BULLETIN №081Last updated · 27 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -20.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 14 May 2026 | EmiratesEmirates was fined by the Italian Garante €180,000 for breaching data protection rules. The airline required passengers with reduced mobility to complete a medical form without providing adequate information about how their data would be processed. | IT | Garante | GDPR | €180,000 | ↗ |
| 27 Apr 2023 | Roma CapitaleRoma Capitale was fined EUR 176,000 by the Garante for the unlawful processing and dissemination of personal health data relating to women who had terminated pregnancies. The sensitive information was displayed on crosses at a cemetery, creating a serious data protection breach. | IT | Garante | GDPR | €176,000 | ↗ |
| 17 Dec 2025 | Stichting Hogeschool van Arnhem en NijmegenThe Autoriteit Persoonsgegevens imposed a fine of €175,000 on Stichting Hogeschool van Arnhem en Nijmegen for failing to implement adequate technical and organizational measures appropriate to the risk. These deficiencies resulted in a data breach. | NL | AP | GDPR | €175,000 | ↗ |
| 20 Mar 2025 | FAVORIT SPORTSKA KLADIONICA d.o.o.FAVORIT SPORTSKA KLADIONICA d.o.o. was fined by AZOP EUR 175,000 for failing to store personal data only as long as necessary and for not implementing appropriate technical safeguards. The case concerned breaches of Articles 5 and 32 of the GDPR. | HR | AZOP | GDPR | €175,000 | ↗ |
| 08 Oct 2020 | Anonymizováno (ÚOOÚ UOOU-00179/19-38)The entity was fined for retaining personal data of financial service applicants longer than necessary, failing to inform them about potential data recipients, and lacking internal data protection measures. The authority found these practices inconsistent with data protection obligations. | CZ | UOOU | GDPR | €6,459 | ↗ |
| 07 Jul 2022 | SOCIETE DE LOCATION DE VEHICULESCNIL imposed a fine of EUR 175,000 on SOCIETE DE LOCATION DE VEHICULES. The case concerned a breach of personal data protection rules. | FR | CNIL | GDPR | €175,000 | ↗ |
| 10 Oct 2023 | Hogeschool van Arnhem en Nijmegen (HAN)The Autoriteit Persoonsgegevens imposed a fine of EUR 175,000 on Hogeschool van Arnhem en Nijmegen (HAN). The authority found that the institution did not provide sufficient protection for students’ personal data. | NL | Autoriteit Persoonsgegevens | GDPR | €175,000 | ↗ |
| 28 May 2015 | El Dom S.a.s.El Dom S.a.s. was fined EUR 174,000 by the Garante for activating 185 phone cards under the names of 58 individuals without their knowledge. The case involved a breach of data protection rules and the unauthorized use of personal identification data. | IT | Garante | GDPR | €174,000 | ↗ |
| 12 Dec 2024 | Breathe Services LtdBreathe Services Ltd, a debt advice company based in Bolton, was investigated by the ICO following complaints about unsolicited calls to potentially vulnerable individuals. The ICO found that the company spoofed outbound numbers and made 4,376,037 unsolicited direct marketing calls to numbers registered with the Telephone Preference Service, generating multiple complaints. | GB | ICO | GDPR | €206,000 | ↗ |
| 03 Feb 2021 | MERCADONA S.A.MERCADONA S.A. was fined EUR 170,000 by the AEPD for failing to respond to a data access request within the required timeframe and for deleting security camera footage. The authority found that these actions breached GDPR obligations, including Articles 12 and 6. | ES | AEPD | GDPR | €170,000 | ↗ |
| 30 Mar 2026 | Energy Prices Direct LimitedThe ICO fined Energy Prices Direct Limited, an energy switching services provider, for breaches of the PECR. The company obtained data from public sources and list providers, but failed to screen it against the TPS/CTPS registers before making marketing calls. | GB | ICO | ePrivacy | €184,000 | ↗ |
| 29 Feb 2024 | WATIUM S.L.WATIUM S.L. was fined by the Spanish Data Protection Agency (AEPD) in the amount of EUR 160,000. The case concerned the failure to provide the required information, which constitutes a breach of Article 58.1 of the GDPR. | ES | AEPD | GDPR | €160,000 | ↗ |
| 21 Dec 2011 | Edreams s.r.l.Edreams s.r.l. was fined €160,000 by the Garante for sending unsolicited commercial emails without obtaining the required consent. The case concerned breaches of data protection rules and direct marketing requirements. | IT | Garante | GDPR | €160,000 | ↗ |
| 08 Mar 2018 | Yahoo! Emea Limited oggi Oath (Emea) LimitedYahoo! Emea Limited, now Oath (Emea) Limited, was fined 160,000 EUR by the Garante. The authority found that the company failed to comply with a request to remove specific URLs containing personal information from Yahoo! Search. | IT | Garante | GDPR | €160,000 | ↗ |
| 21 Jun 2021 | DKN.5131.3.2021StatusprawomocnaTytuUODO imposed an administrative fine of PLN 159,176 on an insurance company. The authority found that the company failed to notify the President of UODO of a personal data breach within the required timeframe. | PL | UODO | GDPR | €35,116 | ↗ |
| 06 Mar 2024 | Sectorul 1 al Municipiului BucureștiSectorul 1 of Bucharest was fined 159,000 RON by ANSPDCP for failing to comply with a remediation measure. The authority had required the requested information to be provided within 10 days, but the obligation was not met. | RO | ANSPDCP | GDPR | €31,988 | ↗ |
| 11 Apr 2023 | CORPORACION DE MEDIOS DE EXTREMADURA, S.A.The entity published a video containing personal data of 56 women registered as victims of gender-based violence. The authority found a breach of the data minimization principle and imposed a 150,000 EUR fine. | ES | AEPD | GDPR | €150,000 | ↗ |
| 25 Jun 2025 | Vodafone-PanafonVodafone-Panafon was fined EUR 150,000 by the HDPA for inadequate technical and organizational security measures. The authority found a violation of Article 12 of Law 3471/2006. | GR | HDPA | ePrivacy | €150,000 | ↗ |
| 25 Mar 2021 | Dragefossen ASDragefossen AS was fined 150,000 NOK by Datatilsynet for unlawfully live streaming surveillance footage from a camera in Rognan sentrum on the internet. The authority found no legal basis for the processing, which breached GDPR Articles 6 and 5. | NO | Datatilsynet | GDPR | €14,756 | ↗ |
| 17 Aug 2021 | UdlændingestyrelsenThe Danish DPA, Datatilsynet, recommended a fine of DKK 150,000 against Udlændingestyrelsen. The case concerned inadequate security measures in personal data processing, which could have affected the rights of residents at deportation centers. | DK | Datatilsynet | GDPR | €20,171 | ↗ |