights, including requests for access, deletion, and objection. | DE | Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen | GDPR | €300,000 | ↗ |
| 01 Jan 2026 | CloudflareAGCOM issued an ordinanza ingiunzione against Cloudflare under the Digital Services Act. The fine is 100,000 EUR and relates to a breach of DSA obligations. | IT | AGCOM | DSA | €100,000 | ↗ |
| 02 Jan 2026 | Dane anonimowe (Spółkę)UODO imposed an administrative fine of PLN 978,128 on the company. The authority found that the controller did not ensure the independence of the Data Protection Officer and failed to prevent a conflict of interest arising from the DPO’s other tasks and duties. | PL | UODO | GDPR | €232,000 | ↗ |
| 08 Jan 2026 | OPÉRATEUR DE TÉLÉPHONIE MOBILECNIL imposed an administrative fine of EUR 27 million on OPÉRATEUR DE TÉLÉPHONIE MOBILE and issued an injunction. The case concerns a regulatory breach addressed by the authority’s decision. | FR | CNIL | GDPR | €27,000,000 | ↗ |
| 08 Jan 2026 | Amendă pentru încălcarea Legii nr. 506/2004 și a RGPDA fine of EUR 2,000 was imposed for violations of certain provisions of Law No. 506/2004 and the GDPR. The case concerns non-compliant personal data processing and privacy protection obligations. | RO | ANSPDCP | GDPR | €2,000 | ↗ |
| 08 Jan 2026 | OPÉRATEUR DE TÉLÉPHONIE FIXECNIL imposed an administrative fine of EUR 15 million on a fixed-line telecom operator and issued an injunction. The case concerns a breach requiring corrective action and compliance with regulatory obligations. | FR | CNIL | GDPR | €15,000,000 | ↗ |
| 08 Jan 2026 | MEDIOS DE PREVENCIÓN EXTERNOS SUR, S.L.The company suffered a ransomware attack that caused a breach of the confidentiality and availability of personal data. AEPD found a violation of Article 5(1)(f) GDPR. | ES | AEPD | GDPR | €60,000 | ↗ |
| 10 Jan 2026 | NAROBESA INV, S.L.NAROBESA INV, S.L. was fined 1,000 EUR by the AEPD for unlawfully accessing a job applicant's credit information without consent during recruitment. The conduct breached data protection rules and occurred in the hiring process. | ES | AEPD | GDPR | €1,000 | ↗ |
| 10 Jan 2026 | DÉCIMAS, S.L.DÉCIMAS, S.L. was fined by the AEPD in the amount of EUR 200,000 for a personal data breach. The incident exposed personal data and breached GDPR Article 5(1)(f). | ES | AEPD | GDPR | €200,000 | ↗ |
| 10 Jan 2026 | MULTISPORTS GALICIA, S.L.MULTISPORTS GALICIA, S.L. was fined by the AEPD EUR 6,000 for failing to implement appropriate technical and organizational measures proportionate to the risk. The weakness allowed easy access to personal data of race participants through its website. | ES | AEPD | GDPR | €6,000 | ↗ |
| 12 Jan 2026 | Zalando SEThe President of UOKiK imposed a fine of PLN 30,945,000 on Zalando SE for failing to provide the lowest price from the 30 days before a discount and for misleading discount presentation. The decision concerns consumer protection and is not yet final. | PL | UOKiK | Omnibus | €7,351,000 | ↗ |
| 13 Jan 2026 | Free Mobile and FreeFrance’s CNIL fined Free Mobile and Free a combined EUR 42 million for GDPR breaches linked to a 2024 data breach affecting more than 24 million users. The regulator found inadequate security measures and said Free Mobile unlawfully retained former subscribers’ data. | FR | Commission nationale de l’informatique et des libertés | GDPR | €42,000,000 | ↗ |
| 13 Jan 2026 | PREMIER RESTAURANTS ROMANIA SRLThe National Supervisory Authority for Personal Data Processing imposed a fine on PREMIER RESTAURANTS ROMANIA SRL for GDPR violations. The case concerned non-compliance with personal data protection requirements. | RO | ANSPDCP | GDPR | €8,000 | ↗ |