BULLETIN №083Last updated · 10 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.1%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 11 Jul 2024 | EOS MatrixAZOP imposed a EUR 5.47 million fine on EOS Matrix for a personal data protection breach following an incident involving the data of 181,641 debtors. The case was described as a GDPR violation and the largest fine in the authority's history. | HR | AZOP | GDPR | €5,470,000 | ↗ |
| 12 Jan 2023 | WhatsApp Ireland Ltd.The Irish DPC fined WhatsApp Ireland Ltd. EUR 5,500,000 in case IN-18-5-6. The decision is currently under appeal. | IE | DPC | GDPR | €5,500,000 | ↗ |
| 02 Feb 2017 | Sigue Global Service LimitedSigue Global Service Limited was fined by the Garante 5,880,000 EUR for breaches of data protection rules and anti-money laundering requirements. The authority cited money transfers carried out without proper consent, techniques used to obscure the true origin of funds, and non-compliance with AML obligations. | IT | Garante | GDPR | €5,880,000 | ↗ |
| 16 Mar 2026 | Restaurant Partner PolskaThe Polish Data Protection Authority imposed an administrative fine of PLN 5,898,064 on Restaurant Partner Polska, the operator of Glovo in Poland. The authority found that the company unlawfully collected and processed scans and photos of users’ identity documents, in breach of GDPR requirements. | PL | Urząd Ochrony Danych Osobowych | GDPR | €1,381,000 | ↗ |
| 19 Feb 2026 | Dane anonimowe (W.)UODO imposed an administrative fine of PLN 5,898,064 on Dane anonimowe (W.). The authority found that the company processed personal data without a legal basis and in a manner that was excessive and disproportionate to the stated purpose, including by collecting photos or scans of identity cards or passports. | PL | UODO | GDPR | €1,397,000 | ↗ |
| 26 Feb 2025 | SportadminIMY fined Sportadmin SEK 6 million after an IT attack exposed personal data of more than 2.1 million individuals, mostly children. The authority found that the company had not maintained an appropriate security level for the personal data it processed. | SE | Integritetsskyddsmyndigheten | GDPR | €538,000 | ↗ |
| 01 Jan 2022 | CosmoteThe Greek data protection authority imposed a €6 million fine on Cosmote under decision 4/2022. The sanction concerned inadequate security measures and retaining more data than permitted after a 2020 cyberattack. | GR | Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα | GDPR | €6,000,000 | ↗ |
| 17 Jun 2024 | FÚTBOL CLUB BARCELONAFútbol Club Barcelona was fined by the AEPD for processing biometric data without explicit consent during a mandatory member census update. The authority found breaches of GDPR Articles 9 and 35, relating to special-category data processing and data protection impact assessment requirements. | ES | AEPD | GDPR | €6,000,000 | ↗ |
| 26 Aug 2020 | Anonymizováno (ÚOOÚ UOOU-03916/19-49)The entity was fined for sending unsolicited commercial communications without a valid legal basis. The conduct violated the Czech law on certain information society services. | CZ | UOOU | ePrivacy | €228,000 | ↗ |
| 26 Jan 2026 | SportAdmin i Skandinavien ABSportAdmin i Skandinavien AB was fined by IMY 6,000,000 SEK for failing to implement appropriate technical and organizational measures to ensure an adequate level of security for personal data. The deficiency resulted in a data breach. | SE | IMY | GDPR | €564,000 | ↗ |
| 01 Dec 2023 | ENDESA, S.A.The Spanish data protection authority imposed a EUR 6.1 million fine on ENDESA in December 2023. The case involved a security breach that led to the sale of customer personal data through Facebook ads. | ES | Agencia Española de Protección de Datos | GDPR | €6,100,000 | ↗ |
| 05 Feb 2026 | Dane anonimowe (X.)UODO imposed an administrative fine of PLN 6,251,471 on Dane anonimowe (X.) for breaching Article 28(3) GDPR. The company used external transport providers without prior data processing agreements and without implementing adequate organizational measures to ensure data security. | PL | UODO | GDPR | €1,481,000 | ↗ |
| 06 Jun 2024 | Eni Plenitude S.p.A. Società BenefitEni Plenitude S.p.A. was fined by the Garante 6,419,631 EUR for making unsolicited promotional calls without prior consent. The company also used numbers listed in the Public Opposition Register, which constituted a breach of GDPR rules. | IT | Garante | GDPR | €6,419,000 | ↗ |
| 01 Jan 2023 | PHONE HOUSEPHONE HOUSE was fined by the AEPD for failing to ensure data integrity and confidentiality. The breach resulted in a data incident caused by a cyberattack. | ES | AEPD | GDPR | €6,500,000 | ↗ |
| 01 Feb 2019 | CAIXABANK, S.A.CAIXABANK was fined by the AEPD for introducing new data protection conditions that required consent for sharing data within its group. The authority found the measure disproportionate and lacking a proper legal basis. | ES | AEPD | GDPR | €6,500,000 | ↗ |
| 17 Apr 2026 | Poste Italiane S.p.a. e PostePay S.p.a.Poste Italiane S.p.a. and PostePay S.p.a. were sanctioned for unlawful processing of personal data in their Bancoposta and PostePay apps on Android devices. The apps required users to authorize access to data to detect malicious software, which breached GDPR principles. | IT | Garante | GDPR | €6,624,000 | ↗ |
| 15 May 2026 | Unnamed Hungarian employerHungary’s data protection authority, NAIH, imposed a HUF 7 million GDPR fine on an unnamed employer. The case involved continuous camera monitoring in employee dining and rest areas, as well as deficiencies in documentation and privacy notices. | HU | Nemzeti Adatvédelmi és Információszabadság Hatóság | GDPR | €19,460 | ↗ |
| 02 Aug 2022 | Oraculum 2020 Korlátolt Felelősségű TársaságNAIH fined Oraculum 2020 Kft. and SzondaPhone Kft. for unlawful data processing during telephone surveys. The authority found breaches of GDPR principles of lawfulness, transparency, data minimization, and accountability. | HU | NAIH | GDPR | €17,640 | ↗ |
| 28 Mar 2022 | Klarna Bank AB, bristande informationKlarna Bank AB was fined by IMY SEK 7.5 million for failing to provide adequate information on the purposes and legal basis for processing personal data. The authority also found incomplete and misleading information about data recipients and automated decision-making. | SE | IMY | GDPR | €719,000 | ↗ |
| 27 Apr 2020 | Hungária Med-M Kereskedelmi és Szolgáltató Korlátolt Felelősségű TársaságThe company failed to implement adequate security measures, report a data breach, and notify affected individuals in a timely manner. NAIH found violations of GDPR Articles 32, 33, and 34. | HU | NAIH | GDPR | €21,150 | ↗ |