BULLETIN №081Last updated · 27 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -20.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 23 Feb 2023 | Ediscom S.p.A.Ediscom S.p.A. was fined by the Garante 300,000 EUR for lacking clarity and transparency when obtaining user consent for marketing purposes. The authority also found that data was processed despite objections from data subjects. | IT | Garante | GDPR | €300,000 | ↗ |
| 23 May 2019 | Bérleti jogviszony során keletkezett dokumentumok másolatban történő kiadásaThe controller did not comply with the data subject's access request for personal data beyond the 2012 lease agreement. The authority treated this as a breach of access-right obligations and imposed a fine. | HU | NAIH | GDPR | €918 | ↗ |
| 24 Jun 2025 | PROCONO SAPROCONO SA was fined EUR 300,000 by the AEPD for a data breach. The incident exposed customer data on the internet, including names, addresses, email addresses, and possibly bank account details. | ES | AEPD | GDPR | €300,000 | ↗ |
| 27 Feb 2025 | Energia Pulita S.r.l.Energia Pulita S.r.l. was fined EUR 300,000 by the Garante for making unsolicited marketing calls without a valid legal basis. The authority found a breach of GDPR Article 5. | IT | Garante | GDPR | €300,000 | ↗ |
| 30 Nov 2022 | OPERATEUR DE TELECOMMUNICATION FIXECNIL imposed a fine of EUR 300,000 on OPERATEUR DE TELECOMMUNICATION FIXE and issued an injunction subject to penalty payments. The case concerns a compliance breach in the area of data protection. | FR | CNIL | GDPR | €300,000 | ↗ |
| 19 Aug 2022 | Fidesz-Magyar Polgári SzövetségFidesz-Magyar Polgári Szövetség was fined by NAIH 300,000 HUF for unlawfully processing personal data, including phone numbers, without a legal basis. The authority also found violations of the rights to erasure and access, as well as inadequate information provided during phone campaigns. | HU | NAIH | GDPR | €735 | ↗ |
| 08 Feb 2024 | Medtronic Italia S.p.a.Medtronic Italia S.p.a. was fined by the Garante in the amount of €300,000 for a data protection breach. The authority found inadequate technical and organizational measures that led to unauthorized disclosure of data. | IT | Garante | GDPR | €300,000 | ↗ |
| 23 May 2019 | Alkotmányjogi panasz elbírálása a NAIH/2019/1189/11. sz. ügyben (IV/1561/2020.)The controller did not comply with a data subject access request under the GDPR. NAIH imposed a fine of HUF 300,000 for unlawful data processing. | HU | NAIH | GDPR | €918 | ↗ |
| 18 Oct 2012 | Fastweb S.p.A.Fastweb S.p.A. was fined by the Garante in the amount of EUR 300,000 for violations related to unsolicited telemarketing calls and improper data processing. The case indicates deficiencies in marketing compliance and personal data protection controls. | IT | Garante | GDPR | €300,000 | ↗ |
| 26 Jan 2022 | Region Uppsala, personuppgiftsincidenterRegionstyrelsen i Region Uppsala was fined for sending sensitive personal data and personal identification numbers by email without encrypting the content. The authority found a breach of Article 32 GDPR because appropriate security measures were not in place. | SE | IMY | GDPR | €28,710 | ↗ |
| 14 Dec 2020 | Uppsalahem ABUppsalahem AB was fined for unlawful video surveillance in a residential building. The authority found that the company did not properly balance its surveillance interests against residents’ privacy rights under GDPR Article 6(1)(f). | SE | IMY | GDPR | €29,433 | ↗ |
| 18 Apr 2024 | H&M Hennes & MauritzH&M Hennes & Mauritz GBC AB was fined for conducting camera surveillance without a legal basis and for failing to provide required information to data subjects. The authority found breaches of GDPR Articles 6(1) and 13. | SE | IMY | GDPR | €25,779 | ↗ |
| 31 May 2024 | MAPFRE INVERSIÓN SOCIEDAD DE VALORES, S.AMAPFRE INVERSIÓN SOCIEDAD DE VALORES, S.A was fined EUR 300,000 by the AEPD. The authority found that the company carried out unauthorized investment transactions using personal data without consent, in breach of data protection rules. | ES | AEPD | GDPR | €300,000 | ↗ |
| 09 Jul 2025 | SOCIEDAD DE GESTIÓN DE ACTIVOS PROCEDENTES DE LA REESTRUCTURACIÓN BANCARIA, S.A. (SAREB)SAREB was fined €300,000 by the AEPD for breaches of GDPR Articles 5(1)(f) and 28. The case concerned data protection failures and insufficient contractual oversight of data processing activities. | ES | AEPD | GDPR | €300,000 | ↗ |
| 08 Sept 2025 | SIA "ZZ Dats"DVI imposed a fine of 300,000 EUR on SIA "ZZ Dats". The decision has been appealed. | LV | DVI | GDPR | €300,000 | ↗ |
| 28 Oct 2025 | SIA ZZ DatsThe Latvian Data State Inspectorate found that SIA ZZ Dats failed to meet GDPR Article 32 requirements for appropriate technical and organizational measures. The case involved a major personal data leak affecting nearly all Latvian municipalities, and the authority imposed an administrative fine of EUR 300,000. The company has appealed the decision. | LV | Datu valsts inspekcija | GDPR | €300,000 | ↗ |
| 30 Nov 2023 | Dane anonimowe (V. S.A. z siedzibą w P. ul.)UODO imposed an administrative fine of PLN 282,960 on the controller for failing to report a personal data breach to the supervisory authority. The authority also found that the affected data subject was not notified of the breach. | PL | UODO | GDPR | €65,064 | ↗ |
| 01 Mar 2018 | Massimo FarinaMassimo Farina was fined EUR 280,000 by the Garante. The case concerned the use of prepaid credit cards under false names without obtaining consent, which breached data protection rules. | IT | Garante | GDPR | €280,000 | ↗ |
| 08 May 2026 | Permanent TSBPermanent TSB was fined EUR 277,500 by Ireland's Data Protection Commission. The case involved fraudsters impersonating customers at a contact centre, resulting in three GDPR breaches and financial loss to three customers. | IE | Data Protection Commission | GDPR | €277,000 | ↗ |
| 05 Aug 2021 | Anonymisé (CNPD decision-31-fr-2021)The company sent emails containing sensitive medical data to incorrect recipients. The authority also found a breach of data protection duties due to improper documentation of the incidents. | LU | CNPD | GDPR | €275,000 | ↗ |