BULLETIN №081Last updated · 27 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -20.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 10 Jul 2025 | Comune di LanghiranoThe Municipality of Langhirano was fined by the Garante for the unauthorized disclosure of personal data on its institutional website. The data was removed, but the authority imposed a monetary penalty of EUR 12,000. | IT | Garante | GDPR | €12,000 | ↗ |
| 10 Jul 2025 | Asilo nido “La Combricola Dei Birichini Di Betty”The Garante imposed a 10,000 EUR fine on the nursery for failing to provide parents with the required information about the processing of children's images. It also found that no data protection impact assessment had been carried out for the surveillance system. | IT | Garante | GDPR | €10,000 | ↗ |
| 10 Jul 2025 | Istituto Comprensivo 2 C.D.The Garante fined Istituto Comprensivo 2 C.D. EUR 4,000 for breaches of data protection rules. The authority cited non-compliance with the principles of lawfulness, fairness, and transparency in the processing of personal data. | IT | Garante | GDPR | €4,000 | ↗ |
| 10 Jul 2025 | Cooperativa Sociale CoopseliosCooperativa Sociale Coopselios was fined by the Garante €10,000 for failing to properly handle data subject requests. The нарушения concerned the GDPR rights of access, rectification, and data portability. | IT | Garante | GDPR | €10,000 | ↗ |
| 10 Jul 2025 | Magna PT S.p.A.Magna PT S.p.A. was fined EUR 50,000 by the Garante for requiring employees to complete a questionnaire after absences due to illness. The authority found that this practice breached GDPR rules on the processing of personal data. | IT | Garante | GDPR | €50,000 | ↗ |
| 10 Jul 2025 | Banco Bilbao Vizcaya Argentaria SABanco Bilbao Vizcaya Argentaria SA was fined by the Italian authority Garante in the amount of €100,000. The case concerned an inadequate response to a data access request linked to a fraud incident, which breached Article 15 of the GDPR. | IT | Garante | GDPR | €100,000 | ↗ |
| 10 Jul 2025 | dottoressa Monica Maria FerrariThe doctor was fined for recording conversations with a patient during a specialist visit without proper consent. The authority also found a failure to provide required information, breaching transparency and information obligations. | IT | Garante | GDPR | €7,000 | ↗ |
| 10 Jul 2025 | Università degli Studi di Cassino e del Lazio MeridionaleThe University of Cassino and Southern Lazio was fined €8,000 by the Garante for failing to comply with data protection rules. The case concerned improper handling of personal data requests and deficiencies in administrative procedures. | IT | Garante | GDPR | €8,000 | ↗ |
| 10 Jul 2025 | Centro Medico Italiano S.r.l.Centro Medico Italiano S.r.l. was fined by the Garante 30,000 EUR for failing to provide an adequate response to a data subject’s request for access to health data and information about its processing. The authority found a breach of GDPR Article 15. | IT | Garante | GDPR | €30,000 | ↗ |
| 10 Jul 2025 | Outly di Veneziani & Co s.r.l.The Garante fined Outly di Veneziani & Co s.r.l. EUR 15,000 for insufficient transparency when obtaining consent and for inadequate information on data retention periods. The issues affected all interested parties and potential customers. | IT | Garante | GDPR | €15,000 | ↗ |
| 10 Jul 2025 | Comune di ConversanoComune di Conversano was fined €3,000 by the Garante for failing to communicate the contact details of its Data Protection Officer. The breach concerned the obligation under Article 37 GDPR to notify the supervisory authority. | IT | Garante | GDPR | €3,000 | ↗ |
| 09 Jul 2025 | KAFFA KOFFEE ORGANISATION, S.L.KAFFA KOFFEE ORGANISATION, S.L. was fined EUR 900 by the AEPD for failing to implement appropriate technical and organizational measures. The deficiency led to email addresses being visible to multiple recipients, in breach of GDPR requirements. | ES | AEPD | GDPR | €900 | ↗ |
| 09 Jul 2025 | DISTRIBUTED ENERGY ASSETS, S.L.DISTRIBUTED ENERGY ASSETS, S.L. was fined by the AEPD 5,000 EUR for obstructing the exercise of data subject rights. The breach concerned in particular the right to erasure under Article 17 of the GDPR. | ES | AEPD | GDPR | €5,000 | ↗ |
| 09 Jul 2025 | SC Tremend Software Consulting SRLSC Tremend Software Consulting SRL was fined by ANSPDCP for GDPR violations. The penalty amounted to EUR 3,000. | RO | ANSPDCP | GDPR | €3,000 | ↗ |
| 09 Jul 2025 | EDICIONES CATÓLICOS Y VIDA PÚBLICA, S.L.U.The entity was fined for using non-essential cookies without obtaining prior user consent. This conduct breached the LSSI requirements on obtaining consent before activating such tracking tools. | ES | AEPD | ePrivacy | €5,000 | ↗ |
| 09 Jul 2025 | VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD 150,000 EUR for issuing a SIM card duplicate without proper consent. The incident led to unauthorized bank transfers and involved processing personal data without a lawful basis. | ES | AEPD | GDPR | €150,000 | ↗ |
| 09 Jul 2025 | SOCIEDAD DE GESTIÓN DE ACTIVOS PROCEDENTES DE LA REESTRUCTURACIÓN BANCARIA, S.A. (SAREB)SAREB was fined €300,000 by the AEPD for breaches of GDPR Articles 5(1)(f) and 28. The case concerned data protection failures and insufficient contractual oversight of data processing activities. | ES | AEPD | GDPR | €300,000 | ↗ |
| 09 Jul 2025 | REAL SOCIEDAD DE FUTBOL S.A.D.REAL SOCIEDAD DE FUTBOL S.A.D. suffered a ransomware attack that led to a data breach affecting 60,000 individuals, including biometric, identification, financial, and health data. The AEPD fined the company for failing to implement adequate technical and organizational measures to protect data security. | ES | AEPD | GDPR | €60,000 | ↗ |
| 08 Jul 2025 | Stichting Oud LemmerStichting Oud Lemmer was fined by the AP 500 EUR for processing personal data without a legal basis. The case concerned live streaming camera footage of public spaces, which breached GDPR Articles 5 and 6. | NL | AP | GDPR | €500 | ↗ |
| 08 Jul 2025 | Selgros Cash & Carry SRLIn June 2025, ANSPDCP completed an investigation at Selgros Cash & Carry SRL and found a GDPR violation. The operator was fined EUR 3,000. | RO | ANSPDCP | GDPR | €3,000 | ↗ |