BULLETIN №084Last updated · 13 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -24%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 14 Jan 2026 | ZalandoUOKiK imposed a fine on Zalando for misleading consumers by improperly presenting promotional prices and hiding the required lowest price from the previous 30 days. According to the report, the combined sanctions against Zalando and Temu were about PLN 37 million, with Zalando accounting for PLN 31,488,674. | PL | Urząd Ochrony Konkurencji i Konsumentów | Other | €7,465,000 | ↗ |
| 15 Jan 2026 | Allay Claims Ltd The ICO issued an MPN and EN to Allay Claims Ltd after a large volume of unsolicited SMS messages promoting PPI tax refund services. The case indicates a breach of direct marketing and electronic communications rules. | GB | ICO | GDPR | €138,000 | ↗ |
| 15 Jan 2026 | CANDIDATS AUX ÉLECTIONS LÉGISLATIVES (procédure simplifiée)CNIL imposed an administrative fine of 2,000 EUR on CANDIDATS AUX ÉLECTIONS LÉGISLATIVES (procédure simplifiée) and issued an injunction. The case concerns a breach of rules supervised by CNIL. | FR | CNIL | GDPR | €2,000 | ↗ |
| 16 Jan 2026 | BAR GIOIA di XXThe Garante imposed a fine of EUR 600 on BAR GIOIA for the non-compliant installation of a video surveillance system. The case concerned breaches of data protection rules and the requirements for lawful processing. | IT | Garante | GDPR | €600 | ↗ |
| 16 Jan 2026 | Provvedimento del 16 gennaio 2026 [10213836]The Garante imposed a fine of EUR 500 on an anonymized data controller for a minor breach of data protection rules in the health sector. The authority also ordered publication of the decision on its website. | IT | Garante | GDPR | €500 | ↗ |
| 16 Jan 2026 | Liceo Classico e Scientifico Alessandro VoltaLiceo Classico e Scientifico Alessandro Volta was fined 2,000 EUR by the Garante for publishing personal data on its institutional website without a proper legal basis. The authority found breaches of lawfulness, fairness, and transparency principles. | IT | Garante | GDPR | €2,000 | ↗ |
| 16 Jan 2026 | Born S.r.l.Born S.r.l. was fined by the Garante 15,000 EUR for making unsolicited promotional calls to numbers listed in the Public Register of Oppositions. The conduct breached data protection rules governing telephone marketing and the right to object. | IT | Garante | GDPR | €15,000 | ↗ |
| 16 Jan 2026 | Macelleria La Costata s.r.l.s.The Garante fined Macelleria La Costata s.r.l.s. EUR 1,500 for the non-compliant installation of a video surveillance system. The authority found a breach of GDPR Article 5, which sets out the core principles for personal data processing. | IT | Garante | GDPR | €1,500 | ↗ |
| 16 Jan 2026 | Associazione Turistica Pro Loco di CittarealeThe association unlawfully disclosed the personal data of 23 members by publishing it in a public notice and online. The authority found breaches of lawfulness, fairness, transparency, and data minimization. | IT | Garante | GDPR | €600 | ↗ |
| 16 Jan 2026 | Azienda Ospedaliera S. Pio di BeneventoAzienda Ospedaliera S. Pio di Benevento was fined by the Garante EUR 6,000 for violations related to the processing of personal data. The case concerned special categories of data and disclosure to third parties. | IT | Garante | GDPR | €6,000 | ↗ |
| 16 Jan 2026 | Πυροσβεστικό ΣώμαThe Hellenic Data Protection Authority imposed a €10,000 fine on the Fire Service for unlawfully processing an employee’s special-category health data. The authority found breaches of GDPR lawfulness and data minimization principles and noted that the data were accessible through an internal electronic application. | GR | Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα | GDPR | €10,000 | ↗ |
| 20 Jan 2026 | Timegrip ASTimegrip AS was fined 250,000 NOK for failing to provide employees access to their own timekeeping data after the bankruptcy of a retail chain. The authority treated the company as the data controller and found a breach of the GDPR right of access. | NO | Datatilsynet | GDPR | €21,340 | ↗ |
| 22 Jan 2026 | ÉTABLISSEMENT PUBLIC ADMINISTRATIFCNIL imposed an administrative fine of EUR 5,000,000 on ÉTABLISSEMENT PUBLIC ADMINISTRATIF and issued an injunction. The case concerns a confirmed breach of rules supervised by CNIL. | FR | CNIL | GDPR | €5,000,000 | ↗ |
| 24 Jan 2026 | IBERANUNCIOS SLIBERANUNCIOS SL was fined by the AEPD EUR 15,000 for a data protection breach. The incident allowed unauthorized access to personal data, breaching the confidentiality principle under GDPR. | ES | AEPD | GDPR | €15,000 | ↗ |
| 24 Jan 2026 | CENTRO MÉDICO REY FERNANDO, S.L.P.The entity charged a fee for providing a patient with their medical history, which breached the right of access under GDPR Article 12. The AEPD imposed a fine of 1,000 EUR. | ES | AEPD | GDPR | €1,000 | ↗ |
| 26 Jan 2026 | SportAdmin i Skandinavien ABSportAdmin i Skandinavien AB was fined by IMY 6,000,000 SEK for failing to implement appropriate technical and organizational measures to ensure an adequate level of security for personal data. The deficiency resulted in a data breach. | SE | IMY | GDPR | €564,000 | ↗ |
| 29 Jan 2026 | Università Telematica e-CampusThe Garante fined Università Telematica e-Campus EUR 50,000 for violations related to biometric data processing. The authority also found that the university failed to carry out a proper Data Protection Impact Assessment (DPIA). | IT | Garante | GDPR | €50,000 | ↗ |
| 29 Jan 2026 | Ministero della CulturaMinistero della Cultura was fined EUR 12,000 by the Garante for using surveillance footage for disciplinary purposes without ensuring proper transparency toward visitors and employees. The authority found breaches of the GDPR and national data protection rules. | IT | Garante | GDPR | €12,000 | ↗ |
| 29 Jan 2026 | dott. Paolo MontemurroDott. Paolo Montemurro was fined 5,000 EUR by the Garante for posting photographs of a patient's surgical procedure on Instagram without consent. The authority found this breached GDPR principles of lawfulness, fairness, and transparency. | IT | Garante | GDPR | €5,000 | ↗ |
| 29 Jan 2026 | ASSOCIATION RELIGIEUSE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 10,000 on ASSOCIATION RELIGIEUSE (procédure simplifiée) and issued an injunction. The case concerned a confirmed breach of rules supervised by the CNIL. | FR | CNIL | GDPR | €10,000 | ↗ |