BULLETIN №081Last updated · 28 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -20.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 14 Apr 2023 | Join the Triboo LimitedBetween 1 August 2019 and 19 August 2020, Join the Triboo Limited sent a confirmed total of 107 million direct marketing messages, of which 437,324 were received by distinct individuals. On average, each person received 244 emails during the period, and the messages contained direct marketing material without valid subscriber consent. | GB | ICO | GDPR | €146,000 | ↗ |
| 08 Jun 2023 | Crown Glazing LtdThe case was part of Operation Tinago, which assessed complaint trends in the energy and home improvements sector. Crown Glazing Ltd made 503,445 unsolicited calls to TPS-registered numbers between 4 January and 11 November 2021, resulting in 37 complaints. | GB | ICO | GDPR | €150,000 | ↗ |
| 01 Jan 2013 | GOOGLE INCGoogle Inc. was fined by the AEPD EUR 130,000 for failing to provide adequate information on privacy and cookie policies on a website. The authority found a breach of the LSSI information requirements toward users. | ES | AEPD | ePrivacy | €130,000 | ↗ |
| 01 Jan 2024 | DIGI SPAIN TELECOM, S.L.DIGI SPAIN TELECOM, S.L. was fined by the AEPD 130,000 EUR for unauthorized SIM card duplication. The incident led to identity theft and fraudulent charges, and the authority found the data protection measures insufficient. | ES | AEPD | GDPR | €130,000 | ↗ |
| 23 Jun 2025 | City of Dublin Education and Training Board (CDETB)The Irish supervisory authority concluded an inquiry into City of Dublin Education and Training Board (CDETB) and found GDPR infringements linked to a personal data breach. It imposed administrative fines totaling EUR 125,000 and issued a reprimand on 23 June 2025. | IE | Data Protection Commission (Ireland) | GDPR | €125,000 | ↗ |
| 23 Jun 2025 | City of Dublin Education and Training Board (CDETB)The Irish DPC imposed a fine of EUR 125,000 on City of Dublin Education and Training Board (CDETB) in inquiry IN-19-7-3. The fine status is collected. | IE | DPC | GDPR | €125,000 | ↗ |
| 14 Dec 2022 | Monetise Media LimitedBetween 28 July 2020 and 28 July 2021, Monetise Media Limited sent 3,506,157 direct marketing emails and text messages. The recipients had not provided valid consent, which breached regulation 22 of PECR. | GB | ICO | ePrivacy | €145,000 | ↗ |
| 16 Mar 2023 | SOCIETE DE LOCATION DE SCOOTERS ELECTRIQUES EN LIBRE-SERVICEThe CNIL imposed a fine of EUR 125,000 on SOCIETE DE LOCATION DE SCOOTERS ELECTRIQUES EN LIBRE-SERVICE. The case concerns a confirmed breach of rules supervised by the data protection authority. | FR | CNIL | GDPR | €125,000 | ↗ |
| 11 May 2020 | Hälso- och sjukvårdsnämnden i Region Örebro länHälso- och sjukvårdsnämnden i Region Örebro län was fined by IMY 120,000 SEK for publishing sensitive personal data on its website without a legal basis. The authority found breaches of GDPR Articles 5, 6, 9, and 32. | SE | IMY | GDPR | €11,321 | ↗ |
| 27 May 2021 | Azienda Usl della RomagnaAzienda Usl della Romagna was fined by the Garante in the amount of EUR 120,000 for violations related to the processing of a patient's health data in the gynecology department. The case also involved issues with electronic health records and data breaches. | IT | Garante | GDPR | €120,000 | ↗ |
| 06 Jun 2024 | Cappello Giovanni & figli s.r.l.Cappello Giovanni & figli s.r.l. was fined by Garante for unlawful processing of employee personal data using Infinity DMS software and X.-Face 380 hardware. The authority found that the company's practices breached GDPR principles. | IT | Garante | GDPR | €120,000 | ↗ |
| 26 Oct 2011 | H3G S.p.A.H3G S.p.A. was fined EUR 120,000 by the Garante for sending unsolicited promotional communications to a fixed telephone line. The conduct breached data protection provisions. | IT | Garante | GDPR | €120,000 | ↗ |
| 02 Oct 2025 | TIGER MEDIA INC.TIGER MEDIA INC. was fined by the AEPD EUR 120,000 for processing personal data without a lawful basis. The authority also found that the company failed to appoint an EU representative, in breach of GDPR Articles 6 and 27. | ES | AEPD | GDPR | €120,000 | ↗ |
| 05 Jul 2019 | VODAFONE ESPAÑA SAUVODAFONE ESPAÑA SAU was fined €120,000 by the AEPD for failing to exercise due diligence in response to a fraudulent situation involving unauthorized service contracts. The authority found a breach of Article 6 GDPR. | ES | AEPD | GDPR | €120,000 | ↗ |
| 08 Jun 2023 | Maxen Power Supply LimitedMaxen Power Supply Limited used overseas call centres to make unsolicited marketing calls to businesses. The conduct breached regulations 21 and 24 of PECR, and the ICO imposed a fine of 120,000 GBP and issued an enforcement notice. | GB | ICO | ePrivacy | €139,000 | ↗ |
| 15 Jan 2026 | Allay Claims Ltd The ICO issued an MPN and EN to Allay Claims Ltd after a large volume of unsolicited SMS messages promoting PPI tax refund services. The case indicates a breach of direct marketing and electronic communications rules. | GB | ICO | GDPR | €138,000 | ↗ |
| 12 Dec 2024 | Money Bubble Ltd MPNBetween October and November 2022, the company made 168,852 spam calls, leading to further complaints to the ICO and TPS. Money Bubble Ltd MPN did not provide evidence that the called individuals had consented to receive calls. The ICO imposed a £120,000 fine. | GB | ICO | GDPR | €145,000 | ↗ |
| 14 Dec 2017 | Salvatore AloiSalvatore Aloi was fined EUR 120,000 by the Italian Garante. The case concerned the processing of personal data of 12 individuals without consent, by activating phone cards in their names without authorization. | IT | Garante | GDPR | €120,000 | ↗ |
| 27 May 2021 | Tempocasa S.p.A.Tempocasa S.p.A. was fined €120,000 by the Italian Garante. The authority found that the company made unsolicited promotional calls without the required consent, breaching GDPR rules on data processing and consent. | IT | Garante | GDPR | €120,000 | ↗ |
| 12 Apr 2012 | Alitalia – Compagnia Aerea Italiana s.p.a.Alitalia was fined by the Garante for inadequate data protection measures and for failing to provide proper information to customers during call center interactions. The authority found that these practices breached Italian data protection law. | IT | Garante | GDPR | €120,000 | ↗ |