BULLETIN №083Last updated · 10 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.1%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 15 Nov 2019 | Raiffeisen Bank Zrt.Raiffeisen Bank Zrt. was fined by the NAIH 25,000,000 HUF for processing personal data of non-advisory service clients without a legal basis. The authority also found that the bank failed to provide adequate information about the processing of personal data collected through MiFID questionnaires. | HU | NAIH | GDPR | €74,750 | ↗ |
| 16 Dec 2021 | Enel Energia S.p.a.Enel Energia S.p.a. was investigated for improper promotional contacts, including contacts to individuals with reserved numbers or registered in the ROP. The authority also challenged making access to online services conditional on consent to marketing and profiling. | IT | Garante | GDPR | €26,513,000 | ↗ |
| 08 Jan 2026 | OPÉRATEUR DE TÉLÉPHONIE MOBILECNIL imposed an administrative fine of EUR 27 million on OPÉRATEUR DE TÉLÉPHONIE MOBILE and issued an injunction. The case concerns a regulatory breach addressed by the authority’s decision. | FR | CNIL | GDPR | €27,000,000 | ↗ |
| 05 Mar 2026 | Poczta Polska S.A.The President of the Polish Data Protection Authority imposed a fine of PLN 27,124,816 on Poczta Polska S.A. for processing personal data in connection with preparations for the presidential election at the prime minister's order. The Warsaw Regional Administrative Court overturned the decision on 2026-03-05. | PL | Prezes Urzędu Ochrony Danych Osobowych | GDPR | €6,348,000 | ↗ |
| 27 Feb 2020 | Tim S.p.A.The Italian data protection authority imposed a EUR 27.8 million fine on Tim S.p.A. The case concerned privacy violations in marketing and telemarketing activities, including issues with obtaining valid consent. | IT | Garante per la protezione dei dati personali | GDPR | €27,800,000 | ↗ |
| 04 Jun 2025 | Noi Compriamo Auto.it S.r.l.On 4 June 2025, the Italian Data Protection Authority fined Noi Compriamo Auto.it S.r.l. for GDPR breaches in email marketing. The authority found that the company sent promotional emails without consent, failed to properly govern its processors, and did not adequately support data subject rights. | IT | Garante per la protezione dei dati personali | GDPR | €27,800,000 | ↗ |
| 15 Jan 2020 | TIM S.p.A.TIM S.p.A. was fined by the Garante for making unauthorized promotional calls. The authority found that the company failed to ensure adequate consent and accountability measures under data protection rules. | IT | Garante | GDPR | €27,802,000 | ↗ |
| 24 Jun 2025 | OLXUOKiK imposed a PLN 28.4 million fine on OLX for irregularities in its ratings system that could mislead consumers. The decision was not yet final, as OLX could appeal. | PL | Urząd Ochrony Konkurencji i Konsumentów | Omnibus | €6,676,000 | ↗ |
| 23 May 2019 | Sziget Kulturális Menedzser Iroda Zártkörűen Működő RészvénytársaságThe NAIH fined Sziget Zrt. HUF 30,000,000 for unlawful data processing linked to event entry management. The authority found no proper legal basis and insufficient information provided to data subjects. | HU | NAIH | GDPR | €91,800 | ↗ |
| 02 Aug 2022 | BankThe Bank and the Mortgage Bank processed personal data for credit assessment without a legal basis. They also failed to provide adequate information required under the GDPR. | HU | NAIH | GDPR | €75,600 | ↗ |
| 12 Sept 2022 | Magyar Éremkibocsátó Kft.The Hungarian data protection authority, NAIH, imposed a fine of 30,000,000 HUF on Magyar Éremkibocsátó Kft. The authority found that personal data were processed without a proper legal basis, specific purpose, or valid consent, and that GDPR transparency and information obligations were breached. | HU | NAIH | GDPR | €75,900 | ↗ |
| 02 Dec 2020 | Capio S:t Görans Sjukhus ABCapio S:t Görans Sjukhus AB was fined by IMY for processing personal data in breach of GDPR. The authority found inadequate needs and risk analyses and insufficient restriction of user access to patient data in the journal systems. | SE | IMY | GDPR | €2,917,000 | ↗ |
| 06 Feb 2023 | I&S Limited Kft.I&S Limited Kft. was fined by NAIH for continuous recording of work activities and monitoring guests, as well as for misleading information about data processing. The authority also found unauthorized processing of health data for marketing purposes. | HU | NAIH | GDPR | €76,800 | ↗ |
| 03 Sept 2024 | Clearview AI Inc.Clearview AI Inc. was fined by the Dutch data protection authority AP for processing personal data without a legal basis, including biometric data. The authority also cited inadequate notice to data subjects, failure to respond to access requests, and failure to appoint an EU representative. | NL | AP | GDPR | €30,500,000 | ↗ |
| 12 Jan 2026 | Zalando SEThe President of UOKiK imposed a fine of PLN 30,945,000 on Zalando SE for failing to provide the lowest price from the 30 days before a discount and for misleading discount presentation. The decision concerns consumer protection and is not yet final. | PL | UOKiK | Omnibus | €7,351,000 | ↗ |
| 14 Jan 2026 | ZalandoUOKiK imposed a fine on Zalando for misleading consumers by improperly presenting promotional prices and hiding the required lowest price from the previous 30 days. According to the report, the combined sanctions against Zalando and Temu were about PLN 37 million, with Zalando accounting for PLN 31,488,674. | PL | Urząd Ochrony Konkurencji i Konsumentów | Other | €7,465,000 | ↗ |
| 30 Apr 2026 | Intesa SanpaoloItaly’s data protection authority, Garante, fined Intesa Sanpaolo EUR 31.8 million. The sanction concerned serious failures in security and access management for personal data. | IT | Garante per la protezione dei dati personali | GDPR | €31,800,000 | ↗ |
| 27 Dec 2023 | SOCIETE DE SUPPORT LOGISTIQUECNIL imposed a fine of EUR 32 million on SOCIETE DE SUPPORT LOGISTIQUE. The case concerned identified regulatory violations, with no further details provided in the source data. | FR | CNIL | GDPR | €32,000,000 | ↗ |
| 28 Aug 2023 | Trygg-HansaTrygg-Hansa Försäkring filial was fined by IMY SEK 35,000,000 for failing to implement appropriate technical measures. This allowed unauthorized access to sensitive customer data, breaching GDPR Articles 5(1)(f) and 32(1). | SE | IMY | GDPR | €2,941,000 | ↗ |
| 16 Dec 2020 | Babaváró kölcsönnel összefüggésben végzett adatkezelés – várandósgondozási könyvekről való másolatkészítés jogszerűségeThe supervisory authority found that the entity processed personal and health data from maternity care records without a legal basis in connection with Babaváró loan applications. It also failed to provide clear and transparent information about the processing, breaching GDPR principles. | HU | NAIH | GDPR | €98,350 | ↗ |