BULLETIN №084Last updated · 13 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -24%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 12 Feb 2026 | Velletri ServiziVelletri Servizi was fined EUR 2,500 by the Garante for inadequate technical and organizational measures in data processing. The authority found that the company did not meet the requirements of GDPR Article 32. | IT | Garante | GDPR | €2,500 | ↗ |
| 12 Feb 2026 | Ordine dei Medici Chirurghi e degli Odontoiatri della Provincia di MacerataOrdine dei Medici Chirurghi e degli Odontoiatri della Provincia di Macerata was fined EUR 4,000 by the Garante. The authority found breaches of the principles of lawfulness, fairness, transparency, and data minimization. The case indicates non-compliance with core GDPR processing requirements. | IT | Garante | GDPR | €4,000 | ↗ |
| 12 Feb 2026 | Based s.r.l.Based s.r.l. was fined by the Garante EUR 12,000 for providing an inadequate response to a data subject’s request for access to and deletion of email account data. The authority found that the company failed to comply with GDPR requirements on data subject rights. | IT | Garante | GDPR | €12,000 | ↗ |
| 12 Feb 2026 | Bressanelli Galli Gelpi Porta & C. S.r.l.The company was fined EUR 15,000 by the Garante for sending promotional emails without prior consent from recipients. The authority found this to be a breach of GDPR principles, including Article 5. | IT | Garante | GDPR | €15,000 | ↗ |
| 12 Feb 2026 | Anconambiente S.P.A.Anconambiente S.P.A. was fined by the Garante for failing to ensure that personal data processing was lawful, fair, and transparent. The authority also found that the company did not have a proper contract with a data processor, as required by Article 28 GDPR. | IT | Garante | GDPR | €2,500 | ↗ |
| 13 Feb 2026 | Dane anonimowe (Komitet Wyborczy Kandydata na Prezydenta Rzeczypospolitej Polskiej M. W.)UODO imposed a fine of 35,582 PLN on the Election Committee of Presidential Candidate M. W. The authority found that campaign activities infringed the privacy of other individuals by using their personal data. The right to present truthful information about a candidate does not justify such processing. | PL | UODO | GDPR | €8,442 | ↗ |
| 16 Feb 2026 | KONECTA BTO, S.L.KONECTA BTO, S.L. was fined by the AEPD EUR 500,000 for a personal data breach. The case involved unauthorized access to personal data, which breached the confidentiality principle under Article 5(1)(f) of the GDPR. | ES | AEPD | GDPR | €500,000 | ↗ |
| 18 Feb 2026 | ALÍA GESTIÓN INTEGRAL DE SERVICIOS, S.L.ALÍA GESTIÓN INTEGRAL DE SERVICIOS, S.L. was fined EUR 250,000 by the AEPD for a data protection breach. The incident involved unauthorized access to the internal network after VPN credentials were compromised. | ES | AEPD | GDPR | €250,000 | ↗ |
| 19 Feb 2026 | Hrvatska agencija za nekretnineAZOP imposed an administrative fine of EUR 100,000 on a Croatian real estate agency for GDPR breaches. The authority found unlawful retention of personal data of 11,887 clients after the processing purpose had expired, processing without a legal basis, and inadequate technical and organizational measures. | HR | AZOP | GDPR | €100,000 | ↗ |
| 19 Feb 2026 | Dane anonimowe (W.)UODO imposed an administrative fine of PLN 5,898,064 on Dane anonimowe (W.). The authority found that the company processed personal data without a legal basis and in a manner that was excessive and disproportionate to the stated purpose, including by collecting photos or scans of identity cards or passports. | PL | UODO | GDPR | €1,397,000 | ↗ |
| 20 Feb 2026 | Szegedi TudományegyetemSzegedi Tudományegyetem was fined HUF 2,000,000 by NAIH for GDPR breaches in data processing related to dormitory admissions. The authority found a lack of proper legal basis, insufficient transparency, and failure to respect data minimization. | HU | NAIH | GDPR | €5,260 | ↗ |
| 20 Feb 2026 | VodafoneThe Greek Data Protection Authority fined Vodafone EUR 30,000 for GDPR breaches related to a subscriber’s request to access recorded phone conversations. The authority found violations of transparency obligations under Article 12 and of the rights of access and restriction of processing under Articles 15 and 18 GDPR. | GR | Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα | GDPR | €30,000 | ↗ |
| 21 Feb 2026 | VERTI ASEGURADORA, COMPAÑÍA DE SEGUROS Y REASEGUROS, S.A.VERTI Aseguradora was fined by the AEPD €5,000 for sending promotional emails without providing a simple and free way for recipients to opt out. The authority found this to be a breach of Article 21.2 of the LSSI. | ES | AEPD | ePrivacy | €5,000 | ↗ |
| 23 Feb 2026 | Reddit, Inc.The ICO imposed a penalty of 14,472,500 GBP on Reddit, Inc. for breaches of Articles 5(1)(a), 6, 8, and 35 of the UK GDPR. The case concerned unlawful personal data processing and failures to implement appropriate safeguards and a data protection impact assessment. | GB | ICO | GDPR | €16,571,000 | ↗ |
| 24 Feb 2026 | SIA Izdevniecība “DIENAS ŽURNĀLI”A fine of EUR 500 was imposed. The decision is final and has entered into force. | LV | DVI | GDPR | €500 | ↗ |
| 24 Feb 2026 | Reddit, Inc.The ICO imposed a GBP 14.5 million UK GDPR fine on Reddit, Inc. for failures related to age-gating and the protection of children’s data. The matter was initially misfiled as an enforcement notice and later refiled as a monetary penalty notice. | GB | Information Commissioner's Office | GDPR | €16,606,000 | ↗ |
| 26 Feb 2026 | Groupharma s.r.l.s.Groupharma s.r.l.s. was fined EUR 3,000 by the Italian supervisory authority, Garante. The case concerned the company’s failure to respond to a former employee’s request to access and delete personal data, including photos and contact details, from its website after employment ended. | IT | Garante | GDPR | €3,000 | ↗ |
| 26 Feb 2026 | Ministero delle Imprese e del Made in ItalyMinistero delle Imprese e del Made in Italy was fined by the Garante €15,000 for unlawfully publishing personal data in a ranking list. The authority found breaches of data minimization and transparency principles. | IT | Garante | GDPR | €15,000 | ↗ |
| 26 Feb 2026 | Conservatorio “XX” di XXThe Garante fined Conservatorio “XX” di XX EUR 5,000 for processing personal data relating to criminal convictions without a valid legal basis. The authority found breaches of the GDPR and the national privacy code. | IT | Garante | GDPR | €5,000 | ↗ |
| 26 Feb 2026 | Radio Immagine Uno S.r.l.The Garante imposed a €10,000 fine on Radio Immagine Uno S.r.l. for failing to respond to a data subject's request to remove an online article containing personal data. The company did not comply with the right to be forgotten, resulting in a data protection breach. | IT | Garante | GDPR | €10,000 | ↗ |