BULLETIN №082Last updated · 29 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 07 May 2026 | South Staffordshire Plc and South Staffordshire Water PlcThe Information Commissioner’s Office (ICO) imposed a fine of 963,900 GBP on South Staffordshire Plc and South Staffordshire Water Plc for breaches of Article 5(1)(f) and Article 32(1) of the UK GDPR. The case followed a cyber incident in which personal data relating to approximately 633,887 UK data subjects was exfiltrated. | GB | ICO | GDPR | €1,115,000 | ↗ |
| 11 May 2026 | South Staffordshire PlcThe ICO issued a monetary penalty against South Staffordshire Plc and South Staffordshire Water Plc in the amount of GBP 963,000. The case concerned a security breach affecting more than 633,000 individuals and an admitted infringement of Article 5(1)(f) UK GDPR. | GB | Information Commissioner's Office | GDPR | €1,113,000 | ↗ |
| 11 Apr 2013 | Sound station s.a.s.Sound station s.a.s. was fined 30,000 EUR by the Garante for registering numerous phone SIM cards to unaware third parties. The conduct breached data protection requirements. | IT | Garante | GDPR | €30,000 | ↗ |
| 01 Jan 2015 | SOTO GLOBAL SERVICE, S.L.SOTO GLOBAL SERVICE, S.L. was fined by the AEPD €3,200 for sending nine unsolicited commercial emails without prior consent. The authority found a breach of Article 21 of the LSSI. | ES | AEPD | ePrivacy | €3,200 | ↗ |
| 22 Dec 2021 | SOS Leukémiás Gyermekekért AlapítványSOS Leukémiás Gyermekekért Alapítvány was fined by NAIH 500,000 HUF for processing personal data without a valid legal basis. The authority also found failures to provide transparent information and to facilitate data subject access rights. | HU | NAIH | GDPR | €1,355 | ↗ |
| 14 Apr 2023 | Sorgenia S.p.a.Sorgenia S.p.a. was fined EUR 676,956 by the Italian data protection authority, Garante. The case concerned failure to respect data deletion and objection rights in connection with unlawful telemarketing practices in the energy sector. | IT | Garante | GDPR | €676,000 | ↗ |
| 06 Jul 2016 | Sorec s.r.l.Sorec s.r.l. was fined EUR 4,000 by the Garante for inadequate password security in its data processing systems. The case concerned non-compliance with data protection requirements. | IT | Garante | GDPR | €4,000 | ↗ |
| 01 Dec 2011 | Soprintendenza per i beni architettonici, paesaggistici, storici, artistici e etnoantropologici per Napoli e provinciaThe Garante fined Soprintendenza 32,000 EUR for violations related to the processing of biometric data. The authority found that the processing did not comply with the required legal requirements. | IT | Garante | GDPR | €32,000 | ↗ |
| 23 Apr 2015 | Soprintendenza per i Beni Architettonici e Paesaggistici di Venezia e LagunaThe Soprintendenza per i Beni Architettonici e Paesaggistici di Venezia e Laguna was fined 4,000 EUR by the Garante. The authority found that personal data had been unlawfully communicated to private entities without an appropriate legal basis, in breach of Article 19 of the Italian Data Protection Code. | IT | Garante | GDPR | €4,000 | ↗ |
| 01 Apr 2022 | SOPHIE ET VOILA, S.L.SOPHIE ET VOILA, S.L. was fined EUR 10,000 by the AEPD for publishing a photo on Instagram without the data subject’s consent. The authority found a breach of Article 6 GDPR on lawful processing. | ES | AEPD | GDPR | €10,000 | ↗ |
| 24 Jun 2021 | Soluzione Tasse S.p.A.Soluzione Tasse S.p.A. was fined by the Garante 30,000 EUR for sending unsolicited emails without proper consent. The case concerned GDPR principles on data processing and transparency. | IT | Garante | GDPR | €30,000 | ↗ |
| 11 Jul 2012 | SOLUCIONES CORPORATIVAS IP, S.L.U.SOLUCIONES CORPORATIVAS IP, S.L.U. was fined 600 EUR by the AEPD for sending an unsolicited email. The conduct breached Article 21 of the LSSI, which restricts commercial communications without prior consent. | ES | AEPD | ePrivacy | €600 | ↗ |
| 17 Mar 2021 | SOLRAM T Y R S.L.SOLRAM T Y R S.L. was fined by the AEPD in the amount of 3,000 EUR for failing to delete personal data from its databases. The authority found a breach of Article 17 GDPR after the company continued sending unsolicited commercial messages via WhatsApp. | ES | AEPD | GDPR | €3,000 | ↗ |
| 09 May 2018 | SO.LOG. SrlSO.LOG. Srl was fined EUR 8,000 by the Italian data protection authority, Garante. The sanction concerned the failure to properly notify processing activities related to vehicle geolocation, in breach of the Italian Privacy Code. | IT | Garante | GDPR | €8,000 | ↗ |
| 07 Feb 2020 | SOLO EMBRAGUE, S.L.SOLO EMBRAGUE, S.L. was fined by the AEPD 3,000 EUR for failing to provide information about its privacy policy and for not obtaining consent for cookies on its website. The case concerns breaches of transparency obligations and consent requirements under data protection rules. | ES | AEPD | ePrivacy | €3,000 | ↗ |
| 25 Feb 2016 | Sol Levante s.r.l.Sol Levante s.r.l. was fined EUR 12,000 by the Garante for retaining surveillance footage for 11 days. This exceeded the 7-day limit set out in the authority’s video surveillance guidelines. | IT | Garante | GDPR | €12,000 | ↗ |
| 29 Sept 2021 | Solera Italia s.r.l.Solera Italia s.r.l. was fined EUR 10,000 by the Garante for continuing to use an employee's email account after the employment ended. The authority found that the company did not provide proper information about this processing. | IT | Garante | GDPR | €10,000 | ↗ |
| 29 Mar 2023 | SOLAR PROGRESS, S.L.SOLAR PROGRESS, S.L. was fined 5,000 EUR by the AEPD for displaying an employee’s personal data on a company WhatsApp profile. The authority found a breach of data protection rules. | ES | AEPD | GDPR | €5,000 | ↗ |
| 21 Mar 2012 | Solar Energy Group s.p.aSolar Energy Group s.p.a was fined by the Garante 32,000 EUR for processing personal data collected through online forms without providing the required information or obtaining consent. The authority found breaches of Articles 13 and 23 of the Italian Privacy Code. | IT | Garante | GDPR | €32,000 | ↗ |
| 16 May 2019 | SOGIMA S.r.l.SOGIMA S.r.l. was fined by the Garante for allowing unauthorized access to personal data on its website. The breach involved names, email addresses, and bank details without the consent of the data subjects. | IT | Garante | GDPR | €4,000 | ↗ |