BULLETIN №082Last updated · 29 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 02 Jul 2015 | Lycamobile s.r.l.Lycamobile s.r.l. was fined EUR 102,000 by the Garante for failing to provide requested information on the retention of telephone and telematic traffic data. The case concerned a breach of data protection rules. | IT | Garante | GDPR | €102,000 | ↗ |
| 02 Jul 2025 | Hrvatski ured za osiguranjeAZOP imposed a 101,000 euro fine on Hrvatski ured za osiguranje (HUO) after finding that it had not implemented adequate technical and organizational measures to protect personal data. The decision followed an investigation into a major data leak affecting about 1.2 million vehicle owners in Croatia. | HR | AZOP | GDPR | €101,000 | ↗ |
| 31 Jan 2024 | EDITEUR DE SITE WEB PROPOSANT AUX PARTICULIERS DE PUBLIER OU CONSULTER DES ANNONCES IMMOBILIERES ET AUTRES SERVICESCNIL imposed an administrative fine of EUR 100,000 on EDITEUR DE SITE WEB PROPOSANT AUX PARTICULIERS DE PUBLIER OU CONSULTER DES ANNONCES IMMOBILIERES ET AUTRES SERVICES. The case concerns identified breaches of rules supervised by the CNIL. | FR | CNIL | GDPR | €100,000 | ↗ |
| 16 May 2023 | UK Direct Business Solutions LimitedUK Direct Business Solutions Limited was fined by the ICO for making 410,369 unsolicited marketing calls to businesses registered with the CTPS or TPS. The calls were made between 1 March 2020 and 31 October 2021 and breached rules on telephone marketing. | GB | ICO | GDPR | €115,000 | ↗ |
| 17 Aug 2021 | BANCO BILBAO VIZCAYA ARGENTARIA, S.A.Banco Bilbao Vizcaya Argentaria, S.A. was fined by the AEPD for sending unsolicited SMS messages to the complainant's mobile phone. The company also failed to remove the number from its database after the request, which constituted a data protection breach. | ES | AEPD | GDPR | €100,000 | ↗ |
| 17 Apr 2024 | BANCO BILBAO VIZCAYA ARGENTARIA, S.A.BBVA was fined EUR 100,000 by the AEPD for processing a payment to a new account without the account holder’s explicit consent. The authority found this conduct to be a breach of GDPR Article 6. | ES | AEPD | GDPR | €100,000 | ↗ |
| 04 Mar 2020 | Fotó készítése és közzététele Facebookon hozzájárulás nélkülThe authority found unlawful processing and publication of personal data without a valid legal basis. A fine was imposed and the image had to be deleted from Facebook. | HU | NAIH | GDPR | €299 | ↗ |
| 12 Jun 2015 | ALPHA BANKThe HDPA imposed a fine of EUR 100,000 on ALPHA BANK for the unlawful provision of data from the TIRESIAS databases. The case concerned a breach of rules on the processing and disclosure of personal data. | GR | HDPA | GDPR | €100,000 | ↗ |
| 11 Apr 2024 | Facile.Energy S.r.l.Facile.Energy S.r.l. was fined EUR 100,000 by the Garante for making unsolicited promotional calls without prior consent and activating energy supplies without a request from the customer. The authority found that these practices breached GDPR rules on data protection and security measures. | IT | Garante | GDPR | €100,000 | ↗ |
| 14 May 2021 | SIA "SS"DVI imposed a fine of EUR 100,000 on SIA "SS". According to the record, the sanction was later annulled. | LV | DVI | GDPR | €100,000 | ↗ |
| 05 Oct 2017 | Regione autonoma Valle d'AostaRegione autonoma Valle d'Aosta was fined by the Garante 100,000 EUR for publishing a regional council resolution on its institutional website that contained an employee’s personal data. The document included professional evaluations and transfer details. | IT | Garante | GDPR | €100,000 | ↗ |
| 25 Jun 2025 | Vodafone-PanafonVodafone-Panafon was fined by the HDPA for failing to notify a data breach in a timely manner. The authority cited a violation of Article 12 of Law L.3471/2006. | GR | HDPA | ePrivacy | €100,000 | ↗ |
| 16 Dec 2021 | Ubi Banca S.p.a., ora Intesa Sanpaolo S.p.a.Ubi Banca S.p.a., now Intesa Sanpaolo S.p.a., was fined EUR 100,000 by the Italian Garante. The breach involved sending a letter with the phrase “credito anomalo Chieti” visible on the envelope, which could disclose the recipient’s financial information to third parties. | IT | Garante | GDPR | €100,000 | ↗ |
| 15 Dec 2022 | Altroconsumo Edizioni S.r.lAltroconsumo Edizioni S.r.l was fined EUR 100,000 by the Garante for making unsolicited promotional calls without a proper legal basis. The authority also found that the company failed to provide adequate information and to obtain free and specific consent from data subjects. | IT | Garante | GDPR | €100,000 | ↗ |
| 28 Jul 2022 | Intesa Sanpaolo S.p.a.Intesa Sanpaolo S.p.a. was fined EUR 100,000 by Garante after an employee accessed a customer's financial data without authorization. The data was then used in judicial proceedings. The authority found that the bank had not implemented adequate data protection measures. | IT | Garante | GDPR | €100,000 | ↗ |
| 22 Feb 2024 | Italiaonline S.p.A.Italiaonline S.p.A. was fined by the Garante 100,000 EUR for conducting direct email marketing campaigns without proper consent. The authority also found inadequate information about data processing activities shared with Google LLC. | IT | Garante | GDPR | €100,000 | ↗ |
| 25 Sept 2025 | RCS MediaGroup S.p.a.RCS MediaGroup S.p.a. was fined by the Italian data protection authority, Garante, in the amount of EUR 100,000. The case concerned the publication of images of a person in a private setting without consent, which infringed privacy rights. | IT | Garante | GDPR | €100,000 | ↗ |
| 12 Jun 2023 | Piraeus Bank S.A.Piraeus Bank S.A. was fined by the HDPA in the amount of 100,000 EUR for failing to implement appropriate technical and organizational measures. The authority found that the bank did not ensure data protection by design and by default. | GR | HDPA | GDPR | €100,000 | ↗ |
| 02 Jul 2020 | Głównego Geodetę Kraju z siedzibą w Warszawie przy ul.UODO imposed a fine of PLN 100,000 on the Chief Surveyor of Poland based in Warsaw. The sanction concerned failure to provide access during an inspection to rooms, equipment and tools used for personal data processing, as well as access to personal data and information. | PL | UODO | GDPR | €22,351 | ↗ |
| 07 Jul 2021 | Nordbornholms Byggeforretning ApSNordbornholms Byggeforretning ApS was fined 100,000 DKK by Datatilsynet. The company unlawfully disclosed information about a former employee's criminal activities to customers without a legal basis. | DK | Datatilsynet | GDPR | €13,448 | ↗ |