BULLETIN №082Last updated · 29 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 28 Jan 2022 | IBERCAJA BANCO, S.A.IBERCAJA BANCO, S.A. was fined by the AEPD EUR 100,000 for unlawfully processing personal data linked to a family inheritance matter. The breach included opening a bank account for a minor without consent and disclosing personal data to third parties without authorization. | ES | AEPD | GDPR | €100,000 | ↗ |
| 06 May 2019 | ENDESA ENERGÍA XXI, S.L.U.ENDESA ENERGÍA XXI, S.L.U. was fined by the AEPD 100,000 EUR for a data protection breach. An agent mistakenly altered a contract, replacing the complainant’s data with that of a third party. | ES | AEPD | GDPR | €100,000 | ↗ |
| 17 Mar 2025 | Ministra CyfryzacjiUODO imposed an administrative fine of 100,000 PLN on the Minister of Digital Affairs. The breach concerned Article 6(1) and Article 5(1)(a) of Regulation 2016/679. | PL | UODO | GDPR | €23,887 | ↗ |
| 18 Jul 2023 | Tiscali Italia S.p.A.Tiscali Italia S.p.A. was fined EUR 100,000 by the Garante for sending promotional SMS messages to existing customers without their consent. The authority also found inadequate data retention policies and insufficient transparency in the privacy notices. | IT | Garante | GDPR | €100,000 | ↗ |
| 09 Feb 2012 | Banca popolare Sant'Angelo S.C.P.A.The bank was fined for deploying a biometric data collection system without proper notification and without complying with data protection principles. The authority found that the processing did not meet privacy compliance requirements. | IT | Garante | GDPR | €100,000 | ↗ |
| 29 Apr 2025 | Energia Verde S.p.A.Energia Verde S.p.A. was fined EUR 100,000 by the Garante for making unsolicited promotional calls without a legal basis. The authority also found that the company did not adequately respond to data subjects' requests, indicating failures in data protection compliance. | IT | Garante | GDPR | €100,000 | ↗ |
| 20 Dec 2023 | Ministra ZdrowiaThe President of the Personal Data Protection Office imposed an administrative fine of 100,000 PLN on Ministra Zdrowia. The authority found unlawful processing of personal data, including special-category data without a legal basis, and a failure to implement technical and organizational measures appropriate to the processing risk. The affected individual was also not provided with the information required under Article 33(3)(c) and (d) of the GDPR. | PL | UODO | GDPR | €23,035 | ↗ |
| 16 Jan 2024 | Skean Homes LtdSkean Homes Ltd was fined by the ICO after it was found to have instigated 614,342 unsolicited direct marketing calls between 2 March 2022 and 31 May 2022. The calls promoted energy grants for resin driveways and generated 31 complaints through the ICO and TPS reporting tools. The ICO found breaches of regulations 21 and 24 of PECR. | GB | ICO | ePrivacy | €116,000 | ↗ |
| 31 May 2024 | MEDIOS DE PREVENCIÓN EXTERNOS, S.L.MEDIOS DE PREVENCIÓN EXTERNOS, S.L. was fined by the AEPD for leaving medical documentation of police and civil guard agents in a public place. The authority found this to be a breach of data protection rules. | ES | AEPD | GDPR | €100,000 | ↗ |
| 24 Aug 2020 | Głównego Geodetę KrajuUODO imposed a fine of PLN 100,000 on the Chief Surveyor of Poland. The authority found a breach of the lawfulness principle in personal data processing due to the intentional disclosure, without a legal basis, of land and mortgage register numbers obtained from the land and building records. | PL | UODO | GDPR | €22,735 | ↗ |
| 01 Jan 2025 | STRATESYS TECHNOLOGY SOLUTIONS, S.L.STRATESYS TECHNOLOGY SOLUTIONS, S.L. was fined EUR 100,000 by the AEPD for breaching Article 5(1)(f) of the GDPR. The case concerned a failure to protect the integrity and confidentiality of personal data. | ES | AEPD | GDPR | €100,000 | ↗ |
| 18 Sept 2025 | SOCIETE EXPLOITANT UN GRAND MAGASINCNIL imposed an administrative fine of EUR 100,000 on SOCIETE EXPLOITANT UN GRAND MAGASIN. The case concerns a breach of rules supervised by CNIL. | FR | CNIL | GDPR | €100,000 | ↗ |
| 11 Dec 2018 | Anonymizováno (ÚOOÚ UOOU-00313/19-23)The supervisory authority found that the entity failed to implement adequate technical and organizational measures to secure personal data processing and did not properly inform data subjects. Personal data of loan applicants were retained longer than necessary, in breach of the GDPR. | CZ | UOOU | GDPR | €3,869 | ↗ |
| 11 Apr 2013 | PLD srlPLD srl was fined €100,000 by the Italian Garante. The company registered numerous phone cards to unaware third parties without providing the required data protection information. | IT | Garante | GDPR | €100,000 | ↗ |
| 13 May 2021 | Artemisia s.p.a.Artemisia s.p.a. was fined EUR 100,000 by the Garante for GDPR breaches in data processing. The violations concerned consent, information notices, and the handling of health data. | IT | Garante | GDPR | €100,000 | ↗ |
| 08 Aug 2023 | VODAFONE ESPAÑA, S.A.U.The AEPD fined VODAFONE ESPAÑA, S.A.U. 100,000 EUR for processing personal data without proper authorization. The case involved unsolicited marketing calls and messages sent to a complainant who had no commercial relationship with the company. | ES | AEPD | GDPR | €100,000 | ↗ |
| 10 Jul 2020 | VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD EUR 100,000 for repeatedly sending a former customer electronic notices about invoice availability. The authority found that the processing lacked a valid legal basis under GDPR Article 6.1. | ES | AEPD | GDPR | €100,000 | ↗ |
| 11 Apr 2024 | Olimpia S.r.l.Olimpia S.r.l. was fined for making unsolicited promotional calls without prior consent and for using numbers listed in the Public Opposition Register. The conduct breached GDPR requirements on data protection and security measures. | IT | Garante | GDPR | €100,000 | ↗ |
| 15 Sept 2022 | Regione LazioThe Garante imposed a 100,000 EUR fine on Regione Lazio for improper processing of health data in the SIPSOweb system. The authority found that sensitive health information was processed without a proper legal basis and with incorrect role designation. | IT | Garante | GDPR | €100,000 | ↗ |
| 14 Feb 2022 | COMERCIALIZADORA REGULADA, GAS & POWER, S.A.The company sent a customer's electricity supply contract containing personal data to an incorrect address. This breached data protection principles and led to a fine by the AEPD. | ES | AEPD | GDPR | €100,000 | ↗ |