BULLETIN №084Last updated · 13 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -24%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 26 Feb 2026 | Dante Labs S.r.l.Dante Labs S.r.l. was fined EUR 600 by the Garante for failing to provide the results of a genetic test after receiving a customer's DNA sample. Despite multiple attempts by the customer to contact the company, the results were not delivered or explained. | IT | Garante | GDPR | €600 | ↗ |
| 26 Feb 2026 | Depac Società Cooperativa Sociale a r.l.Depac Società Cooperativa Sociale a r.l. was fined by the Garante EUR 15,000 for unauthorized processing of employees' biometric data. The case concerned the collection and storage of fingerprint data without proper consent or a valid legal basis. | IT | Garante | GDPR | €15,000 | ↗ |
| 26 Feb 2026 | Ciemme S.r.l.sThe Italian Data Protection Authority fined Ciemme S.r.l.s EUR 1,000 for failing to respond to a data subject request to exercise rights of access, erasure, and objection. The case arose after unsolicited marketing calls. | IT | Garante | GDPR | €1,000 | ↗ |
| 26 Feb 2026 | Ministero dell’Economia e delle FinanzeThe Ministry of Economy and Finance was fined 12,000 EUR by Garante for inadequate control measures over the data processor. The authority found breaches of GDPR Articles 3, 5 and 6, as well as Article 2-ter of the Italian Privacy Code. | IT | Garante | GDPR | €12,000 | ↗ |
| 26 Feb 2026 | Flamel S.r.l.Flamel S.r.l. was fined by the Garante 15,000 EUR for carrying out promotional activities without a legal basis. The company used phone numbers not registered with the ROC, affecting the data of more than 500 individuals. | IT | Garante | GDPR | €15,000 | ↗ |
| 26 Feb 2026 | Dedalus Italia S.p.A.Dedalus Italia S.p.A. was fined EUR 32,000 by the Garante for inadequate security measures that led to a data breach. The company implemented corrective actions promptly, but prior violations were taken into account when setting the penalty. | IT | Garante | GDPR | €32,000 | ↗ |
| 26 Feb 2026 | Istituto Tecnico Statale L. 80014050357Istituto Tecnico Statale was fined by the Garante for breaches of data protection principles, including lawfulness, fairness, transparency, and data minimization. The school improperly published personal data on its website. | IT | Garante | GDPR | €2,000 | ↗ |
| 27 Feb 2026 | T., za naruszenie art. 5 ust. 1 lit. f), art. 5 ust. 2 oraz art. 32 ust. 1 i 2 rozporządzenia 2016/679,The Polish DPA (UODO) imposed an administrative fine of PLN 975 on T. for failing to implement appropriate technical and organizational measures and for lacking a proper, accountable data protection policy tailored to its processing activities. The authority also noted deficiencies in transparency notices, processor agreements, access authorizations, and the record of processing activities. | PL | UODO | GDPR | €231 | ↗ |
| 02 Mar 2026 | Nordic Cleaning ApSThe Danish DPA reported Klein2 ApS and Nordic Cleaning ApS to the police for failing to comply with orders to address access requests. Nordic Cleaning ApS accepted a fine notice of 60,000 DKK. | DK | Datatilsynet | GDPR | €8,031 | ↗ |
| 05 Mar 2026 | ASSOCIATION AYANT POUR OBJET DE PROMOUVOIR L'ACCÈS AUX SOINS DENTAIRES DES PERSONNES DÉMUNIES (procédure simplifiée)The CNIL imposed an administrative fine of EUR 6,000 on ASSOCIATION AYANT POUR OBJET DE PROMOUVOIR L'ACCÈS AUX SOINS DENTAIRES DES PERSONNES DÉMUNIES and issued an injunction. The case was handled under a simplified procedure. | FR | CNIL | GDPR | €6,000 | ↗ |
| 05 Mar 2026 | Poczta Polska S.A.The President of the Polish Data Protection Authority imposed a fine of PLN 27,124,816 on Poczta Polska S.A. for processing personal data in connection with preparations for the presidential election at the prime minister's order. The Warsaw Regional Administrative Court overturned the decision on 2026-03-05. | PL | Prezes Urzędu Ochrony Danych Osobowych | GDPR | €6,348,000 | ↗ |
| 05 Mar 2026 | ASSOCIATION DE DÉFENSE DE DROITS FONDAMENTAUX(procédure simplifiée)CNIL imposed a EUR 5,100 penalty on ASSOCIATION DE DÉFENSE DE DROITS FONDAMENTAUX in connection with the liquidation of astreinte. The matter concerns enforcement of a prior obligation, with the amount arising from non-compliance. | FR | CNIL | GDPR | €5,100 | ↗ |
| 05 Mar 2026 | Altex România S.R.L.The National Supervisory Authority for Personal Data Processing imposed fines totaling EUR 8,000 on Altex România S.R.L. for GDPR violations. The case followed complaints from data subjects. | RO | ANSPDCP | GDPR | €8,000 | ↗ |
| 12 Mar 2026 | Enel Energia S.p.A.Enel Energia S.p.A. was fined by the Italian data protection authority, Garante, for making unwanted telemarketing calls without a proper legal basis. The authority found that the company’s conduct breached data protection principles. | IT | Garante | GDPR | €563,000 | ↗ |
| 12 Mar 2026 | Bakeca s.r.l.Bakeca s.r.l. was fined €5,000 by the Italian data protection authority, Garante. The case concerned the publication of online ads without the required consent, which breached data protection rules. | IT | Garante | GDPR | €5,000 | ↗ |
| 12 Mar 2026 | Comune di SutriComune di Sutri was fined EUR 2,000 by the Garante for publishing personal data on its institutional website. The case concerns a breach of data protection rules in the public online disclosure of information. | IT | Garante | GDPR | €2,000 | ↗ |
| 12 Mar 2026 | ITAS MutuaITAS Mutua was fined EUR 50,000 by the Garante for failing to adequately respond to a former employee’s request for access to personal data. The authority found a breach of GDPR Article 15. | IT | Garante | GDPR | €50,000 | ↗ |
| 12 Mar 2026 | Almas SalonThe Garante imposed an EUR 800 fine on Almas Salon for operating a video surveillance system without proper compliance with data protection rules. The case concerns a breach of GDPR Article 5, indicating failure to meet core data processing principles. | IT | Garante | GDPR | €800 | ↗ |
| 12 Mar 2026 | INPS – Istituto nazionale previdenza socialeThe Italian Data Protection Authority fined INPS EUR 40,000 for improperly displaying personal data of individuals residing in a care facility during an ISEE precompilation request. The authority found a breach of data protection principles. | IT | Garante | GDPR | €40,000 | ↗ |
| 12 Mar 2026 | Artemide S.r.l.s.Artemide S.r.l.s., the owner of MeridioNews.it, was fined 10,000 EUR by the Garante. The authority found that the company failed to properly handle a request to delete and de-index articles concerning judicial matters, thereby infringing data protection rights. | IT | Garante | GDPR | €10,000 | ↗ |