BULLETIN №084Last updated · 14 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -24.5%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 17 Apr 2026 | Poste Italiane S.p.a. e PostePay S.p.a.Poste Italiane S.p.a. and PostePay S.p.a. were sanctioned for unlawful processing of personal data in their Bancoposta and PostePay apps on Android devices. The apps required users to authorize access to data to detect malicious software, which breached GDPR principles. | IT | Garante | GDPR | €6,624,000 | ↗ |
| 17 Apr 2026 | Comune di VeneziaThe Municipality of Venice was fined €3,000 by the Garante for failing to ensure the required transparency in data processing. The authority found a breach of the GDPR principles of lawfulness, fairness, and transparency. | IT | Garante | GDPR | €3,000 | ↗ |
| 17 Apr 2026 | Pak StorePak Store was fined EUR 2,000 by the Garante for using a CCTV camera without the required signage and without the necessary authorization from the Labour Inspectorate. The authority found a breach of the information obligations under GDPR Article 13. | IT | Garante | GDPR | €2,000 | ↗ |
| 17 Apr 2026 | The European House - Ambrosetti S.p.A.The European House - Ambrosetti S.p.A. was fined by Garante 85,000 EUR for a data breach. The incident involved unauthorized access and exfiltration of personal and authentication data affecting an unspecified number of individuals. | IT | Garante | GDPR | €85,000 | ↗ |
| 17 Apr 2026 | Comune di CogoletoComune di Cogoleto was fined EUR 4,000 by the Garante for failing to ensure transparency in data processing. The authority also found that no data protection impact assessment had been carried out, breaching the principles of lawfulness, fairness, and transparency. | IT | Garante | GDPR | €4,000 | ↗ |
| 17 Apr 2026 | Io e te s.r.l.s.Io e te s.r.l.s. was fined EUR 2,000 by the Italian Garante. The case concerned improper use of a surveillance camera that enabled remote viewing through a mobile application without proper authorization. | IT | Garante | GDPR | €2,000 | ↗ |
| 17 Apr 2026 | Carlo Maria Antonio ParisiThe Garante fined Carlo Maria Antonio Parisi, owner of the online newspaper “giornalistitalia.it”, EUR 2,500. The authority found inadequate technical and organizational measures to support data subject rights and delays in handling requests without undue delay. | IT | Garante | GDPR | €2,500 | ↗ |
| 17 Apr 2026 | Ausl ModenaAusl Modena was fined by the Garante in the amount of 3,500 EUR for creating duplicate patient records. The case involved processing health data without proper transparency and compliance with data protection rules. | IT | Garante | GDPR | €3,500 | ↗ |
| 17 Apr 2026 | Comune di Mazara del ValloThe Garante fined Comune di Mazara del Vallo 6,000 EUR for violations related to the online publication of personal data. The case concerned the improper disclosure of personal information through online publication. | IT | Garante | GDPR | €6,000 | ↗ |
| 17 Apr 2026 | Azienda USL ModenaAzienda USL Modena was fined by the Garante in the amount of 10,000 EUR for a data breach caused by a ransomware attack. The authority found a breach of GDPR data security obligations. | IT | Garante | GDPR | €10,000 | ↗ |
| 17 Apr 2026 | Provvedimento del 17 aprile 2026 [10254325]The supervisory authority found that a video surveillance system with 25 cameras operated without the required informational signage. The breach concerned GDPR information obligations. | IT | Garante | GDPR | €3,000 | ↗ |
| 17 Apr 2026 | Associazione Movimento Cinque Stelle SiciliaThe Garante fined Associazione Movimento Cinque Stelle Sicilia 5,000 EUR for failing to adopt adequate technical and organizational measures to facilitate the exercise of data protection rights. The authority also found that requests were not addressed without undue delay. | IT | Garante | GDPR | €5,000 | ↗ |
| 17 Apr 2026 | Sicra PressThe Garante imposed a 2,000 EUR fine on Sicra Press for using non-anonymized data in articles related to judicial matters. The authority found a breach of data protection rules. | IT | Garante | GDPR | €2,000 | ↗ |
| 17 Apr 2026 | Istituto “Ancelle della Compagnia della Regina dei Gigli”The Garante fined the school EUR 4,000 for processing students’ personal data without a proper legal basis. The authority found breaches of lawfulness, fairness, and transparency. | IT | Garante | GDPR | €4,000 | ↗ |
| 28 Apr 2026 | RESIDENCIAL ETXE-LAN, S.L.RESIDENCIAL ETXE-LAN, S.L. was fined by the AEPD for failing to provide the required information to the supervisory authority. The breach concerned Article 58(1) GDPR and hindered the authority’s supervisory powers. | ES | AEPD | GDPR | €3,000 | ↗ |
| 28 Apr 2026 | Fondation YThe APD Litigation Chamber fined Fondation Y EUR 1,000 for failing to respond to a data erasure request. The authority also found negligent cooperation with the data protection authority, constituting a breach of Article 31 GDPR. | BE | APD | GDPR | €1,000 | ↗ |
| 28 Apr 2026 | CROWD ENTERTAINMENT LIMITEDCROWD ENTERTAINMENT LIMITED was fined EUR 15,000 by ANSPDCP for GDPR violations. The case concerned non-compliant processing of personal data. | RO | ANSPDCP | GDPR | €15,000 | ↗ |
| 28 Apr 2026 | vzwDecision on the merits No. 94/2026 of 28 April 2026 was issued by the Belgian Gegevensbeschermingsautoriteit. A Belgian vzw was fined EUR 1,000 for failing to respond to registered letters and failing to appear at the hearing, which was treated as a breach of the GDPR cooperation duty. | BE | Gegevensbeschermingsautoriteit (GBA) | GDPR | €1,000 | ↗ |
| 28 Apr 2026 | CROWD ENTERTAINMENT LIMITEDCROWD ENTERTAINMENT LIMITED was fined EUR 20,000 by the Romanian authority ANSPDCP. The sanction concerned violations of GDPR requirements. | RO | ANSPDCP | GDPR | €20,000 | ↗ |
| 28 Apr 2026 | SIPHONE 2020, S.L.SIPHONE 2020, S.L. was fined by the AEPD 4,000 EUR for operating a video surveillance system that also recorded audio. Employees were not informed and did not consent, which breached privacy and data protection rules. | ES | AEPD | GDPR | €4,000 | ↗ |