BULLETIN №082Last updated · 29 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 23 Apr 2025 | Diskrimineringsombudsmannen (DO)The Swedish Authority for Privacy Protection (IMY) fined the Equality Ombudsman (DO) 100,000 SEK. IMY found that DO failed to implement appropriate technical and organizational measures to ensure an adequate level of security for personal data collected via a web form. | SE | IMY | GDPR | €9,141 | ↗ |
| 21 May 2019 | Ferencvárosi Szociális és Gyermekjóléti Intézmények IgazgatóságaThe Ferencvárosi Social and Child Welfare Institutions Directorate was fined for failing to report a personal data breach within the required deadline. The incident involved documents sent to the wrong address, triggering the notification duty under GDPR Article 33. | HU | NAIH | GDPR | €306 | ↗ |
| 02 Dec 2021 | Omnia 24 S.r.l.Omnia 24 S.r.l. was fined EUR 100,000 by the Garante for sending unsolicited promotional SMS messages without proper consent. The authority found that the company’s conduct breached data protection rules. | IT | Garante | GDPR | €100,000 | ↗ |
| 29 Apr 2026 | Lepida S.c.p.A.Lepida S.c.p.A. was fined by the Italian supervisory authority Garante €100,000 for unauthorized access and data handling violations linked to SPID digital identity management. The authority found breaches of GDPR Articles 25 and 32, covering data protection by design and security of processing. | IT | Garante | GDPR | €100,000 | ↗ |
| 20 Dec 2022 | Virtue Integrated Elder Care LtdThe Irish DPC imposed a fine of EUR 100,000 on Virtue Integrated Elder Care Ltd in inquiry IN-21-2-5. The penalty has been collected. | IE | DPC | GDPR | €100,000 | ↗ |
| 23 Jan 2025 | XFERA MÓVILES, S.A.XFERA MÓVILES, S.A. was fined 100,000 EUR by the AEPD for inaccuracies in data retention relating to SIM card purchasers. The authority found a breach of the GDPR data accuracy obligation. | ES | AEPD | GDPR | €100,000 | ↗ |
| 10 Dec 2025 | University of LimerickThe Irish DPC fined University of Limerick 98,000 EUR in inquiry IN-19-7-1. The record notes the status as not confirmed. | IE | DPC | GDPR | €98,000 | ↗ |
| 26 Mar 2026 | Eni S.p.A.Eni S.p.A. was fined 96,000 EUR by the Garante for publishing personal data on its website, including dates of birth and addresses, without proper masking. The authority found this breached GDPR principles of lawfulness, fairness, and transparency. | IT | Garante | GDPR | €96,000 | ↗ |
| 09 Nov 2017 | GSG Enterprise società cooperativa edileGSG Enterprise was fined EUR 96,000 by the Garante for using the personal data of car owners to demand payment for services that were neither performed nor requested. The case concerns unlawful processing of personal data for debt-collection style demands. | IT | Garante | GDPR | €96,000 | ↗ |
| 24 Jan 2024 | CAJA RURAL DE GIJÓN, S.C.A.C.CAJA RURAL DE GIJÓN was fined by the AEPD 95,000 EUR for breaching data protection principles, specifically confidentiality and integrity. The incident resulted in unauthorized access to personal data and indicates a significant compliance failure. | ES | AEPD | GDPR | €95,000 | ↗ |
| 23 Jun 2025 | Dane anonimowe (U.)UODO imposed a PLN 94,286 administrative fine on an anonymous entity for improperly vetting a processor before entering into a data processing agreement. The authority also found inadequate technical and organizational safeguards, insufficient testing of their effectiveness, and failure to properly involve the data protection officer in privacy matters. | PL | UODO | GDPR | €22,053 | ↗ |
| 15 Oct 2015 | Ordinanza ingiunzione - 15 ottobre 2015 [4703503]A fine was imposed for activating 85 SIM cards in the names of 31 people without their knowledge. The conduct breached data protection rules. | IT | Garante | GDPR | €93,000 | ↗ |
| 21 Mar 2018 | Ordinanza ingiunzione - 21 marzo 2018 [9004702]The Garante imposed a EUR 92,000 fine on a medical professional for processing the personal data of 23 patients without the required consent. The authority found a breach of privacy and data protection rules. | IT | Garante | GDPR | €92,000 | ↗ |
| 14 Sept 2023 | GFB One s.r.l.GFB One s.r.l. was fined EUR 90,000 by the Italian Garante. The case concerned its failure to respond to requests for information relating to the unauthorized activation of SIM cards and the misuse of personal identification documents. | IT | Garante | GDPR | €90,000 | ↗ |
| 01 Jan 2023 | MASLUZ ENERGY POWER, S.L.MASLUZ ENERGY POWER, S.L. was fined EUR 90,000 by the AEPD for changing a customer's energy provider without authorization. The authority also found a failure to provide the required information, constituting breaches of GDPR Articles 13 and 6(1). | ES | AEPD | GDPR | €90,000 | ↗ |
| 22 Feb 2024 | Coop Italia Società CooperativaCoop Italia Società Cooperativa was fined by the Garante 90,000 EUR for unlawfully processing personal data for marketing purposes without proper consent. The authority found a breach of GDPR principles, including Article 5. | IT | Garante | GDPR | €90,000 | ↗ |
| 27 Mar 2025 | AFK Letters Co LtdBetween January and September 2023, AFK Letters Co Ltd made 95,277 spam calls, leading to multiple complaints to the ICO and TPS. The company did not provide evidence that the called numbers had consented to receiving calls. The ICO imposed a £90,000 fine. | GB | ICO | GDPR | €108,000 | ↗ |
| 29 Aug 2018 | Anonymizováno (ÚOOÚ UOOU-08277/18-40)The entity was fined for sending unsolicited commercial communications by electronic means without recipients' consent. This breached Czech rules on information society services. | CZ | UOOU | ePrivacy | €3,496 | ↗ |
| 23 Mar 2021 | Irish Credit Bureau DACThe Irish Data Protection Commission (DPC) fined Irish Credit Bureau DAC EUR 90,000 in inquiry IN-19-7-2. The fine has been collected. | IE | DPC | GDPR | €90,000 | ↗ |
| 09 Nov 2023 | DPG Professional Services LtdBetween 3 August 2021 and 3 August 2022, DPG made 74,119 unsolicited calls for direct marketing purposes, breaching Reg 21 of PECR. The activity resulted in 13 complaints and came to the Commissioner’s attention through an operation focused on life insurance and later life planning marketing. | GB | ICO | ePrivacy | €103,000 | ↗ |