BULLETIN №081Last updated · 27 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -20.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 10 Apr 2025 | Azienda Ospedaliera Universitaria Integrata VeronaAzienda Ospedaliera Universitaria Integrata Verona was fined by the Garante for failing to adequately protect personal data. After a ransomware attack, 612 GB of data was published on the dark web, indicating serious security shortcomings. | IT | Garante | GDPR | €10,000 | ↗ |
| 10 Apr 2025 | Acea EnergiaAcea Energia was fined EUR 3,000,000 by the Garante. The authority found unauthorized telemarketing activities and insufficient protection of databases against access by unauthorized agents. | IT | Garante | GDPR | €3,000,000 | ↗ |
| 10 Apr 2025 | SOCIETE DE COMMERCE DE DETAIL D'ARTICLES DE SPORT EN MAGASIN SPECIALISE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 20,000 on SOCIETE DE COMMERCE DE DETAIL D'ARTICLES DE SPORT EN MAGASIN SPECIALISE. The case was handled under a simplified procedure. | FR | CNIL | GDPR | €20,000 | ↗ |
| 10 Apr 2025 | Luka Inc.The Italian data protection authority fined Luka Inc., the US company behind the Replika chatbot, EUR 5,000,000. The 2025-04-10 decision concerned inadequate age verification, an unlawful processing basis, and missing privacy notice information required under the GDPR. | IT | Garante per la protezione dei dati personali | GDPR | €5,000,000 | ↗ |
| 10 Apr 2025 | Provvedimento del 10 aprile 2025 [10144184]A healthcare organization was fined after an employee accessed a patient's health dossier without authorization. The case highlights a breach of data protection rules in the healthcare sector. | IT | Garante | GDPR | €18,000 | ↗ |
| 10 Apr 2025 | Agenzia Mobilità Ambiente e Territorio S.r.l.The Garante fined Agenzia Mobilità Ambiente e Territorio S.r.l. 9,000 EUR for failing to provide sufficient transparency to data subjects. The authority found a breach of the GDPR principles of lawfulness, fairness, and transparency. | IT | Garante | GDPR | €9,000 | ↗ |
| 10 Apr 2025 | Immobiliare Valdalpone S.r.l.Immobiliare Valdalpone S.r.l. was fined by the Garante 15,000 EUR for making unsolicited marketing calls without proper consent. The authority also found inadequate data protection measures. | IT | Garante | GDPR | €15,000 | ↗ |
| 10 Apr 2025 | Vogliocasa Holding & Servizi S.r.l.Vogliocasa Holding & Servizi S.r.l. was fined by the Garante EUR 5,000 for making unsolicited telemarketing calls promoting real estate brokerage services without valid consent. The company also failed to respond to the authority's information requests, which hindered the supervisory process. | IT | Garante | GDPR | €5,000 | ↗ |
| 10 Apr 2025 | Stefanelli FedericaThe Garante imposed a 45,000 EUR fine on Stefanelli Federica for processing personal data without proper consent in unauthorized call-center operations. The case also involved sensitive data, including payment method information, which could have led to unauthorized contract activations. | IT | Garante | GDPR | €45,000 | ↗ |
| 10 Apr 2025 | SOCIETE EXERCANT UNE ACTIVITE DE RESTAURATION (procédure simplifiée)The CNIL imposed an administrative fine of EUR 6,000 on SOCIETE EXERCANT UNE ACTIVITE DE RESTAURATION. The case was handled under a simplified procedure. | FR | CNIL | GDPR | €6,000 | ↗ |
| 10 Apr 2025 | Comune di Ponte nelle AlpiThe Garante fined Comune di Ponte nelle Alpi 4,000 EUR for breaches of GDPR Articles 5 and 6 and Article 2-ter of the Codice. The case concerned improper personal data processing activities. | IT | Garante | GDPR | €4,000 | ↗ |
| 10 Apr 2025 | Tensa Art Design S.A.Tensa Art Design S.A. was fined by ANSPDCP EUR 5,000 for GDPR violations related to its website www.lensa.ro. The case concerned non-compliant processing of personal data under data protection requirements. | RO | ANSPDCP | GDPR | €5,000 | ↗ |
| 08 Apr 2025 | Adatbiztonsági problémák ügyféladatbázis adatfeldolgozó általi költöztetése soránThe authority found that Ügyfél1 failed to implement appropriate security measures when processing data during the database migration. This breach of GDPR Article 32 resulted in a fine of 2,000,000 HUF. | HU | NAIH | GDPR | €4,920 | ↗ |
| 04 Apr 2025 | Unnamed bankThe Polish data protection authority imposed a fine of EUR 928,498.06 on a bank. The authority found that the bank failed to inform customers about a personal data breach. The case concerns post-incident notification obligations. | PL | Polish Data Protection Authority | GDPR | €928,000 | ↗ |
| 04 Apr 2025 | MEDCENTER SRLMEDCENTER SRL was fined EUR 30,000 by ANSPDCP for breaching GDPR requirements. The company failed to inform affected individuals about a personal data security breach. | RO | ANSPDCP | GDPR | €30,000 | ↗ |
| 03 Apr 2025 | SOCIETE DE COURTAGE EN TRAVAUX, CONSULTING EN BATIMENT ET TRAVAUX PUBLICS, ACHAT ET REVENTE DE MATERIEL, TRANSACTION IMMOBILIERE ET MAITRISE D'ŒUVRE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 10,000 and issued an injunction. The case was handled under a simplified procedure. | FR | CNIL | GDPR | €10,000 | ↗ |
| 03 Apr 2025 | Banca Transilvania S.A.Banca Transilvania S.A. was fined EUR 5,000 by ANSPDCP for processing personal data without a legal basis. The authority found a breach of the GDPR principle of lawfulness, fairness, and transparency. | RO | ANSPDCP | GDPR | €5,000 | ↗ |
| 03 Apr 2025 | SOCIETE SPECIALISEE DANS LE SECTEUR D'ACTIVITE DES SUPERETTES (procédure simplifiée)The CNIL imposed an administrative fine of EUR 5,000 on SOCIETE SPECIALISEE DANS LE SECTEUR D'ACTIVITE DES SUPERETTES and issued an injunction. The case was handled under a simplified procedure. | FR | CNIL | GDPR | €5,000 | ↗ |
| 02 Apr 2025 | BINBOX GLOBAL SERVICES S.R.L.In March 2025, Romania’s data protection authority ANSPDCP completed an investigation into BINBOX GLOBAL SERVICES S.R.L. The authority found a GDPR violation and imposed a fine of EUR 3,000. | RO | ANSPDCP | GDPR | €3,000 | ↗ |
| 01 Apr 2025 | Dane anonimowe (G. M. prowadzącą działalność gospodarczą pod firmą)UODO imposed an administrative fine of PLN 29,043 on the business operator. The authority found that appropriate technical and organizational measures proportionate to the risk of personal data processing were not implemented, and that their effectiveness was not regularly tested, measured, and assessed. | PL | UODO | GDPR | €6,938 | ↗ |