BULLETIN №081Last updated · 28 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -20.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 27 Feb 2025 | Velvet Medical SRLThe National Supervisory Authority for Personal Data Processing completed an investigation in February into Velvet Medical SRL. It found a GDPR violation and imposed a fine of 1,000 EUR. | RO | ANSPDCP | GDPR | €1,000 | ↗ |
| 27 Feb 2025 | Istarski vodovod d.o.o.Istarski vodovod d.o.o. was fined by AZOP EUR 25,000 for failing to implement adequate technical security measures. The deficiencies included the absence of two-factor authentication and monitoring systems, which led to unauthorized access and a data breach. | HR | AZOP | GDPR | €25,000 | ↗ |
| 27 Feb 2025 | Energia Pulita S.r.l.Energia Pulita S.r.l. was fined EUR 300,000 by the Garante for making unsolicited marketing calls without a valid legal basis. The authority found a breach of GDPR Article 5. | IT | Garante | GDPR | €300,000 | ↗ |
| 27 Feb 2025 | Ministero dell’Interno-Dipartimento per gli affari interni e territorialiThe Ministry of the Interior was fined EUR 3,000 for processing personal data through the CIE-Agenda Online service. The authority found that the processing did not comply with the principles of lawfulness, fairness, transparency, and purpose limitation. | IT | Garante | GDPR | €3,000 | ↗ |
| 26 Feb 2025 | SportadminIMY fined Sportadmin SEK 6 million after an IT attack exposed personal data of more than 2.1 million individuals, mostly children. The authority found that the company had not maintained an appropriate security level for the personal data it processed. | SE | Integritetsskyddsmyndigheten | GDPR | €538,000 | ↗ |
| 25 Feb 2025 | SERVICIOS ESPECIALES, S.A.SERVICIOS ESPECIALES, S.A. was fined by the AEPD 200,000 EUR for disclosing the identity of a complainant in a workplace harassment case. The authority found a breach of personal data confidentiality principles. | ES | AEPD | GDPR | €200,000 | ↗ |
| 24 Feb 2025 | SCHOOL FITNESS HOLIDAY & FRANCHISING, S.L.SCHOOL FITNESS HOLIDAY & FRANCHISING, S.L. was fined by the AEPD 15,000 EUR for recording gym sessions without informing participants or obtaining their consent. The authority found this to be a breach of GDPR rules on consent and personal data processing. | ES | AEPD | GDPR | €15,000 | ↗ |
| 24 Feb 2025 | UNICAJA BANCO, S.A.U.UNICAJA BANCO, S.A.U. was fined by the AEPD EUR 3,500,000 for inadequate security measures in its video surveillance system. The authority found a breach of data protection requirements. | ES | AEPD | GDPR | €3,500,000 | ↗ |
| 24 Feb 2025 | 4USPORT INSTALACIONES DEPORTIVAS, S.L.4USPORT INSTALACIONES DEPORTIVAS, S.L. was fined by the AEPD in the amount of 600 EUR for failing to provide access. The case concerned Article 58(1) of the GDPR and indicates a failure to cooperate with the supervisory authority. | ES | AEPD | GDPR | €600 | ↗ |
| 21 Feb 2025 | Österreichische Post AGThe Austrian Federal Administrative Court upheld a major GDPR fine against Österreichische Post AG for unlawful processing of political affinity data and other personal data used in direct marketing. The court reduced the penalty from EUR 18 million to EUR 16 million, while confirming the underlying data protection breaches. | AT | Österreichische Datenschutzbehörde | GDPR | €16,000,000 | ↗ |
| 20 Feb 2025 | Medstar S.R.L.Medstar S.R.L. was fined by ANSPDCP for failing to notify the data breach to the supervisory authority. The company also did not inform the affected individuals about the unauthorized disclosure of their personal data. | RO | ANSPDCP | GDPR | €2,000 | ↗ |
| 20 Feb 2025 | NAROBESA INV, S.L.NAROBESA INV, S.L. was fined EUR 2,000 by the AEPD for failing to provide the required documentation to the data protection authority. The case concerns a breach of the cooperation duty under Article 58(1) GDPR. | ES | AEPD | GDPR | €2,000 | ↗ |
| 20 Feb 2025 | SIA “DAILENS”SIA “DAILENS” was fined EUR 500 by the DVI. The decision is final and has entered into force. | LV | DVI | GDPR | €500 | ↗ |
| 20 Feb 2025 | BLUE TEAM FLIGHT SCHOOL, S.L.BLUE TEAM FLIGHT SCHOOL, S.L. was fined 6,000 EUR by the AEPD. The authority found that the company failed to provide access to personal data and information requested by the data protection authority, in breach of Article 58.1 of the GDPR. | ES | AEPD | GDPR | €6,000 | ↗ |
| 19 Feb 2025 | EDA TV CONSULTING, S.L.EDA TV CONSULTING, S.L. was fined by the AEPD EUR 2,000 for failing to comply with cookie policy requirements on its website. The breach concerned obligations under the LSSI. | ES | AEPD | ePrivacy | €2,000 | ↗ |
| 17 Feb 2025 | CLUB DE GOLF VILLA DE CUÉLLARCLUB DE GOLF VILLA DE CUÉLLAR was fined by the AEPD EUR 400 for failing to inform an employee about the installation and operation of surveillance cameras. The authority found a breach of Article 13 GDPR. | ES | AEPD | GDPR | €400 | ↗ |
| 17 Feb 2025 | ARCONADA 1932, S.L.ARCONADA 1932, S.L. did not properly handle a data subject request for access to and deletion of personal data. This breached Articles 15 and 17 of the GDPR, and the company was fined for failing to comply with the AEPD's resolution. | ES | AEPD | GDPR | €1,500 | ↗ |
| 17 Feb 2025 | Heilsugæsla höfuðborgarsvæðisinsHeilsugæsla höfuðborgarsvæðisins was fined ISK 5,000,000 by Persónuvernd. The authority found that the organization unlawfully merged its medical records system with those of other entities, breaching GDPR requirements on lawful data processing. | IS | Persónuvernd | GDPR | €34,050 | ↗ |
| 17 Feb 2025 | Meedea Construct Prest SRLThe company was fined for violating the principles and lawfulness of personal data processing, specifically Articles 6 and 9 of the GDPR. A corrective measure was also imposed to ensure GDPR compliance in data collection and processing and to reduce the risk of unauthorized access and disclosure. | RO | ANSPDCP | GDPR | €2,000 | ↗ |
| 13 Feb 2025 | Comune di TuscaniaThe Garante imposed a 4,000 EUR fine on Comune di Tuscania for violating data protection rules. The authority took into account the limited financial resources of the small municipality when setting the sanction. | IT | Garante | GDPR | €4,000 | ↗ |