BULLETIN №084Last updated · 13 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -24%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 05 Feb 2026 | Dane anonimowe (X.)UODO imposed an administrative fine of PLN 6,251,471 on Dane anonimowe (X.) for breaching Article 28(3) GDPR. The company used external transport providers without prior data processing agreements and without implementing adequate organizational measures to ensure data security. | PL | UODO | GDPR | €1,481,000 | ↗ |
| 05 Feb 2026 | Gemeente DelftGemeente Delft processed personal data without a sufficient legal basis. It also processed special categories of personal data without a valid exception, breaching GDPR principles. | NL | AP | GDPR | €25,000 | ↗ |
| 05 Feb 2026 | MÉDECIN (procédure simplifiée)The CNIL imposed EUR 1,000 on MÉDECIN (simplified procedure) as a liquidation of an astreinte. The case concerns compliance with a prior obligation set by the supervisory authority. | FR | CNIL | GDPR | €1,000 | ↗ |
| 05 Feb 2026 | Gemeente HilversumThe Autoriteit Persoonsgegevens found that Gemeente Hilversum processed personal data without a valid legal basis during an investigation into Muslim residents and organizations. The municipality accepted an administrative fine of 25,000 EUR and acknowledged responsibility. | NL | Autoriteit Persoonsgegevens | GDPR | €25,000 | ↗ |
| 10 Feb 2026 | Dane anonimowe (R.)The UODO imposed a PLN 6,700 fine on Anonymous data (R.) for failing to notify a personal data breach within 72 hours and for not informing affected individuals without undue delay. The authority also found deficiencies in the appointment of the data protection officer, including missing contact details, failure to notify the supervisory authority, and a conflict of interest because the role was assigned to a board member. | PL | UODO | GDPR | €1,589 | ↗ |
| 12 Feb 2026 | Sportitalia Società Sportiva Dilettantistica a.r.l.Sportitalia Società Sportiva Dilettantistica a.r.l. was fined EUR 30,000 by the Garante for violations related to the processing of personal data in promotional emails. The authority found that the company did not comply with GDPR requirements in connection with these marketing communications. | IT | Garante | GDPR | €30,000 | ↗ |
| 12 Feb 2026 | Comune di AnconaThe Garante fined Comune di Ancona EUR 3,000 for failing to ensure lawful, fair, and transparent processing of personal data. The authority also found that no proper contract was in place with a data processor, in breach of GDPR Articles 5 and 28. | IT | Garante | GDPR | €3,000 | ↗ |
| 12 Feb 2026 | Conversion Media S.r.l.Conversion Media S.r.l. was fined EUR 10,000 by the Garante for failing to meet data protection obligations. The case concerned telemarketing activities in which required transparency and information duties toward data subjects were not fulfilled. | IT | Garante | GDPR | €10,000 | ↗ |
| 12 Feb 2026 | Comune di AversaThe Garante fined Comune di Aversa 3,000 EUR for failing to communicate the contact details of the Data Protection Officer. The case concerns Article 37 GDPR and the obligation to make DPO contact information available. | IT | Garante | GDPR | €3,000 | ↗ |
| 12 Feb 2026 | Provvedimento del 12 febbraio 2026 [10225084]The Garante fined a retail business for failing to provide adequate informational signage for its video surveillance system. The authority found a breach of data protection rules because individuals on the premises were not properly informed about the processing of their personal data. | IT | Garante | GDPR | €2,000 | ↗ |
| 12 Feb 2026 | Comune di Mazara del ValloComune di Mazara del Vallo was fined EUR 4,000 by the Garante for breaches of data protection principles. The authority found that the municipality failed to provide adequate information to data subjects and did not carry out a data protection impact assessment for its video surveillance system. | IT | Garante | GDPR | €4,000 | ↗ |
| 12 Feb 2026 | Provvedimento del 12 febbraio 2026 [10225110]The Garante imposed a EUR 1,000 fine for using a video surveillance system without providing the required information notice to data subjects. The case concerned a breach of GDPR transparency obligations. | IT | Garante | GDPR | €1,000 | ↗ |
| 12 Feb 2026 | Comune di CoccaglioComune di Coccaglio was fined EUR 6,000 for using surveillance footage for disciplinary purposes without informing employees. The authority also found that no data protection impact assessment had been carried out, in breach of data protection rules. | IT | Garante | GDPR | €6,000 | ↗ |
| 12 Feb 2026 | Depurazione Acqua S.r.l.Depurazione Acqua S.r.l. was fined by the Garante for carrying out promotional activities without a valid legal basis. The case concerns GDPR breaches related to data processing and consent. | IT | Garante | GDPR | €15,000 | ↗ |
| 12 Feb 2026 | Unleadmited S.r.l.Unleadmited S.r.l. was fined EUR 5,000 by the Garante for violations linked to aggressive telemarketing practices. The authority found non-compliance with data protection requirements. | IT | Garante | GDPR | €5,000 | ↗ |
| 12 Feb 2026 | Acea Energia S.p.A.Acea Energia S.p.A. was fined by the Garante 2,000,000 EUR for processing inaccurate and outdated personal data of customers. This led to the activation of unsolicited energy supply contracts, indicating significant deficiencies in data quality controls. | IT | Garante | GDPR | €2,000,000 | ↗ |
| 12 Feb 2026 | Ristorante pizzeria CN 45The Garante fined Ristorante pizzeria CN 45 2,000 EUR for operating a video surveillance system without proper compliance. The case concerns GDPR breaches related to the lawful operation and implementation of CCTV monitoring. | IT | Garante | GDPR | €2,000 | ↗ |
| 12 Feb 2026 | Klab s.r.l.Klab s.r.l. was fined by the Garante in the amount of 1,000 EUR for failing to obtain valid consent for marketing purposes. The authority also found that the company did not provide adequate information about the legal basis for data processing, in breach of GDPR requirements. | IT | Garante | GDPR | €1,000 | ↗ |
| 12 Feb 2026 | Provvedimento del 12 febbraio 2026 [10226120]The Garante imposed a fine of EUR 1,500 for unlawful processing of personal data through a video surveillance system at a commercial establishment. The cameras captured public streets and private residences, and the data subjects were not properly notified. | IT | Garante | GDPR | €1,500 | ↗ |
| 12 Feb 2026 | Lex Iuris S.r.l.Lex Iuris S.r.l. was fined by the Garante in the amount of 15,000 EUR for sending unsolicited promotional emails. The authority also found that the company failed to respond to data access requests, breaching transparency and data subject rights obligations. | IT | Garante | GDPR | €15,000 | ↗ |