BULLETIN №081Last updated · 27 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -20.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 21 Mar 2024 | LAZIOcrea S.p.a.LAZIOcrea S.p.a. was fined by the Garante for failing to implement adequate technical and organizational measures to ensure data security. The deficiencies led to unauthorized access attempts and temporary unavailability of regional services. | IT | Garante | GDPR | €271,000 | ↗ |
| 29 Dec 2025 | SOCIETE EDITANT UNE APPLICATION MOBILECNIL imposed an administrative fine of EUR 270,000 on SOCIETE EDITANT UNE APPLICATION MOBILE. The case concerns a breach of personal data protection rules and should be considered in compliance assessments. | FR | CNIL | GDPR | €270,000 | ↗ |
| 18 Dec 2024 | Dane anonimowe (C. S.A. z siedzibą w D. przy ul.)UODO imposed an administrative fine of PLN 261,918 on C. S.A. for breaches of GDPR obligations. The case concerned, among others, Article 38(3), Article 30(1), and Article 35(1) and (7) of Regulation 2016/679. | PL | UODO | GDPR | €61,514 | ↗ |
| — | Timegrip ASDatatilsynet imposed an administrative fine of NOK 250,000 on Timegrip AS for denying employees access to their personal data relating to time tracking. The authority found that Timegrip effectively acted as the controller and had no valid basis to refuse the access requests. | NO | Datatilsynet | — | €22,435 | ↗ |
| 30 Aug 2023 | LORO PARQUE, S.A.LORO PARQUE, S.A. was fined by the AEPD 250,000 EUR for processing biometric data without a proper legal basis. The authority classified this as a very serious breach of Article 9 GDPR. | ES | AEPD | GDPR | €250,000 | ↗ |
| 23 Jan 2024 | CAJA RURAL DE TERUEL, S.C.C.CAJA RURAL DE TERUEL was fined by the AEPD EUR 250,000 for failing to ensure the confidentiality and integrity of personal data. The breach resulted in unauthorized access following a data security incident. | ES | AEPD | GDPR | €250,000 | ↗ |
| 08 Apr 2024 | VODAFONE ESPAÑA, S.A.U.The AEPD imposed a fine of 250,000 EUR on VODAFONE ESPAÑA, S.A.U. for failing to implement adequate measures to prevent unauthorized access to personal data. The authority found a breach of the GDPR confidentiality requirements. | ES | AEPD | GDPR | €250,000 | ↗ |
| 18 Feb 2026 | ALÍA GESTIÓN INTEGRAL DE SERVICIOS, S.L.ALÍA GESTIÓN INTEGRAL DE SERVICIOS, S.L. was fined EUR 250,000 by the AEPD for a data protection breach. The incident involved unauthorized access to the internal network after VPN credentials were compromised. | ES | AEPD | GDPR | €250,000 | ↗ |
| 02 Mar 2021 | Anonymisert (Datatilsynet far-gebyr-for-ulovlig-videresending-av-e-post)The company was fined 250,000 NOK for forwarding an employee’s emails without a legal basis. The authority found that this breached the GDPR and the rules governing employer access to employee email accounts. | NO | Datatilsynet | GDPR | €24,378 | ↗ |
| 23 Jan 2024 | CAJA RURAL DE EXTREMADURA S.C.C.CAJA RURAL DE EXTREMADURA S.C.C. was fined by the AEPD 250,000 EUR for a breach that compromised the confidentiality and integrity of personal data. The authority found a violation of Article 5(1)(f) of the GDPR. | ES | AEPD | GDPR | €250,000 | ↗ |
| 20 Jan 2026 | Timegrip ASTimegrip AS was fined 250,000 NOK for failing to provide employees access to their own timekeeping data after the bankruptcy of a retail chain. The authority treated the company as the data controller and found a breach of the GDPR right of access. | NO | Datatilsynet | GDPR | €21,340 | ↗ |
| 22 Jan 2024 | CAJASIETE, CAJA RURAL SOCIEDAD COOPERATIVA DE CREDITOCAJASIETE was fined by the AEPD in the amount of 250,000 EUR for a data security incident. The incident compromised the confidentiality and integrity of personal data, breaching GDPR Article 5(1)(f). | ES | AEPD | GDPR | €250,000 | ↗ |
| 03 Nov 2022 | DKN.5131.18.2022StatusnieprawomocnaTytuUODO imposed an administrative fine of PLN 250,000 on the company. The authority found that the company failed to notify the supervisory authority within 24 hours of detecting the personal data breach and did not promptly inform the affected data subject. | PL | UODO | GDPR | €53,090 | ↗ |
| 14 May 2025 | IAB EuropeThe Gegevensbeschermingsautoriteit’s decision concerned IAB Europe and the Transparency and Consent Framework. A fine of EUR 250,000 was imposed for GDPR breaches related to the processing of personal data, and the Brussels Market Court confirmed the violations and sanctions while noting procedural grounds for annulling the original decision. | BE | Gegevensbeschermingsautoriteit (GBA) | GDPR | €250,000 | ↗ |
| 02 Feb 2022 | IAB EuropeIAB Europe was fined EUR 250,000 by the Belgian APD for violations related to its Transparency & Consent Framework. The authority identified issues with transparency, the legal basis for processing, and the security of personal data. | BE | APD | GDPR | €250,000 | ↗ |
| 07 Jun 2021 | Regionstyrelsen Region VärmlandRegionstyrelsen Region Värmland was fined by IMY 250,000 SEK for failing to inform patients calling the 1177 healthcare line that their phone numbers and community IDs were being collected. The authority found this to be a breach of GDPR transparency requirements. | SE | IMY | GDPR | €24,863 | ↗ |
| 06 Jun 2024 | Drivalia Leasys Rent S.p.A.Drivalia Leasys Rent S.p.A. was fined by Garante 250,000 EUR for denying a car rental voucher to a customer listed on a blacklist. The authority found insufficient transparency in data processing and a lack of proper legal basis and consent under GDPR. | IT | Garante | GDPR | €250,000 | ↗ |
| 02 Feb 2022 | IAB EuropeIAB Europe was fined EUR 250,000 by the Belgian APD for violations related to its Transparency & Consent Framework. The authority cited lack of transparency, improper processing of personal data, and failure to meet GDPR obligations. | BE | APD | GDPR | €250,000 | ↗ |
| 21 May 2024 | BANCO CETELEM, S.A.Banco Cetelem, S.A. was fined by the AEPD 250,000 EUR for unauthorized processing of personal data. The case included charging the complainant’s bank account for a loan taken out by an unknown third party without consent. | ES | AEPD | GDPR | €250,000 | ↗ |
| 07 Jun 2021 | Regionstyrelsen Region SörmlandRegionstyrelsen Region Sörmland was fined by IMY 250,000 SEK for failing to inform callers to the 1177 healthcare line that their phone numbers and community IDs were being collected. The authority found a breach of GDPR transparency requirements. | SE | IMY | GDPR | €24,863 | ↗ |