BULLETIN №081Last updated · 27 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -20.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 30 Apr 2025 | Anonymisé (CNPD decision-03-fr-2025)The company did not maintain a complete record of processing activities as required by Article 30 GDPR. CNPD imposed an administrative fine of €11,964. | LU | CNPD | GDPR | €11,964 | ↗ |
| 30 Apr 2025 | BITDEFENDER SRLIn April 2025, the Romanian authority ANSPDCP completed an investigation into BITDEFENDER SRL and found a GDPR violation. The company was fined EUR 10,000. | RO | ANSPDCP | GDPR | €10,000 | ↗ |
| 29 Apr 2025 | Comune di San Francesco al CampoThe Garante imposed a fine of 1,200 EUR on Comune di San Francesco al Campo for violations related to the publication of personal data on its institutional website. The data were subsequently removed. | IT | Garante | GDPR | €1,200 | ↗ |
| 29 Apr 2025 | Comune di BolognaThe Garante imposed a fine of 40,000 EUR on Comune di Bologna for breaches of data protection principles. The case concerned non-compliance with requirements on lawfulness, fairness, transparency, and data minimization. | IT | Garante | GDPR | €40,000 | ↗ |
| 29 Apr 2025 | Energia Verde S.p.A.Energia Verde S.p.A. was fined EUR 100,000 by the Garante for making unsolicited promotional calls without a legal basis. The authority also found that the company did not adequately respond to data subjects' requests, indicating failures in data protection compliance. | IT | Garante | GDPR | €100,000 | ↗ |
| 29 Apr 2025 | Ordine degli Psicologi della Regione LombardiaThe Garante fined the Ordine degli Psicologi della Regione Lombardia EUR 30,000 for a data breach. The incident exposed personal and sensitive data of about 15,000 individuals, including information covered by professional secrecy and special categories of data. | IT | Garante | GDPR | €30,000 | ↗ |
| 29 Apr 2025 | Versilmagra Immobiliare di Robertelli Davide & C. S.a.s.Versilmagra Immobiliare was fined EUR 2,000 by the Garante. The authority found that the company sent unsolicited communications via WhatsApp without proper consent and did not facilitate the exercise of data subject rights. | IT | Garante | GDPR | €2,000 | ↗ |
| 29 Apr 2025 | Cooperativa Sociale QuadrifoglioThe Garante imposed a fine of EUR 20,000 on Cooperativa Sociale Quadrifoglio for violations related to data processing. The case concerned non-compliance with personal data protection requirements. | IT | Garante | GDPR | €20,000 | ↗ |
| 29 Apr 2025 | Energia Pulita S.r.l.Energia Pulita S.r.l. was fined by the Garante for improper handling of personal data in telemarketing activities. The authority also noted failure to cooperate with the supervisory authority and incorrect identification of roles in data processing. | IT | Garante | GDPR | €10,000 | ↗ |
| 29 Apr 2025 | Regione Emilia RomagnaThe Garante fined Regione Emilia Romagna EUR 15,000 for violations related to the processing of personal data for official statistical purposes. The authority found incorrect application of data protection principles and measures. | IT | Garante | GDPR | €15,000 | ↗ |
| 29 Apr 2025 | Comune di NoliComune di Noli was fined EUR 2,000 by the Garante for failing to ensure lawful, fair, and transparent processing of personal data. The authority also found a breach of data minimization because unauthorized access to unredacted images was possible through an online portal. | IT | Garante | GDPR | €2,000 | ↗ |
| 29 Apr 2025 | Tirrenia Hospital S.r.l.Tirrenia Hospital S.r.l. was fined by the Garante EUR 2,000 for breaching the data processing principles set out in GDPR Article 5. The case concerned processing in the healthcare sector, where a particularly high level of compliance is required. | IT | Garante | GDPR | €2,000 | ↗ |
| 29 Apr 2025 | Regione LombardiaThe Garante fined Regione Lombardia 50,000 EUR for violations related to the processing of personal data. The authority cited inadequate technical and organizational measures to protect data, as well as improper handling of employee metadata and internet navigation logs. | IT | Garante | GDPR | €50,000 | ↗ |
| 29 Apr 2025 | Ordine professionale degli psicologi della LombardiaOn 2025-04-29, the Italian Data Protection Authority fined the Ordine professionale degli psicologi della Lombardia EUR 30,000. The sanction concerned breaches of Articles 5(1)(f) and 32 GDPR following a data breach and the failure to implement adequate security measures. | IT | Garante per la protezione dei dati personali | GDPR | €30,000 | ↗ |
| 28 Apr 2025 | Xiting ROM SRLIn April 2025, ANSPDCP completed an investigation at Xiting ROM SRL and found violations of GDPR provisions. As a result, a fine of EUR 1,000 was imposed. | RO | ANSPDCP | GDPR | €1,000 | ↗ |
| 25 Apr 2025 | SC Travel Planner SRLSC Travel Planner SRL was fined EUR 5,000 by ANSPDCP for breaching Article 15 of the GDPR. The case concerned the improper handling of a data subject access request. | RO | ANSPDCP | GDPR | €5,000 | ↗ |
| 25 Apr 2025 | SC Travel Planner SRLSC Travel Planner SRL was fined EUR 1,000 by ANSPDCP for breaching Article 33 of the GDPR. The case concerned failure to notify a personal data breach to the supervisory authority. | RO | ANSPDCP | GDPR | €1,000 | ↗ |
| 24 Apr 2025 | Darian Bishop trading as ECO4UBetween 9 January 2023 and 9 October 2023, 194,110 unsolicited direct marketing calls were made to subscribers registered with the TPS who had not indicated consent to receive such calls. The conduct generated 21 complaints to the Commissioner and the TPS, leading to an ICO fine. | GB | ICO | GDPR | €58,480 | ↗ |
| 24 Apr 2025 | Dante International SAIn April 2025, ANSPDCP completed an investigation into Dante International SA and found violations of GDPR provisions. As a result, a fine of 10,000 EUR was imposed. | RO | ANSPDCP | GDPR | €10,000 | ↗ |
| 23 Apr 2025 | MetaThe European Commission fined Meta EUR 200 million for breaching the Digital Markets Act. The sanction concerns Meta’s “consent or pay” model used for Facebook and Instagram users in Europe. | IE | European Commission | DMA | €200,000,000 | ↗ |