BULLETIN №081Last updated · 28 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -20.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 15 Oct 2024 | Quick Tax Claims LimitedThe ICO found that Quick Tax Claims Limited sent 7,863,547 unlawful text messages over one month, generating 66,793 complaints. In 93% of complaints, recipients said there was no opt-out option, and the company had bought personal data from suppliers without valid consent. | GB | ICO | GDPR | €143,000 | ↗ |
| 01 Jan 2024 | DIGI SPAIN TELECOM, S.L.DIGI SPAIN TELECOM, S.L. was fined by the AEPD 120,000 EUR for a data protection breach involving unauthorized SIM card duplication. The incident enabled fraudulent activity, and the authority found that the company had not implemented sufficient preventive measures. | ES | AEPD | GDPR | €120,000 | ↗ |
| 31 Mar 2021 | Anonymizováno (ÚOOÚ UOOU-04077/20-13)The entity was fined for processing personal data from public registers without a legal basis and for failing to respond to a data subject's erasure request. The case highlights deficiencies in lawful processing and in handling data subject rights. | CZ | UOOU | GDPR | €4,590 | ↗ |
| 21 Mar 2024 | Regione LazioThe Garante fined Regione Lazio EUR 120,000 for inadequate security measures that led to attempted unauthorized access to user accounts. The authority found a breach of GDPR requirements on data protection and processing security. | IT | Garante | GDPR | €120,000 | ↗ |
| 15 Dec 2022 | Assiteca S.p.A.Assiteca S.p.A. was fined EUR 120,000 by the Garante for violations related to the processing of personal data for marketing purposes. The authority also found inadequate responses to data subject requests. The case highlights the need for proper handling of individual rights and GDPR-compliant marketing practices. | IT | Garante | GDPR | €120,000 | ↗ |
| 04 Oct 2025 | OVH HISPANO, S.L.U.OVH HISPANO, S.L.U. was fined by the AEPD 120,000 EUR for a data protection breach. Confidential emails and documents of third parties were improperly shared due to inadequate data protection measures. | ES | AEPD | GDPR | €120,000 | ↗ |
| 16 Jan 2020 | VODAFONE ESPAÑA SAUVODAFONE ESPAÑA SAU was fined 120,000 EUR by the AEPD for unlawful processing of personal data. The case involved threatening to include a minor's data in a credit file over an alleged unpaid debt. | ES | AEPD | GDPR | €120,000 | ↗ |
| 18 Dec 2025 | Pioneer Hi-Bred Italia Sementi s.r.l.Pioneer Hi-Bred Italia Sementi s.r.l. was fined by the Garante 120,000 EUR for installing telematic devices in company vehicles to monitor employees' driving behavior. The authority found that the processing lacked proper data protection safeguards and privacy information. | IT | Garante | GDPR | €120,000 | ↗ |
| 20 Dec 2019 | Anonymizováno (ÚOOÚ UOOU-00136/19-31)The company was fined for disseminating commercial communications without a legal basis and without proper labeling. The authority found a breach of Czech rules on information society services. | CZ | UOOU | ePrivacy | €4,716 | ↗ |
| 30 Nov 2023 | Dane anonimowe (L. Sp. z o.o. z siedzibą we W.)UODO imposed an administrative fine of PLN 117,900 on L. Sp. z o.o. for failing to implement appropriate technical and organizational measures proportionate to the risk of data processing. The authority found deficiencies in ensuring system availability, resilience, and the ability to quickly restore access to personal data after a physical or technical incident. | PL | UODO | GDPR | €27,110 | ↗ |
| 21 Mar 2013 | Giant s.r.l.Giant s.r.l. was fined 114,000 EUR by the Garante for the unauthorized registration of numerous phone cards to third parties without their knowledge. The authority found this conduct to be in breach of data protection rules. | IT | Garante | GDPR | €114,000 | ↗ |
| 24 Jul 2014 | Easy Call srlEasy Call srl was fined EUR 112,000 by the Garante for making unsolicited promotional calls. The company contacted individuals listed in the opposition register, breaching data protection rules. | IT | Garante | GDPR | €112,000 | ↗ |
| 14 Jun 2018 | Faiella Nicola s.r.l.Faiella Nicola s.r.l. was fined EUR 112,000 by the Garante for improper processing of personal data using geolocation and video surveillance systems. The authority found that the company did not comply with data protection requirements when deploying these tools. | IT | Garante | GDPR | €112,000 | ↗ |
| 13 Nov 2023 | Rompetrol Downstream SRLRompetrol Downstream SRL was fined EUR 110,000 by ANSPDCP for failing to ensure the security of personal data. The authority found a breach of Article 32 GDPR, which requires appropriate technical and organizational measures. | RO | ANSPDCP | GDPR | €110,000 | ↗ |
| 09 Dec 2021 | Limerick City and County CouncilThe Irish DPC imposed a fine of EUR 110,000 on Limerick City and County Council in inquiry 03/SIU/2018. The penalty has been collected. | IE | DPC | GDPR | €110,000 | ↗ |
| 11 Apr 2013 | Zeno VincoZeno Vinco was fined by the Garante for registering SIM cards to 36 individuals without their knowledge. The case involved a breach of data protection rules. | IT | Garante | GDPR | €108,000 | ↗ |
| 29 Dec 2023 | SOCIETE PERMETTANT D'EFFECTUER DES PAIEMENTS EN LIGNEA fine of EUR 105,000 was imposed by the CNIL. The case concerns a breach of personal data protection rules. | FR | CNIL | GDPR | €105,000 | ↗ |
| 11 Dec 2025 | ZMLUK LimitedZMLUK Limited received an MPN from the ICO for sending unsolicited emails promoting energy-saving products. The case concerns a breach of electronic marketing rules and should be reviewed for compliance with applicable consent requirements. | GB | ICO | GDPR | €119,000 | ↗ |
| 18 Oct 2023 | Dane anonimowe (J. Towarzystwo Ubezpieczeń S.A. z siedzibą w N.)UODO imposed an administrative fine of PLN 103,752 on J. Towarzystwo Ubezpieczeń S.A. The authority found that the company failed to notify the supervisory authority of a personal data breach without undue delay. | PL | UODO | GDPR | €23,362 | ↗ |
| 18 Apr 2013 | Itel s.r.l. UnipersonaleItel s.r.l. Unipersonale was fined EUR 102,000 by the Garante for improper processing of personal data. The case involved registering phone cards to third parties without their knowledge, in breach of privacy rules. | IT | Garante | GDPR | €102,000 | ↗ |