BULLETIN №084Last updated · 14 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -24.5%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 08 May 2026 | MLU B.V.The Dutch data protection authority imposed a EUR 100 million fine on MLU B.V. for transferring personal data to Russia without adequate safeguards. It also ordered the company to stop transferring personal data of individuals in Norway and Finland to Russia via the Yango app. | NL | Autoriteit Persoonsgegevens | GDPR | €100,000,000 | ↗ |
| 11 May 2026 | Geanonimiseerd (APD 100/2026)The Litigation Chamber imposed a fine for violations related to camera surveillance at a residential complex. It found a lack of transparency and a failure to properly facilitate data subject rights. | BE | APD | GDPR | €5,000 | ↗ |
| 11 May 2026 | South Staffordshire PlcThe ICO issued a monetary penalty against South Staffordshire Plc and South Staffordshire Water Plc in the amount of GBP 963,000. The case concerned a security breach affecting more than 633,000 individuals and an admitted infringement of Article 5(1)(f) UK GDPR. | GB | Information Commissioner's Office | GDPR | €1,113,000 | ↗ |
| 12 May 2026 | SWDESWDE was fined by the APD 50,000 EUR for unlawful call recordings and monitoring used for quality evaluation and training purposes. The authority found breaches of transparency, data minimization, and other GDPR principles. | BE | APD | GDPR | €50,000 | ↗ |
| 14 May 2026 | Comune di Mirabella ImbaccariComune di Mirabella Imbaccari was fined for disclosing personal data online without a legal basis and for violating the data minimization principle. The authority also found that the municipality had failed to appoint a Data Protection Officer and to communicate the DPO’s contact details to the supervisory authority. | IT | Garante | GDPR | €1,800 | ↗ |
| 14 May 2026 | Azienda ospedaliera dei colli Monaldi-Cotugno-CTO di NapoliAzienda ospedaliera dei colli Monaldi-Cotugno-CTO di Napoli was fined EUR 15,000 by the Garante. The authority found that the entity provided false statements and interrupted the performance of its tasks. The case concerns breaches of data protection rules. | IT | Garante | GDPR | €15,000 | ↗ |
| 14 May 2026 | EmiratesEmirates was fined by the Italian Garante €180,000 for breaching data protection rules. The airline required passengers with reduced mobility to complete a medical form without providing adequate information about how their data would be processed. | IT | Garante | GDPR | €180,000 | ↗ |
| 14 May 2026 | Comune di VentassoComune di Ventasso was fined EUR 8,000 by the Garante. The authority found breaches of the principles of lawful, fair and transparent processing of personal data, as well as data minimization. | IT | Garante | GDPR | €8,000 | ↗ |
| 14 May 2026 | Energia Sostenibile S.r.l.Energia Sostenibile S.r.l. was fined EUR 100,000 by the Garante for making unsolicited calls to numbers listed in the Public Opposition Register. The authority also found that the company did not adequately respond to data subjects’ requests to exercise their rights. | IT | Garante | GDPR | €100,000 | ↗ |
| 14 May 2026 | FeGi M&A Services s.r.l.FeGi M&A Services s.r.l. was fined EUR 1,000 by the Garante for making promotional phone calls without the required consent. The authority found this conduct breached GDPR principles of fairness and transparency. | IT | Garante | GDPR | €1,000 | ↗ |
| 15 May 2026 | Unnamed Hungarian employerHungary’s data protection authority, NAIH, imposed a HUF 7 million GDPR fine on an unnamed employer. The case involved continuous camera monitoring in employee dining and rest areas, as well as deficiencies in documentation and privacy notices. | HU | Nemzeti Adatvédelmi és Információszabadság Hatóság | GDPR | €19,460 | ↗ |
| 20 May 2026 | KRA Consultancy LtdKRA Consultancy Ltd was fined £300,000 by the ICO for sending more than 5.5 million unsolicited direct marketing texts and fake bailiff messages. The conduct breached regulations 22 and 23 of PECR and generated over 60,000 complaints to the 7726 spam reporting service. | GB | ICO | ePrivacy | €346,000 | ↗ |
| 21 May 2026 | The European House – Ambrosetti spaThe Italian data protection authority fined The European House – Ambrosetti spa EUR 85,000 for security shortcomings following a data breach affecting 61,670 people. The company notified affected individuals too late, only after intervention by the authority. | IT | Garante per la protezione dei dati personali | GDPR | €85,000 | ↗ |
| 26 May 2026 | Mediaworks Hungary Zrt.Mediaworks Hungary Zrt. was fined by NAIH 50,000,000 HUF for publishing links to a map containing personal data and special category data, including political opinions. The authority found that the processing lacked a lawful basis. | HU | NAIH | GDPR | €140,000 | ↗ |
| 28 May 2026 | AgID – Agenzia per l’Italia digitaleThe Italian Data Protection Authority fined AgID €55,000 for failing to adequately inform professionals about the automatic registration of their digital domiciles. The authority found breaches of transparency and data processing principles. | IT | Garante | GDPR | €55,000 | ↗ |
| 28 May 2026 | Croce Rossa Italiana – Comitato regionale Toscana – Presidio Anna TorrigianiThe Italian Data Protection Authority imposed a 700 EUR fine on Croce Rossa Italiana – Comitato regionale Toscana – Presidio Anna Torrigiani. The case concerned a data protection breach during a patient's hospitalization in the orthopedics department, including improper handling of information about HIV status. | IT | Garante | GDPR | €700 | ↗ |
| 28 May 2026 | Comune di SciaccaComune di Sciacca was fined EUR 6,000 by the Garante for violations related to the processing and dissemination of personal data in the public sector. The case concerned improper handling of personal data within public administration activities. | IT | Garante | GDPR | €6,000 | ↗ |
| 28 May 2026 | Regione Autonoma della SardegnaThe Garante fined Regione Autonoma della Sardegna EUR 3,000 for sharing disciplinary sanction information with unauthorized internal units. The authority found this breached the GDPR and national data protection rules. | IT | Garante | GDPR | €3,000 | ↗ |
| 28 May 2026 | Action Fit di MilanoThe Garante fined Action Fit di Milano EUR 3,930 for sending unsolicited commercial emails to a customer without consent. The authority found this to be a breach of data protection rules. | IT | Garante | GDPR | €3,930 | ↗ |
| 28 May 2026 | Azienda Tutela della Salute per la LiguriaAzienda Tutela della Salute per la Liguria was fined by the Garante 6,000 EUR for violations related to the processing of personal data using a satellite localization system in a disciplinary procedure against an employee. The case concerned the use of data in a manner that did not comply with data protection requirements. | IT | Garante | GDPR | €6,000 | ↗ |