BULLETIN №081Last updated · 27 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -20.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 16 Jun 2025 | Υφυπουργείο Κοινωνικής ΠρόνοιαςThe Cypriot Data Protection Commissioner imposed an administrative fine of EUR 5,000 on Υφυπουργείο Κοινωνικής Πρόνοιας on 16 June 2025. The case concerned CCTV cameras at the ministry’s headquarters, including three cameras that recorded audio without a legal basis and without the required GDPR safeguards. | CY | Επίτροπος Προστασίας Δεδομένων Προσωπικού Χαρακτήρα | GDPR | €5,000 | ↗ |
| 13 Jun 2025 | GRUPO BONATEL SLGRUPO BONATEL SL was fined by the AEPD after an incident in which its database was encrypted and a ransom was demanded to prevent public disclosure. The authority found a breach of Article 5(1)(f) GDPR on integrity and confidentiality of personal data. | ES | AEPD | GDPR | €30,000 | ↗ |
| 13 Jun 2025 | Anonymised (HDPA 21/2025)A fine of EUR 1,000 was imposed for violating the data subject’s right of access. The entity did not provide the requested video footage. | GR | HDPA | GDPR | €1,000 | ↗ |
| 13 Jun 2025 | HEP - Toplinarstvo d.o.o.HEP - Toplinarstvo d.o.o. was fined EUR 320,000 for failing to implement appropriate technical and organizational measures to protect data in its “Moj račun” application. The authority also found a lack of cooperation with the supervisory authority, including refusal to provide required information. | HR | AZOP | GDPR | €320,000 | ↗ |
| 13 Jun 2025 | Anonymised (HDPA 21/2025)A fine was imposed for breaching the principles of lawfulness, fairness, and transparency in data processing in connection with a video surveillance system. The case concerned improper processing of personal data through video monitoring. | GR | HDPA | GDPR | €2,000 | ↗ |
| 12 Jun 2025 | Krajowa Szkoła Sądownictwa i Prokuratury (KSSiP)The President of the Polish data protection authority imposed a PLN 100,000 fine on the National School of Judiciary and Public Prosecution for breaching data protection rules during a data migration. The Supreme Administrative Court upheld the decision, making the sanction final. | PL | Urząd Ochrony Danych Osobowych | GDPR | €23,425 | ↗ |
| 10 Jun 2025 | Accounting Audit SRLAccounting Audit SRL was fined by ANSPDCP for a data security breach caused by a cyber attack. The incident led to unauthorized disclosure of personal data, including identification data and financial documents, affecting a large number of data subjects, mainly employees of the company’s clients. | RO | ANSPDCP | GDPR | €10,000 | ↗ |
| 09 Jun 2025 | Department of Social ProtectionThe Irish DPC imposed a fine of €550,000 on the Department of Social Protection in inquiry IN-21-7-3. The matter is currently pending appeal (TBC). | IE | DPC | GDPR | €550,000 | ↗ |
| 05 Jun 2025 | 23andMeThe UK ICO imposed a GBP 2,310,000 fine on 23andMe for personal data protection breaches. The case concerned inadequate safeguards and processing failures that increased the risk of unauthorized access to user data. | GB | ICO | GDPR | €2,743,000 | ↗ |
| 05 Jun 2025 | SOCIETE AYANT POUR ACTIVITE PRINCIPALE L'EDITION (procédure simplifiée)CNIL imposed an administrative fine of EUR 10,000 on SOCIETE AYANT POUR ACTIVITE PRINCIPALE L'EDITION and issued an injunction. The case was handled under a simplified procedure. | FR | CNIL | GDPR | €10,000 | ↗ |
| 05 Jun 2025 | SOCIETE AYANT POUR ACTIVITE LA FABRICATION ET LE COMMERCE DE PRODUITS PHARMACEUTIQUES DESTINES AU SECTEUR ALIMENTAIRE (procédure simplifiée)The CNIL imposed an administrative fine of 5,000 EUR on the company. The decision was issued under a simplified procedure. | FR | CNIL | GDPR | €5,000 | ↗ |
| 05 Jun 2025 | SOCIETE EXERCANT UNE ACTIVITE HOSPITALIERE A BUT LUCRATIF EN MEDECINE-CHIRURGIE-OBSTETRIQUE (procédure simplifiée)The CNIL imposed an administrative fine of 5,000 EUR on SOCIETE EXERCANT UNE ACTIVITE HOSPITALIERE A BUT LUCRATIF EN MEDECINE-CHIRURGIE-OBSTETRIQUE under a simplified procedure. The decision concerns a confirmed compliance breach and was issued by the French data protection authority. | FR | CNIL | GDPR | €5,000 | ↗ |
| 04 Jun 2025 | Comune di PompeiThe Garante fined Comune di Pompei EUR 5,000 for failing to provide the Authority with the contact details of its Data Protection Officer. The breach concerned the notification duty under Article 37 GDPR. | IT | Garante | GDPR | €5,000 | ↗ |
| 04 Jun 2025 | impresa individuale Pasquale GuadagnoThe company was fined for installing a surveillance camera without proper signage. The camera also captured areas beyond its commercial premises, which breached data protection rules. | IT | Garante | GDPR | €2,000 | ↗ |
| 04 Jun 2025 | Comune di ReccoThe Garante fined Comune di Recco EUR 5,000 for inadequate data protection measures linked to video surveillance used to monitor waste disposal. The authority found breaches of the principles of lawfulness, fairness, and transparency. | IT | Garante | GDPR | €5,000 | ↗ |
| 04 Jun 2025 | Noi Compriamo Auto.it S.r.l.On 4 June 2025, the Italian Data Protection Authority fined Noi Compriamo Auto.it S.r.l. for GDPR breaches in email marketing. The authority found that the company sent promotional emails without consent, failed to properly govern its processors, and did not adequately support data subject rights. | IT | Garante per la protezione dei dati personali | GDPR | €27,800,000 | ↗ |
| 04 Jun 2025 | INTS Italia S.r.l.INTS Italia S.r.l. was fined 15,000 EUR by the Garante for failing to provide employees with adequate information on data protection and for not responding to data access requests. The authority found that the company breached core GDPR principles. | IT | Garante | GDPR | €15,000 | ↗ |
| 04 Jun 2025 | Noi Compriamo Auto.it S.r.l.The Italian Supervisory Authority fined Noi Compriamo Auto.it S.r.l. 45,000 EUR for sending unsolicited promotional emails without proper consent documentation. The case indicates a breach of GDPR requirements for lawful direct marketing. | IT | Garante | GDPR | €45,000 | ↗ |
| 04 Jun 2025 | Yliopiston ApteekkiThe Finnish Data Protection Ombudsman’s sanctions board imposed a EUR 1.1 million fine on Yliopiston Apteekki for data protection deficiencies. The decision states that cookies and other tracking technologies used in the online pharmacy disclosed prescription-related and other customer data to Google and Meta. | FI | Office of the Data Protection Ombudsman | GDPR | €1,100,000 | ↗ |
| 04 Jun 2025 | Comune di RoccaforzataComune di Roccaforzata was fined EUR 8,000 by the Garante for publishing sensitive health data, including an employee’s disability percentage, in a council resolution. The authority found a breach of the GDPR and national privacy code provisions. | IT | Garante | GDPR | €8,000 | ↗ |