BULLETIN №081Last updated · 26 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -20.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 30 Apr 2026 | Dane anonimowe (Burmistrza Miasta i Gminy D.)UODO imposed an administrative fine of 7,700 PLN on Anonymous data (Mayor of D. Municipality). The sanction resulted from failing to notify the President of the Personal Data Protection Office of a personal data breach without undue delay, and no later than 72 hours after becoming aware of it. | PL | UODO | GDPR | €1,807 | ↗ |
| 29 Apr 2026 | DIGI SPAIN TELECOM, S.L.U.DIGI SPAIN TELECOM, S.L.U. was fined by the AEPD 140,000 EUR for processing personal data without a legal basis. The case concerned a SIM card duplication incident that resulted in unauthorized data processing. | ES | AEPD | GDPR | €140,000 | ↗ |
| 29 Apr 2026 | Tirrenia Hospital SRLTirrenia Hospital SRL was fined EUR 1,000 by the Garante for failing to provide a comprehensible transcription of a deceased patient's medical records. The authority treated this as a breach of data protection rules. | IT | Garante | GDPR | €1,000 | ↗ |
| 29 Apr 2026 | Nuova Corrente S.r.l.Nuova Corrente S.r.l. was fined EUR 15,000 by the Garante for making promotional calls without a valid legal basis. The authority found this to be a breach of GDPR lawfulness principles. | IT | Garante | GDPR | €15,000 | ↗ |
| 29 Apr 2026 | Ministero della GiustiziaThe Ministry of Justice was fined EUR 12,000 by the Garante for violations related to personal data processing. The case concerned the absence of an appropriate legal basis and the processing of special categories of data. | IT | Garante | GDPR | €12,000 | ↗ |
| 29 Apr 2026 | dottoressa GuzzoThe Garante imposed a fine of EUR 5,000 on dottoressa Guzzo for unlawfully processing personal data by publishing images of a deceased minor without consent. The authority found that this breached core data protection principles. | IT | Garante | GDPR | €5,000 | ↗ |
| 29 Apr 2026 | Pianeta s.r.l.Pianeta s.r.l. was fined by the Garante 34,000 EUR for unlawfully processing personal data linked to a loyalty card program. The data were used to initiate disciplinary action against an employee, which breached GDPR requirements. | IT | Garante | GDPR | €34,000 | ↗ |
| 29 Apr 2026 | IBERDROLA CLIENTES, S.A.U.IBERDROLA CLIENTES, S.A.U. was fined EUR 1,000,000 by the AEPD for failing to implement adequate technical and organizational security measures. The authority found that the company did not properly verify customer identity, which constitutes a breach of Article 32 GDPR. | ES | AEPD | GDPR | €1,000,000 | ↗ |
| 29 Apr 2026 | Consiglio Nazionale dei Periti Industriali e dei Periti Industriali LaureatiThe Consiglio Nazionale dei Periti Industriali e dei Periti Industriali Laureati was fined €3,000 by the Garante. The authority found that the organization failed to ensure transparency in data processing, breaching GDPR principles of lawfulness, fairness, and transparency. | IT | Garante | GDPR | €3,000 | ↗ |
| 29 Apr 2026 | Azienda Sanitaria Locale di MateraAzienda Sanitaria Locale di Matera was fined by the Garante EUR 8,600 after a data breach caused by a ransomware attack. The incident led to the exfiltration of personal data, and the authority found inadequate technical and organizational measures to protect data security. | IT | Garante | GDPR | €8,600 | ↗ |
| 29 Apr 2026 | Istituto Comprensivo Statale MontelibrettiIstituto Comprensivo Statale Montelibretti was fined EUR 4,000 by the Garante for breaches of data protection rules in the processing of personal data on its institutional website. The authority cited failures to comply with lawfulness, fairness, transparency, and data minimization principles. | IT | Garante | GDPR | €4,000 | ↗ |
| 29 Apr 2026 | Lepida S.c.p.A.Lepida S.c.p.A. was fined by the Italian supervisory authority Garante €100,000 for unauthorized access and data handling violations linked to SPID digital identity management. The authority found breaches of GDPR Articles 25 and 32, covering data protection by design and security of processing. | IT | Garante | GDPR | €100,000 | ↗ |
| 28 Apr 2026 | RESIDENCIAL ETXE-LAN, S.L.RESIDENCIAL ETXE-LAN, S.L. was fined by the AEPD for failing to provide the required information to the supervisory authority. The breach concerned Article 58(1) GDPR and hindered the authority’s supervisory powers. | ES | AEPD | GDPR | €3,000 | ↗ |
| 28 Apr 2026 | Fondation YThe APD Litigation Chamber fined Fondation Y EUR 1,000 for failing to respond to a data erasure request. The authority also found negligent cooperation with the data protection authority, constituting a breach of Article 31 GDPR. | BE | APD | GDPR | €1,000 | ↗ |
| 28 Apr 2026 | CROWD ENTERTAINMENT LIMITEDCROWD ENTERTAINMENT LIMITED was fined EUR 15,000 by ANSPDCP for GDPR violations. The case concerned non-compliant processing of personal data. | RO | ANSPDCP | GDPR | €15,000 | ↗ |
| 28 Apr 2026 | vzwDecision on the merits No. 94/2026 of 28 April 2026 was issued by the Belgian Gegevensbeschermingsautoriteit. A Belgian vzw was fined EUR 1,000 for failing to respond to registered letters and failing to appear at the hearing, which was treated as a breach of the GDPR cooperation duty. | BE | Gegevensbeschermingsautoriteit (GBA) | GDPR | €1,000 | ↗ |
| 28 Apr 2026 | CROWD ENTERTAINMENT LIMITEDCROWD ENTERTAINMENT LIMITED was fined EUR 20,000 by the Romanian authority ANSPDCP. The sanction concerned violations of GDPR requirements. | RO | ANSPDCP | GDPR | €20,000 | ↗ |
| 28 Apr 2026 | SIPHONE 2020, S.L.SIPHONE 2020, S.L. was fined by the AEPD 4,000 EUR for operating a video surveillance system that also recorded audio. Employees were not informed and did not consent, which breached privacy and data protection rules. | ES | AEPD | GDPR | €4,000 | ↗ |
| 28 Apr 2026 | POSADA DEL LEÓN DE ORO, C.B.POSADA DEL LEÓN DE ORO, C.B. was fined EUR 400 by the AEPD for improper use of a surveillance system that recorded audio and video. The authority found violations of employee privacy and of the duty to inform data subjects about processing, contrary to GDPR Articles 5(1)(c) and 13. | ES | AEPD | GDPR | €400 | ↗ |
| 17 Apr 2026 | Comune di Campo CalabroThe Garante fined Comune di Campo Calabro EUR 6,000 for publishing personal data online. The case concerned a breach of data protection rules and the unlawful disclosure of information. | IT | Garante | GDPR | €6,000 | ↗ |