BULLETIN №082Last updated · 29 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 01 Jan 2025 | TELEROSA SPAIN, S.L.TELEROSA SPAIN, S.L. was fined 450 EUR by the AEPD for sending unsolicited commercial SMS messages without prior express consent. The authority also noted that there was no pre-existing contractual relationship with the recipients. | ES | AEPD | ePrivacy | €450 | ↗ |
| 01 Jan 2025 | FEMXA FORMACIÓN, S.L.FEMXA FORMACIÓN, S.L. was fined by the AEPD 25,000 EUR for requiring a full copy of a student's ID during course enrollment. The authority found the data request unnecessary and inconsistent with data protection principles. | ES | AEPD | GDPR | €25,000 | ↗ |
| 01 Jan 2025 | MALAGASUITE SHOWROOM, S.L.MALAGASUITE SHOWROOM, S.L. was fined by the AEPD 2,000 EUR for failing to inform guests about the processing of their personal data. The authority found a breach of Article 13 GDPR. | ES | AEPD | GDPR | €2,000 | ↗ |
| 01 Jan 2025 | AMADEUSAMADEUS was fined EUR 9,000,000 by the AEPD for breaching GDPR Articles 14 and 6. The authority found that the company failed to inform data subjects about the processing of their personal data. | ES | AEPD | GDPR | €9,000,000 | ↗ |
| 01 Jan 2025 | Sambla GroupThe Finnish Data Protection Authority fined Sambla Group EUR 950,000 after unauthorized parties accessed credit application data by manipulating web addresses. The authority found that the company had not implemented adequate safeguards to prevent the breach. | FI | Tietosuojavaltuutetun toimisto | GDPR | €950,000 | ↗ |
| 01 Jan 2025 | Diskrimineringsombudsmannen (DO)Integritetsskyddsmyndigheten (IMY) imposed a 100,000 SEK administrative sanction on Diskrimineringsombudsmannen (DO). The case concerned insufficient security measures for personal data collected via a web form, which resulted in unintended disclosure to a processor. | SE | Integritetsskyddsmyndigheten (IMY) | GDPR | €8,727 | ↗ |
| 01 Jan 2025 | RaiItaly’s data protection authority fined Rai EUR 150,000 over a Report broadcast on 8 December 2024 that disclosed a private conversation. The case concerns unlawful processing of personal data in a television report. | IT | Garante per la protezione dei dati personali | GDPR | €150,000 | ↗ |
| 01 Jan 2025 | ASESORAMOS TU FORMACIÓN CON CALIDAD S.L.ASESORAMOS TU FORMACIÓN CON CALIDAD S.L. was fined by the AEPD 10,000 EUR for processing personal data without a legal basis. The case also involved the improper inclusion of individuals in credit information systems. | ES | AEPD | GDPR | €10,000 | ↗ |
| 01 Jan 2025 | PROYECTOS VISUALES ZARAGOZA SLPROYECTOS VISUALES ZARAGOZA SL was fined by the AEPD 50,000 EUR for a personal data breach. The authority found that the company failed to ensure data integrity and confidentiality under Article 5(1)(f) GDPR. | ES | AEPD | GDPR | €50,000 | ↗ |
| 01 Jan 2025 | Posti Jakelu OyPosti Jakelu Oy was fined EUR 2,400,000 by the Data Protection Ombudsman for deficiencies in data protection related to the OmaPosti service. The case concerned inadequate safeguards and failures to meet personal data protection requirements. | FI | Tietosuojavaltuutettu | GDPR | €2,400,000 | ↗ |
| 31 Dec 2024 | SOCIETE DE TRANSPORT AMBULANCIER (procédure simplifiée)The CNIL imposed an administrative fine of EUR 10,000 on SOCIETE DE TRANSPORT AMBULANCIER. The case was handled under a simplified procedure. | FR | CNIL | GDPR | €10,000 | ↗ |
| 31 Dec 2024 | PARTICULIERS (procédure simplifiée)An administrative fine of EUR 5,000 was imposed by the CNIL. The case was handled under a simplified procedure. | FR | CNIL | GDPR | €5,000 | ↗ |
| 31 Dec 2024 | SOCIETE GERANT UN ROBOT CONVERSATIONNEL UTILISANT L'INTELLIGENCE ARTIFICELLE (procédure simplifiée)The CNIL imposed an administrative fine of 5,000 EUR on the company operating an AI-based conversational robot. The case was handled under a simplified procedure. | FR | CNIL | GDPR | €5,000 | ↗ |
| 26 Dec 2024 | SOCIETE EXPLOITANT DES SUPERMARCHES (procédure simplifiée)The CNIL imposed an administrative fine of EUR 18,000 on SOCIETE EXPLOITANT DES SUPERMARCHES. The case was handled under a simplified procedure. | FR | CNIL | GDPR | €18,000 | ↗ |
| 23 Dec 2024 | HYUNDAI MOTOR ESPAÑA S.L.U.HYUNDAI MOTOR ESPAÑA S.L.U. was fined EUR 2,000,000 by the AEPD for a data security incident. Unauthorized access to customer data occurred, breaching data protection principles. | ES | AEPD | GDPR | €2,000,000 | ↗ |
| 23 Dec 2024 | Fan Courier Express S.R.L.Fan Courier Express S.R.L. was fined €2,000 by ANSPDCP for breaching Article 3 of the GDPR. The case concerned non-compliance with the rules on the regulation’s scope of application. | RO | ANSPDCP | GDPR | €2,000 | ↗ |
| 20 Dec 2024 | FUNDACIÓN SOCIEDAD CIENTÍFICA DE ONCOLOGÍA MÉDICAFUNDACIÓN SOCIEDAD CIENTÍFICA DE ONCOLOGÍA MÉDICA was fined 70,000 EUR by the AEPD for a data breach affecting confidentiality. The authority found a violation of Article 5(1)(f) GDPR, which requires personal data to be processed securely and confidentially. | ES | AEPD | GDPR | €70,000 | ↗ |
| 20 Dec 2024 | OpenAIThe Italian data protection authority fined OpenAI EUR 15 million for GDPR noncompliance related to ChatGPT. The 20 December 2024 decision cites issues with the legal basis for training data processing, transparency obligations, age verification, breach notification, and the security and accuracy of outputs. | IT | Garante per la protezione dei dati personali | GDPR | €15,000,000 | ↗ |
| 20 Dec 2024 | English Home SRLEnglish Home SRL was fined EUR 1,000 by ANSPDCP for violating Article 21 of the GDPR. The case concerned failure to respect the data subject’s right to object to processing. | RO | ANSPDCP | GDPR | €1,000 | ↗ |
| 20 Dec 2024 | English Home SRLEnglish Home SRL was fined €4,000 by ANSPDCP for violating Article 21 of the GDPR. The case concerned failure to respect the data subject’s right to object to processing. | RO | ANSPDCP | GDPR | €4,000 | ↗ |