BULLETIN №082Last updated · 29 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 04 Feb 2025 | LÍNEAS FINANCIERAS INTERNACIONALES, S.L.The entity was fined EUR 500 by the AEPD for sending unsolicited commercial communications by email without prior consent. This conduct breached Article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €500 | ↗ |
| 03 Feb 2025 | IBERMUTUA, MUTUA COLABORADORA CON LA SEGURIDAD SOCIAL NUM.274IBERMUTUA was fined EUR 1,000,000 by the AEPD for a data breach. Due to a computer error, personal data, including health information, was mistakenly sent to various companies. | ES | AEPD | GDPR | €1,000,000 | ↗ |
| 03 Feb 2025 | CENTRAL SINDICAL INDEPENDIENTE Y DE FUNCIONARIOS CSI-CSIFThe labor union CSI-CSIF was fined EUR 4,000 by the AEPD for failing to adequately protect personal data during a voting process. The authority found breaches of GDPR Articles 5(1)(f) and 32 relating to security and confidentiality. | ES | AEPD | GDPR | €4,000 | ↗ |
| 03 Feb 2025 | Unicredit Bank SAANSPDCP imposed a EUR 15,000 fine on Unicredit Bank SA for security breaches linked to an application used to create user names without prior testing. The sanction also covered a client communication solution implemented without adequate pre-testing, which led to unauthorized disclosure of personal data. | RO | ANSPDCP | GDPR | €15,000 | ↗ |
| 01 Feb 2025 | Automobilus International S.R.L.The Romanian data protection authority fined Automobilus International S.R.L. 24,885 RON after concluding its investigation in February 2025. It found breaches of GDPR Articles 32(1) and 32(2) due to inadequate technical and organizational security measures following a personal data breach. | RO | Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal | GDPR | €5,000 | ↗ |
| 01 Feb 2025 | Orange RomaniaThe Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP) fined Orange Romania EUR 40,000 for GDPR violations. The authority found improper handling of personal data deletion requests and excessive collection of identity document copies. | RO | Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal | GDPR | €40,000 | ↗ |
| 31 Jan 2025 | SINDICAT CATAC-CTSCSINDICAT CATAC-CTSC was fined EUR 600 by the AEPD for failing to provide the required information. The authority found a breach of Article 58(1) of the GDPR. | ES | AEPD | GDPR | €600 | ↗ |
| 31 Jan 2025 | S.P.E.E.H. HIDROELECTRICA S.AThe company was fined for a data security breach during the launch of its application. The incident resulted from a technical error and insufficient testing, which did not ensure adequate data protection. | RO | ANSPDCP | GDPR | €15,000 | ↗ |
| 30 Jan 2025 | Guru Nanak s.r.l.s.Guru Nanak s.r.l.s. was fined by the Garante EUR 1,000 for the non-compliant installation of a video surveillance system. The cameras captured areas beyond the company’s premises, creating a privacy and data protection breach. | IT | Garante | GDPR | €1,000 | ↗ |
| 30 Jan 2025 | Azienda Unità Sanitaria locale di ModenaAzienda Unità Sanitaria locale di Modena was fined by the Garante €10,000 for processing personal data concerning health and other sensitive information without a proper legal basis. The case involved unlawful processing of special-category data, which raises heightened compliance and privacy risks. | IT | Garante | GDPR | €10,000 | ↗ |
| 30 Jan 2025 | SOCIETE DE COURTAGE EN ENERGIE (procédure simplifiée)The CNIL used a simplified procedure against SOCIETE DE COURTAGE EN ENERGIE and ordered 4,000 EUR in connection with the liquidation of an astreinte. The case concerns failure to comply with a prior obligation subject to a coercive penalty. | FR | CNIL | GDPR | €4,000 | ↗ |
| 30 Jan 2025 | Azienda Ospedaliero - Universitaria Città della Salute e della Scienza di TorinoThe Garante fined Azienda Ospedaliero - Universitaria Città della Salute e della Scienza di Torino 6,000 EUR for unlawful processing of personal data, including health data. The authority found that the processing lacked an appropriate legal basis. The case concerned sensitive data handling in the healthcare sector. | IT | Garante | GDPR | €6,000 | ↗ |
| 29 Jan 2025 | SINDICATO DE LA ADMON. PÚBLICA DE LA CGT EN JEREZ Y COSTA NOROESTE DE CÁDIZThe union was fined by the AEPD for failing to comply with data protection principles and for not informing individuals about the processing of their personal data. The case indicates shortcomings in transparency and GDPR compliance obligations. | ES | AEPD | GDPR | €2,000 | ↗ |
| 29 Jan 2025 | EDA TV CONSULTING, S.L.EDA TV CONSULTING, S.L. was fined by the AEPD 5,000 EUR for requiring a copy of the DNI when exercising data protection rights. The authority found this to breach the GDPR data minimization principle. | ES | AEPD | GDPR | €5,000 | ↗ |
| 27 Jan 2025 | Orange România SAOrange România SA was fined EUR 20,000 by ANSPDCP for GDPR violations. The case concerns non-compliance with personal data protection requirements. | RO | ANSPDCP | GDPR | €20,000 | ↗ |
| 27 Jan 2025 | Orange România SAOrange România SA was fined EUR 20,000 by ANSPDCP for GDPR violations. The case concerns non-compliance with personal data protection requirements, creating regulatory risk for organizations processing data in Romania. | RO | ANSPDCP | GDPR | €20,000 | ↗ |
| 23 Jan 2025 | Softtehnica S.R.LIn December 2024, ANSPDCP completed an investigation at Softtehnica S.R.L. The authority found a GDPR violation and imposed a fine of EUR 5,000. | RO | ANSPDCP | GDPR | €5,000 | ↗ |
| 23 Jan 2025 | SOCIETE DE TRANSPORT ROUTIER DE MARCHANDISES (procédure simplifiée)CNIL imposed an administrative fine of 8,000 EUR on SOCIETE DE TRANSPORT ROUTIER DE MARCHANDISES. The case was handled under a simplified procedure. | FR | CNIL | GDPR | €8,000 | ↗ |
| 23 Jan 2025 | XFERA MÓVILES, S.A.XFERA MÓVILES, S.A. was fined 100,000 EUR by the AEPD for inaccuracies in data retention relating to SIM card purchasers. The authority found a breach of the GDPR data accuracy obligation. | ES | AEPD | GDPR | €100,000 | ↗ |
| 20 Jan 2025 | Vodafone Romania S.A.Vodafone Romania S.A. was fined EUR 15,000 by ANSPDCP for violations of GDPR provisions. The case concerns non-compliance with personal data protection requirements. | RO | ANSPDCP | GDPR | €15,000 | ↗ |