BULLETIN №081Last updated · 26 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -20.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 02 Apr 2026 | SOCIÉTÉ EXPLOITANT DES BOUTIQUES TOILETTES (procédure simplifiée)CNIL imposed an administrative fine of EUR 7,500 on SOCIÉTÉ EXPLOITANT DES BOUTIQUES TOILETTES under a simplified procedure. The case concerns a breach of rules covered by the authority’s decision. | FR | CNIL | GDPR | €7,500 | ↗ |
| 30 Mar 2026 | Energy Prices Direct LimitedThe ICO fined Energy Prices Direct Limited, an energy switching services provider, for breaches of the PECR. The company obtained data from public sources and list providers, but failed to screen it against the TPS/CTPS registers before making marketing calls. | GB | ICO | ePrivacy | €184,000 | ↗ |
| 30 Mar 2026 | Κέντρο Εκπαίδευσης και Αποκατάστασης Τυφλών (ΚΕΑΤ)The Greek Data Protection Authority fined ΚΕΑΤ EUR 5,000 for an untimely and improper response to an employee’s request for access to CCTV footage. The case involved edited footage, missing material, and inadequate technical and organizational measures to support compliance. | GR | Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα | GDPR | €5,000 | ↗ |
| 26 Mar 2026 | Esselunga S.p.A.Esselunga S.p.A. was fined EUR 5,000 by the Italian supervisory authority, Garante. The case concerned a failure to respond to a data access request under Article 15 GDPR, including access to employee attendance records. | IT | Garante | GDPR | €5,000 | ↗ |
| 26 Mar 2026 | Euro Bangla MinimarketThe Garante fined Euro Bangla Minimarket EUR 1,000 for improper use of a video surveillance system. Images from six cameras were visible to everyone on a monitor in the store, which breached GDPR requirements. | IT | Garante | GDPR | €1,000 | ↗ |
| 26 Mar 2026 | SOCIÉTÉ EXERÇANT UNE ACTIVITÉ D'ARTS DU SPECTACLE VIVANT (procédure simplifiée)CNIL imposed a fine of 850 EUR on SOCIÉTÉ EXERÇANT UNE ACTIVITÉ D'ARTS DU SPECTACLE VIVANT in connection with the liquidation of astreinte. The case concerns compliance with a prior obligation under a simplified procedure. | FR | CNIL | GDPR | €850 | ↗ |
| 26 Mar 2026 | Provvedimento del 26 marzo 2026 [10246060]The entity was fined for operating a video surveillance system without providing adequate informational signage. The authority found this to be a breach of GDPR Article 13 on the duty to inform data subjects. | IT | Garante | GDPR | €2,000 | ↗ |
| 26 Mar 2026 | Copacabana s.r.l.Copacabana s.r.l. was fined EUR 2,000 by the Garante for installing a video surveillance system without the required informational signage and necessary authorization. The authority cited a breach of GDPR Article 13. | IT | Garante | GDPR | €2,000 | ↗ |
| 26 Mar 2026 | Messina Social CityMessina Social City was fined by the Garante 10,000 EUR for breaching GDPR principles. The case concerned the improper dissemination of personal data, including images of minors, on Facebook without proper legal grounds and contracts. | IT | Garante | GDPR | €10,000 | ↗ |
| 26 Mar 2026 | Provvedimento del 26 marzo 2026 [10241477]A doctor did not comply with a request to delete data and provided patients with incomplete information, which constituted a breach of GDPR Article 13. The Garante imposed a fine of EUR 2,000. | IT | Garante | GDPR | €2,000 | ↗ |
| 26 Mar 2026 | Comune di XXThe Garante fined Comune di XX EUR 5,000 for breaches of lawfulness, fairness, transparency, and data minimization. It also found failures to implement data protection by design and by default. | IT | Garante | GDPR | €5,000 | ↗ |
| 26 Mar 2026 | Eni S.p.A.Eni S.p.A. was fined 96,000 EUR by the Garante for publishing personal data on its website, including dates of birth and addresses, without proper masking. The authority found this breached GDPR principles of lawfulness, fairness, and transparency. | IT | Garante | GDPR | €96,000 | ↗ |
| 26 Mar 2026 | SOCIÉTÉ AYANT POUR ACTIVITÉ L'HÉBERGEMENT DE TOURISME (procédure simplifiée)CNIL imposed an administrative fine of EUR 3,000 on SOCIÉTÉ AYANT POUR ACTIVITÉ L'HÉBERGEMENT DE TOURISME under a simplified procedure. The case concerns a confirmed breach of rules supervised by CNIL. | FR | CNIL | GDPR | €3,000 | ↗ |
| 26 Mar 2026 | PSK AD Network S.r.l.PSK AD Network S.r.l. was fined EUR 5,000 by the Garante. The case concerned the failure to respond to a data subject’s deletion request and the failure to provide information requested by the authority, in breach of Article 157 of the Codice. | IT | Garante | GDPR | €5,000 | ↗ |
| 26 Mar 2026 | SOCIÉTÉ ORGANISANT DES ÉVÈNEMENTS PAR LA PROMOTION ET LA VENTE DE BILLETS (procédure simplifiée)The CNIL imposed an administrative fine of EUR 15,000 on the company organizing events and selling tickets, and issued an injunction. The case was handled under a simplified procedure. | FR | CNIL | GDPR | €15,000 | ↗ |
| 26 Mar 2026 | Ordine degli Avvocati di PiacenzaOrdine degli Avvocati di Piacenza was fined EUR 3,000 by the Garante for improper handling of disciplinary sanctions in its professional register. The authority found that the processing did not comply with data protection requirements. | IT | Garante | GDPR | €3,000 | ↗ |
| 26 Mar 2026 | Comune di CassinoComune di Cassino was fined for unlawfully publishing personal data online. The case concerns a breach of data protection rules and indicates a need to review procedures for publishing public information. | IT | Garante | GDPR | €2,500 | ↗ |
| 26 Mar 2026 | Comune di XXThe Garante fined Comune di XX EUR 3,000 for breaches of GDPR Articles 6 and 9 and Article 2-ter of the Italian Privacy Code. The case concerned processing personal data without a proper legal basis. | IT | Garante | GDPR | €3,000 | ↗ |
| 24 Mar 2026 | SIA "Fitsypro"SIA "Fitsypro" was fined EUR 1,500 by the DVI. The decision has entered into force. | LV | DVI | GDPR | €1,500 | ↗ |
| 23 Mar 2026 | ING Bank NV Amsterdam – Sucursala București S.A.The fine was imposed for failing to implement adequate technical and organizational measures to ensure the confidentiality of personal data. As a result, an unauthorized third party received a bank account statement. | RO | ANSPDCP | GDPR | €4,000 | ↗ |