BULLETIN №082Last updated · 29 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 15 Jun 2026 | SSG SELECT SOLUTIONS S.R.LSSG SELECT SOLUTIONS S.R.L. was fined by ANSPDCP in the amount of EUR 2,000 for GDPR violations. The investigation was completed in April 2026. | RO | ANSPDCP | GDPR | €2,000 | ↗ |
| 15 Mar 2018 | S.P. Selezione Personale s.r.l.S.P. Selezione Personale s.r.l. was fined by the Garante in the amount of EUR 20,000 for violations related to the processing of personal data in head hunting and recruitment activities. The case concerned irregularities in the handling of candidate data. | IT | Garante | GDPR | €20,000 | ↗ |
| 22 Oct 2025 | SPRINTER MEGACENTROS DEL DEPORTE, S.L.SPRINTER MEGACENTROS DEL DEPORTE, S.L. experienced a data breach affecting approximately 6.2 million individuals, involving unauthorized access and encryption of critical systems. The incident was intentional and involved data from multiple EU member states. | ES | AEPD | GDPR | €2,600,000 | ↗ |
| 12 Jun 2023 | Spotify, rätten till tillgångIMY fined Spotify AB SEK 58 million for failing to provide clear and understandable information about the purposes of processing, categories of personal data, and other required details under Article 15 GDPR. The authority also found that technical log file descriptions were provided in English, which did not meet the requirement for clear communication in the data subject’s language. | SE | IMY | GDPR | €4,992,000 | ↗ |
| 03 Jun 2025 | Spotify ABOn 2025-06-03, Kammarrätten ruled that Spotify AB must pay an administrative fine of 58 million SEK. The case concerned insufficient transparency and inadequate information to data subjects under the GDPR, following an investigation by Integritetsskyddsmyndigheten. | SE | Integritetsskyddsmyndigheten (IMY) | GDPR | €5,309,000 | ↗ |
| 20 Feb 2024 | SPORT & SPA GEST, S.L.SPORT & SPA GEST, S.L. was fined by the AEPD 20,000 EUR for breaches of GDPR Articles 6(1), 13, 9, and 35. The case concerned improper data processing and insufficient information provided to users. | ES | AEPD | GDPR | €20,000 | ↗ |
| 07 Aug 2021 | SPORTIUM APUESTAS DIGITAL S.A.U.SPORTIUM APUESTAS DIGITAL S.A.U. was fined by the AEPD 5,000 EUR for sending marketing emails after a data deletion request and for having non-compliant cookie policies on its website. The case indicates failures in data protection and user consent controls. | ES | AEPD | ePrivacy | €5,000 | ↗ |
| 12 Feb 2026 | Sportitalia Società Sportiva Dilettantistica a.r.l.Sportitalia Società Sportiva Dilettantistica a.r.l. was fined EUR 30,000 by the Garante for violations related to the processing of personal data in promotional emails. The authority found that the company did not comply with GDPR requirements in connection with these marketing communications. | IT | Garante | GDPR | €30,000 | ↗ |
| 10 Nov 2022 | Sportitalia, società sportiva dilettantistica a responsabilità limitataSportitalia was fined €20,000 by the Italian supervisory authority, Garante. The case concerned the use of a biometric system to record employee attendance without a proper legal basis, in breach of GDPR rules on data processing and special categories of data. | IT | Garante | GDPR | €20,000 | ↗ |
| 26 Jan 2026 | SportAdmin i Skandinavien ABSportAdmin i Skandinavien AB was fined by IMY 6,000,000 SEK for failing to implement appropriate technical and organizational measures to ensure an adequate level of security for personal data. The deficiency resulted in a data breach. | SE | IMY | GDPR | €564,000 | ↗ |
| 26 Feb 2025 | SportadminIMY fined Sportadmin SEK 6 million after an IT attack exposed personal data of more than 2.1 million individuals, mostly children. The authority found that the company had not maintained an appropriate security level for the personal data it processed. | SE | Integritetsskyddsmyndigheten | GDPR | €538,000 | ↗ |
| 01 Mar 2023 | Spółdzielnie Mieszkaniową „UODO imposed an administrative fine of PLN 51,876 on the controller for failing to notify the supervisory authority of a personal data breach without undue delay. The authority also found that the affected data subject was not informed about the breach. | PL | UODO | GDPR | €11,098 | ↗ |
| 13 Nov 2024 | Spinacqua S.r.l.Spinacqua S.r.l. was fined by the Garante €10,000 for making unsolicited promotional calls to a number listed in the Public Opposition Register. The company did not obtain consent and failed to verify the number’s registration status before contacting it. | IT | Garante | GDPR | €10,000 | ↗ |
| 31 Jan 2025 | S.P.E.E.H. HIDROELECTRICA S.AThe company was fined for a data security breach during the launch of its application. The incident resulted from a technical error and insufficient testing, which did not ensure adequate data protection. | RO | ANSPDCP | GDPR | €15,000 | ↗ |
| 20 Oct 2025 | S.P.E.E.H. HIDROELECTRICA SAS.P.E.E.H. HIDROELECTRICA SA was fined by ANSPDCP EUR 5,000 for failing to notify a personal data breach. The incident involved customer data, including names, contract details, and billing information. | RO | ANSPDCP | GDPR | €5,000 | ↗ |
| 01 Aug 2012 | Spazio S s.r.l.Spazio S s.r.l. was fined by the Garante 10,400 EUR for sending unsolicited commercial emails. The authority found that the company failed to provide adequate information and did not obtain valid consent from recipients, breaching privacy rules. | IT | Garante | GDPR | €10,400 | ↗ |
| 22 Jun 2023 | Spaziani FabrizioThe Garante fined Spaziani Fabrizio EUR 1,000 for non-compliant video surveillance practices. The case involved cameras that were not properly signposted and may have captured public areas. | IT | Garante | GDPR | €1,000 | ↗ |
| 10 Sept 2025 | S-PankkiThe sanctions board of the Office of the Data Protection Ombudsman imposed a EUR 1.8 million fine on S-Pankki for failing to ensure information security in its online banking authentication service. The case concerned a software vulnerability in S-mobiili that allowed logins using another customer’s credentials and resulted in a personal data security breach. | FI | Office of the Data Protection Ombudsman | GDPR | €1,800,000 | ↗ |
| 01 Jan 2013 | SPAIN ON LINE, S.L.SPAIN ON LINE, S.L. was fined €30,001 by the AEPD for sending unsolicited promotional emails despite requests to stop. The conduct breached Article 21 of the LSSI on marketing communications without consent. | ES | AEPD | ePrivacy | €30,001 | ↗ |
| 01 Jan 2013 | SPACIO TERMAL, S.L.SPACIO TERMAL, S.L. was fined by the AEPD EUR 600 for sending unsolicited commercial emails without the required consent. The conduct breached Article 21 of the LSSI, which governs electronic marketing communications. | ES | AEPD | ePrivacy | €600 | ↗ |