BULLETIN №084Last updated · 14 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -24.5%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 28 Apr 2026 | POSADA DEL LEÓN DE ORO, C.B.POSADA DEL LEÓN DE ORO, C.B. was fined EUR 400 by the AEPD for improper use of a surveillance system that recorded audio and video. The authority found violations of employee privacy and of the duty to inform data subjects about processing, contrary to GDPR Articles 5(1)(c) and 13. | ES | AEPD | GDPR | €400 | ↗ |
| 29 Apr 2026 | DIGI SPAIN TELECOM, S.L.U.DIGI SPAIN TELECOM, S.L.U. was fined by the AEPD 140,000 EUR for processing personal data without a legal basis. The case concerned a SIM card duplication incident that resulted in unauthorized data processing. | ES | AEPD | GDPR | €140,000 | ↗ |
| 29 Apr 2026 | Tirrenia Hospital SRLTirrenia Hospital SRL was fined EUR 1,000 by the Garante for failing to provide a comprehensible transcription of a deceased patient's medical records. The authority treated this as a breach of data protection rules. | IT | Garante | GDPR | €1,000 | ↗ |
| 29 Apr 2026 | Nuova Corrente S.r.l.Nuova Corrente S.r.l. was fined EUR 15,000 by the Garante for making promotional calls without a valid legal basis. The authority found this to be a breach of GDPR lawfulness principles. | IT | Garante | GDPR | €15,000 | ↗ |
| 29 Apr 2026 | Ministero della GiustiziaThe Ministry of Justice was fined EUR 12,000 by the Garante for violations related to personal data processing. The case concerned the absence of an appropriate legal basis and the processing of special categories of data. | IT | Garante | GDPR | €12,000 | ↗ |
| 29 Apr 2026 | dottoressa GuzzoThe Garante imposed a fine of EUR 5,000 on dottoressa Guzzo for unlawfully processing personal data by publishing images of a deceased minor without consent. The authority found that this breached core data protection principles. | IT | Garante | GDPR | €5,000 | ↗ |
| 29 Apr 2026 | Pianeta s.r.l.Pianeta s.r.l. was fined by the Garante 34,000 EUR for unlawfully processing personal data linked to a loyalty card program. The data were used to initiate disciplinary action against an employee, which breached GDPR requirements. | IT | Garante | GDPR | €34,000 | ↗ |
| 29 Apr 2026 | IBERDROLA CLIENTES, S.A.U.IBERDROLA CLIENTES, S.A.U. was fined EUR 1,000,000 by the AEPD for failing to implement adequate technical and organizational security measures. The authority found that the company did not properly verify customer identity, which constitutes a breach of Article 32 GDPR. | ES | AEPD | GDPR | €1,000,000 | ↗ |
| 29 Apr 2026 | Consiglio Nazionale dei Periti Industriali e dei Periti Industriali LaureatiThe Consiglio Nazionale dei Periti Industriali e dei Periti Industriali Laureati was fined €3,000 by the Garante. The authority found that the organization failed to ensure transparency in data processing, breaching GDPR principles of lawfulness, fairness, and transparency. | IT | Garante | GDPR | €3,000 | ↗ |
| 29 Apr 2026 | Azienda Sanitaria Locale di MateraAzienda Sanitaria Locale di Matera was fined by the Garante EUR 8,600 after a data breach caused by a ransomware attack. The incident led to the exfiltration of personal data, and the authority found inadequate technical and organizational measures to protect data security. | IT | Garante | GDPR | €8,600 | ↗ |
| 29 Apr 2026 | Istituto Comprensivo Statale MontelibrettiIstituto Comprensivo Statale Montelibretti was fined EUR 4,000 by the Garante for breaches of data protection rules in the processing of personal data on its institutional website. The authority cited failures to comply with lawfulness, fairness, transparency, and data minimization principles. | IT | Garante | GDPR | €4,000 | ↗ |
| 29 Apr 2026 | Lepida S.c.p.A.Lepida S.c.p.A. was fined by the Italian supervisory authority Garante €100,000 for unauthorized access and data handling violations linked to SPID digital identity management. The authority found breaches of GDPR Articles 25 and 32, covering data protection by design and security of processing. | IT | Garante | GDPR | €100,000 | ↗ |
| 30 Apr 2026 | BLUE PROJECTS INDUSTRIES S.R.L.ANSPDCP completed an investigation in April 2026 into BLUE PROJECTS INDUSTRIES S.R.L. and found a GDPR violation. A fine of EUR 2,500 was imposed. | RO | ANSPDCP | GDPR | €2,500 | ↗ |
| 30 Apr 2026 | Intesa SanpaoloItaly’s data protection authority, Garante, fined Intesa Sanpaolo EUR 31.8 million. The sanction concerned serious failures in security and access management for personal data. | IT | Garante per la protezione dei dati personali | GDPR | €31,800,000 | ↗ |
| 30 Apr 2026 | Dane anonimowe (Burmistrza Miasta i Gminy D.)UODO imposed an administrative fine of 7,700 PLN on Anonymous data (Mayor of D. Municipality). The sanction resulted from failing to notify the President of the Personal Data Protection Office of a personal data breach without undue delay, and no later than 72 hours after becoming aware of it. | PL | UODO | GDPR | €1,807 | ↗ |
| 01 May 2026 | Anonymised (IDPC 0583_001)The Commissioner found that the insurance company continued to process the complainant’s personal data for direct marketing despite his objection. The authority also identified inadequate safeguards, weak accountability measures, and non-compliant arrangements with third-party processors. A reprimand was issued, corrective measures were ordered within 20 days, and administrative fines totalling EUR 1,000 were imposed. | MT | IDPC | GDPR | €1,000 | ↗ |
| 05 May 2026 | VOX ESPAÑAVOX ESPAÑA was fined by the AEPD 500 EUR for publishing personal data on Facebook without proper consent. The authority found that this breached Article 6 of the GDPR. | ES | AEPD | GDPR | €500 | ↗ |
| 07 May 2026 | South Staffordshire Plc and South Staffordshire Water PlcThe Information Commissioner’s Office (ICO) imposed a fine of 963,900 GBP on South Staffordshire Plc and South Staffordshire Water Plc for breaches of Article 5(1)(f) and Article 32(1) of the UK GDPR. The case followed a cyber incident in which personal data relating to approximately 633,887 UK data subjects was exfiltrated. | GB | ICO | GDPR | €1,115,000 | ↗ |
| 08 May 2026 | Permanent TSBPermanent TSB was fined EUR 277,500 by Ireland's Data Protection Commission. The case involved fraudsters impersonating customers at a contact centre, resulting in three GDPR breaches and financial loss to three customers. | IE | Data Protection Commission | GDPR | €277,000 | ↗ |
| 08 May 2026 | MLU B.V.MLU B.V. was fined €100,000,000 by AP for transferring personal data of users in Finland and Norway to Russia without adequate safeguards. The authority found breaches of GDPR Articles 44, 46, and 5. | NL | AP | GDPR | €100,000,000 | ↗ |