BULLETIN №081Last updated · 27 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -20.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 04 Jun 2025 | Comune di LatinaThe Garante fined Comune di Latina EUR 4,000 for violations linked to the activation process for the “Dedicata a te” card. Requiring a payment to avoid cancellation of the benefit raised compliance concerns. | IT | Garante | GDPR | €4,000 | ↗ |
| 04 Jun 2025 | Istituto d’Istruzione Superiore “Carlo e Nello Rosselli”The Garante imposed a EUR 4,000 fine on Istituto d’Istruzione Superiore “Carlo e Nello Rosselli” for failing to appoint a Data Protection Officer and for delaying notification of the DPO’s contact details to the authority. The authority also found that transparency obligations toward data subjects were not met. | IT | Garante | GDPR | €4,000 | ↗ |
| 03 Jun 2025 | Spotify ABOn 2025-06-03, Kammarrätten ruled that Spotify AB must pay an administrative fine of 58 million SEK. The case concerned insufficient transparency and inadequate information to data subjects under the GDPR, following an investigation by Integritetsskyddsmyndigheten. | SE | Integritetsskyddsmyndigheten (IMY) | GDPR | €5,309,000 | ↗ |
| 03 Jun 2025 | VodafoneVodafone was fined EUR 45 million by Germany’s federal data protection authority for GDPR-related privacy violations. The case involved weaknesses in authentication and partner oversight that could allow unauthorized access to customer data and eSIM profiles. | DE | Bundesbeauftragte für den Datenschutz und die Informationsfreiheit (BfDI) | GDPR | €45,000,000 | ↗ |
| 03 Jun 2025 | Regione LombardiaThe Italian Data Protection Authority, Garante per la protezione dei dati personali, imposed a EUR 50,000 fine on Regione Lombardia. The case concerned unlawful retention of employees' email metadata, excessive retention of web browsing logs, and prolonged storage of helpdesk ticket data. | IT | Garante per la protezione dei dati personali | GDPR | €50,000 | ↗ |
| 03 Jun 2025 | B*** Parkraumbewirtschaftung Ges.m.b.H.The company was fined by the Austrian Data Protection Authority (DSB) for failing to cooperate during the investigation. It did not respond to multiple requests for statements or to a summons for an oral hearing, which constitutes a breach of Article 31 GDPR. | AT | DSB | GDPR | €16,000 | ↗ |
| 03 Jun 2025 | Dane anonimowe (Gminny Ośrodek Pomocy Społecznej w K.)UODO imposed an administrative fine of 5,000 PLN on Gminny Ośrodek Pomocy Społecznej w K. The authority found insufficient technical and organizational measures to secure personal data processing, as well as a failure to regularly test and assess the effectiveness of those safeguards. | PL | UODO | GDPR | €1,168 | ↗ |
| 01 Jun 2025 | Călin GeorgescuCălin Georgescu was sanctioned by Romania’s data protection authority after an investigation into his website. Two fines totaling about EUR 10,000 were imposed for installing cookies without consent and collecting personal data without proper notice. | RO | Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal | GDPR | €10,000 | ↗ |
| 30 May 2025 | AG-BROKER ASIGURARE S.R.L.AG-BROKER ASIGURARE S.R.L. was fined 5,000 EUR by ANSPDCP. The sanction concerned the failure to notify a personal data security breach. | RO | ANSPDCP | GDPR | €5,000 | ↗ |
| 29 May 2025 | IMMUCURA MED, S.L.IMMUCURA MED, S.L. was fined EUR 20,000 by the AEPD for failing to provide access to personal data and the information requested by the data protection authority. The conduct was found to breach Article 58(1) of the GDPR. | ES | AEPD | GDPR | €20,000 | ↗ |
| 25 May 2025 | ENTIDAD DE CONSERVACION TORREMIRONAThe entity was fined by the AEPD for operating a video surveillance system that excessively covered public areas. This infringed the privacy of residents and passersby. | ES | AEPD | GDPR | €5,000 | ↗ |
| 23 May 2025 | OCI CINE, S.L.OCI CINE, S.L. was fined EUR 30,000 by the AEPD after an incident in which a user's personal information was auto-filled with another person's details in its app. The authority found a breach of data accuracy and processing security principles. | ES | AEPD | GDPR | €30,000 | ↗ |
| 22 May 2025 | Dumitru Viorel FocșaThe National Supervisory Authority for Personal Data Processing imposed a fine on Dumitru Viorel Focșa for GDPR violations. The case followed a complaint from a data subject. | RO | ANSPDCP | GDPR | €1,000 | ↗ |
| 21 May 2025 | Autostrade per l'Italia SpaThe Italian data protection authority fined Autostrade per l'Italia Spa EUR 420,000 for unlawfully processing an employee's personal data. The company used content from her Facebook profile and private Messenger and WhatsApp chats to support disciplinary proceedings and justify her dismissal. | IT | Garante per la protezione dei dati personali | GDPR | €420,000 | ↗ |
| 21 May 2025 | Data Diggers Market Research SRLData Diggers Market Research SRL was fined EUR 2,000 by ANSPDCP for another violation related to the processing of personal data. The case indicates non-compliance with data protection requirements and calls for a review of processing procedures. | RO | ANSPDCP | GDPR | €2,000 | ↗ |
| 21 May 2025 | Data Diggers Market Research SRLThe company was fined EUR 5,000 by ANSPDCP for failing to provide complete information to complainants exercising their right of access to personal data. The case concerns the obligation to respond fully to access requests. | RO | ANSPDCP | GDPR | €5,000 | ↗ |
| 21 May 2025 | SILVANERGIA 2022, S.L.SILVANERGIA 2022, S.L. was fined by the AEPD EUR 5,000 for processing personal data without a legal basis, in breach of Article 6(1) GDPR. The case involved misleading a customer into confirming personal data over the phone. | ES | AEPD | GDPR | €5,000 | ↗ |
| 21 May 2025 | Data Diggers Market Research SRLData Diggers Market Research SRL was fined EUR 5,000 by ANSPDCP. The authority found that the company did not provide complainants with complete information when they exercised their right of access to personal data. | RO | ANSPDCP | GDPR | €5,000 | ↗ |
| 21 May 2025 | Menarini Silicon Biosystems SpAThe Garante imposed a 21,000 EUR fine on Menarini Silicon Biosystems SpA for violations related to personal data processing. The case involved inadequate safeguards in the use of algorithms to identify at-risk patients and online reports accessible to other patients. | IT | Garante | GDPR | €21,000 | ↗ |
| 21 May 2025 | NN ΕλληνικήThe Greek Data Protection Authority imposed a €22,000 fine on NN Ελληνική for refusing to provide recorded telephone calls in response to a data subject access request. The case concerns failure to comply with access rights obligations under data protection law. | GR | Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα | GDPR | €22,000 | ↗ |