BULLETIN №084Last updated · 14 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -24%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 12 Mar 2026 | Domiziana GiorgianniThe Garante imposed a EUR 2,000 fine on Domiziana Giorgianni for failing to implement adequate technical and organizational measures to support data subject rights. The authority also found that requests were not handled without undue delay. | IT | Garante | GDPR | €2,000 | ↗ |
| 12 Mar 2026 | Liceo Scientifico MorgagniLiceo Scientifico Morgagni was fined by the Garante for violations related to the processing of sensitive data. The authority cited inadequate security measures in the protection of those data. | IT | Garante | GDPR | €2,000 | ↗ |
| 12 Mar 2026 | La7 S.p.A.La7 S.p.A. was fined 40,000 EUR by the Garante for broadcasting personal data, including phone numbers and names, during a news segment. The authority found a breach of GDPR Article 5 on data processing principles. | IT | Garante | GDPR | €40,000 | ↗ |
| 12 Mar 2026 | SOCIÉTÉ EXERÇANT UNE ACTIVITÉ DE VENTE À DISTANCE SUR CATALOGUE SPECIALISÉE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 5,000 on Société exerçant une activité de vente à distance sur catalogue spécialisée. The case was handled under a simplified procedure. | FR | CNIL | GDPR | €5,000 | ↗ |
| 12 Mar 2026 | Hanako s.r.l.Hanako s.r.l. was fined by the Garante EUR 2,000 for operating a video surveillance system without ensuring GDPR compliance. The authority cited inadequate security measures and failure to provide sufficient information to employees. | IT | Garante | GDPR | €2,000 | ↗ |
| 16 Mar 2026 | Restaurant Partner PolskaThe Polish Data Protection Authority imposed an administrative fine of PLN 5,898,064 on Restaurant Partner Polska, the operator of Glovo in Poland. The authority found that the company unlawfully collected and processed scans and photos of users’ identity documents, in breach of GDPR requirements. | PL | Urząd Ochrony Danych Osobowych | GDPR | €1,381,000 | ↗ |
| 19 Mar 2026 | HafnarfjarðarbærHafnarfjarðarbær was fined for using Google Workspace for Education in schools without full compliance with data protection rules. The authority cited unclear processing purposes and delayed data protection impact assessments. | IS | Persónuvernd | GDPR | €19,516 | ↗ |
| 19 Mar 2026 | GarðabærGarðabær was fined for multiple data protection violations in its use of Google Workspace for Education without ensuring GDPR compliance. The case concerned the processing of children's personal data, which required additional safeguards and a proper legal basis. | IS | Persónuvernd | GDPR | €17,425 | ↗ |
| 19 Mar 2026 | KópavogsbærKópavogsbær was fined by Persónuvernd for using Google Workspace for Education in schools without full compliance with data protection rules. The authority cited, among other issues, the absence of a data protection impact assessment and unclear processing purposes. | IS | Persónuvernd | GDPR | €20,910 | ↗ |
| 19 Mar 2026 | ReykjavíkurborgReykjavíkurborg was fined by Persónuvernd for using Google Workspace for Education in schools without meeting GDPR requirements. The case concerned the processing of children's personal data, which required heightened compliance and safeguards. | IS | Persónuvernd | GDPR | €13,940 | ↗ |
| 20 Mar 2026 | Domeniul Public și Privat SADomeniul Public și Privat SA was fined 2,000 EUR by ANSPDCP for GDPR violations. The case concerned non-compliance with personal data protection requirements. | RO | ANSPDCP | GDPR | €2,000 | ↗ |
| 20 Mar 2026 | Domeniul Public și Privat SADomeniul Public și Privat SA was fined EUR 1,000 for breaching Article 15 of the GDPR. The case concerned improper handling of data subject access rights. | RO | ANSPDCP | GDPR | €1,000 | ↗ |
| 20 Mar 2026 | Jogalap nélküli hozzáférés az EESZT rendszeréhez és hozzáférési kérelem nemteljesítéseThe supervisory authority imposed a fine for processing personal data without a lawful basis, including health data. It also found failure to comply with an access request, which breaches GDPR obligations. | HU | NAIH | GDPR | €1,275 | ↗ |
| 23 Mar 2026 | ING Bank NV Amsterdam – Sucursala București S.A.The fine was imposed for failing to implement adequate technical and organizational measures to ensure the confidentiality of personal data. As a result, an unauthorized third party received a bank account statement. | RO | ANSPDCP | GDPR | €4,000 | ↗ |
| 24 Mar 2026 | SIA "Fitsypro"SIA "Fitsypro" was fined EUR 1,500 by the DVI. The decision has entered into force. | LV | DVI | GDPR | €1,500 | ↗ |
| 26 Mar 2026 | Esselunga S.p.A.Esselunga S.p.A. was fined EUR 5,000 by the Italian supervisory authority, Garante. The case concerned a failure to respond to a data access request under Article 15 GDPR, including access to employee attendance records. | IT | Garante | GDPR | €5,000 | ↗ |
| 26 Mar 2026 | Euro Bangla MinimarketThe Garante fined Euro Bangla Minimarket EUR 1,000 for improper use of a video surveillance system. Images from six cameras were visible to everyone on a monitor in the store, which breached GDPR requirements. | IT | Garante | GDPR | €1,000 | ↗ |
| 26 Mar 2026 | SOCIÉTÉ EXERÇANT UNE ACTIVITÉ D'ARTS DU SPECTACLE VIVANT (procédure simplifiée)CNIL imposed a fine of 850 EUR on SOCIÉTÉ EXERÇANT UNE ACTIVITÉ D'ARTS DU SPECTACLE VIVANT in connection with the liquidation of astreinte. The case concerns compliance with a prior obligation under a simplified procedure. | FR | CNIL | GDPR | €850 | ↗ |
| 26 Mar 2026 | Provvedimento del 26 marzo 2026 [10246060]The entity was fined for operating a video surveillance system without providing adequate informational signage. The authority found this to be a breach of GDPR Article 13 on the duty to inform data subjects. | IT | Garante | GDPR | €2,000 | ↗ |
| 26 Mar 2026 | Copacabana s.r.l.Copacabana s.r.l. was fined EUR 2,000 by the Garante for installing a video surveillance system without the required informational signage and necessary authorization. The authority cited a breach of GDPR Article 13. | IT | Garante | GDPR | €2,000 | ↗ |