BULLETIN №084Last updated · 12 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 11 Sept 2014 | Alabarda Gestioni s.r.l.Alabarda Gestioni s.r.l. was fined by the Garante 2,400 EUR for processing personal data related to job applications without providing the required information notice. This breached Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 18 Jun 2025 | Aktiebolaget Storstockholms Lokaltrafik (SL)Aktiebolaget Storstockholms Lokaltrafik (SL) was fined 75,000 SEK by IMY for processing personal data without a legal basis and special-category data without a valid exception. The authority found breaches of GDPR Articles 6 and 9. | SE | IMY | GDPR | €6,802 | ↗ |
| 28 Oct 2025 | Aktia PankkiThe sanction panel of the Finnish Data Protection Ombudsman’s Office imposed an EUR 865,000 fine on Aktia Pankki for deficiencies in information security in its strong electronic identification service. The incident caused some users to see other customers’ data in services requiring strong authentication. | FI | Tietosuojavaltuutetun toimisto | GDPR | €865,000 | ↗ |
| 11 Feb 2025 | A követeléskezelő társaságNAIH imposed a HUF 10 million fine on a debt collection company for continuing to process personal data after a court declared the debt time-barred. The company ignored the data subject’s deletion request and kept the case active in its system. | HU | Nemzeti Adatvédelmi és Információszabadság Hatóság | GDPR | €24,800 | ↗ |
| 22 Feb 2024 | Airone società consortile a r.l.Airone società consortile a r.l. was fined EUR 5,000 by Garante for unlawfully processing biometric data through facial recognition to monitor employee attendance. The authority found that the same purpose could have been achieved by less intrusive means. | IT | Garante | GDPR | €5,000 | ↗ |
| 11 Apr 2025 | AIRE NETWORKS DEL MEDITERRÁNEO, S.L.The AEPD fined AIRE NETWORKS DEL MEDITERRÁNEO, S.L. 100,000 EUR for a data security incident. A SIM card duplication enabled unauthorized bank transactions, indicating insufficient safeguards and access controls. | ES | AEPD | GDPR | €100,000 | ↗ |
| 20 Nov 2014 | Aimon s.r.l.Aimon s.r.l. was fined EUR 32,000 by the Garante for sharing customers’ personal data with various companies without proper notice and consent. The authority found that the conduct breached privacy rules. | IT | Garante | GDPR | €32,000 | ↗ |
| 10 Jun 2021 | aiComply S.r.l.aiComply S.r.l. was fined by the Garante in the amount of EUR 20,000 for failing to implement adequate security measures. In particular, it did not use a secure network protocol, which created a risk to the confidentiality and integrity of personal data. | IT | Garante | GDPR | €20,000 | ↗ |
| 27 Jun 2023 | A.I.C. ehf.A.I.C. ehf. was fined by Persónuvernd 3,500,000 ISK for registering loan defaults with Creditinfo Lánstraust hf. without meeting the required registration conditions. The case also involved defaults on loans below the minimum threshold for registration. | IS | Persónuvernd | GDPR | €23,520 | ↗ |
| 18 Jun 2019 | A hozzáférési kérelem pontosítása; a hozzáférési kérelem elektronikus formában való teljesítéseThe controller did not facilitate the data subject’s right of access. It also failed to provide complete information about the personal data processed, including how to access files stored on a DVD. | HU | NAIH | GDPR | €1,550 | ↗ |
| 04 Sept 2024 | Agrotikos Elaiourgikos Synetairismos StylidasAgrotikos Elaiourgikos Synetairismos Stylidas was fined EUR 2,000 by the HDPA. The authority found breaches of data minimization and transparency principles, as well as inadequate technical and organizational measures in its video surveillance system. | GR | HDPA | GDPR | €2,000 | ↗ |
| 08 May 2013 | Agro Informatica di Buracchi GinoAgro Informatica di Buracchi Gino was fined 32,000 EUR by the Garante for sending unsolicited promotional emails without prior explicit consent. The authority also found that the required privacy notice was not provided, in breach of the Italian Data Protection Code. | IT | Garante | GDPR | €32,000 | ↗ |
| 23 Jul 2025 | Agricola International SAAgricola International SA was fined EUR 5,000 by ANSPDCP for a data security breach. The incident was reported by the company itself, indicating an internally detected event that required compliance review. | RO | ANSPDCP | GDPR | €5,000 | ↗ |
| 12 Oct 2016 | AG Preziosi Banco Metalli s.r.l.AG Preziosi Banco Metalli s.r.l. was fined by the Garante for collecting personal data through a website contact form without providing the required privacy notice. This constituted a breach of Article 13 of the Italian Privacy Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 04 Sept 2025 | A*** GmbHA*** GmbH did not report a personal data breach to the Austrian Data Protection Authority within the 72-hour deadline required by Article 33 GDPR. As a result, a fine of EUR 870 was imposed. | AT | DSB | GDPR | €870 | ↗ |
| 12 Feb 2021 | A*** GmbHA*** GmbH was fined by the Austrian Data Protection Authority for failing to cooperate in three separate complaint procedures. The authority found a breach of Article 31 GDPR, which requires cooperation with the supervisory authority. | AT | DSB | GDPR | €3,000 | ↗ |
| 28 May 2026 | AgID – Agenzia per l’Italia digitaleThe Italian Data Protection Authority fined AgID €55,000 for failing to adequately inform professionals about the automatic registration of their digital domiciles. The authority found breaches of transparency and data processing principles. | IT | Garante | GDPR | €55,000 | ↗ |
| 08 Feb 2024 | Agenzia territoriale della Regione Puglia per il servizio di gestione dei rifiuti (AGER)The Garante fined Agenzia territoriale della Regione Puglia per il servizio di gestione dei rifiuti (AGER) EUR 6,000. The authority found that the organization failed to appoint a Data Protection Officer in a timely manner, despite the GDPR requirement being in force for about three years. | IT | Garante | GDPR | €6,000 | ↗ |
| 14 Jan 2021 | Agenzia regionale protezione ambientale Campania (ARPAC)ARPAC was fined by the Garante EUR 8,000 for violations concerning data security measures and data breach notification obligations. The case involved non-compliance with GDPR Articles 5 and 32. | IT | Garante | GDPR | €8,000 | ↗ |
| 10 Mar 2022 | Agenzia Regionale per la Tutela dell'Ambiente dell'AbruzzoThe Regional Agency for Environmental Protection of Abruzzo was fined by the Garante €8,000 for breaches of data protection principles. The violations concerned lawfulness, fairness, transparency, and data minimization. | IT | Garante | GDPR | €8,000 | ↗ |