BULLETIN №082Last updated · 29 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 07 Jul 2022 | Głównego Geodetę Kraju z siedzibą w Warszawie, przy ul.UODO imposed a PLN 60,000 administrative fine on the Chief Geodesist of Poland. The authority found that the personal data breach was not reported to the supervisory authority without undue delay and that affected individuals were not notified. | PL | UODO | GDPR | €12,573 | ↗ |
| 05 Oct 2023 | DPP Law LtdThe Information Commissioner's Office issued a monetary penalty notice against DPP Law Ltd. The firm was fined GBP 60,000 for failing to implement appropriate technical and organisational measures to secure personal data. | GB | Information Commissioner's Office | GDPR | €69,282 | ↗ |
| 10 Feb 2020 | XFERA MÓVILES, S.A.XFERA MÓVILES, S.A. was fined by the AEPD for processing personal data without valid consent. The case concerned a debt claim made against an individual for a contract they had not entered into. | ES | AEPD | GDPR | €60,000 | ↗ |
| 09 Jul 2025 | REAL SOCIEDAD DE FUTBOL S.A.D.REAL SOCIEDAD DE FUTBOL S.A.D. suffered a ransomware attack that led to a data breach affecting 60,000 individuals, including biometric, identification, financial, and health data. The AEPD fined the company for failing to implement adequate technical and organizational measures to protect data security. | ES | AEPD | GDPR | €60,000 | ↗ |
| 06 Mar 2020 | BANCO BILBAO VIZCAYA ARGENTARIA, S.A.BBVA was fined by the AEPD for inaccurate processing of personal data. The bank demanded payment for a debt the complainant did not owe and shared the complainant’s personal data with a debt collection agency. | ES | AEPD | GDPR | €60,000 | ↗ |
| 12 Jun 2014 | Istituto Poligrafico e Zecca dello Stato S.p.AIstituto Poligrafico e Zecca dello Stato S.p.A was fined EUR 60,000 by the Garante. The authority found that the company did not fully implement required security measures, in particular the logging of system administrator access to electronic archives. | IT | Garante | GDPR | €60,000 | ↗ |
| 06 Mar 2025 | Dane anonimowe (J.)UODO imposed an administrative fine of PLN 56,824 on Anonymous data (J.) for failing to implement appropriate technical and organizational measures to ensure processing security. The case concerned a breach of personal data protection obligations. | PL | UODO | GDPR | €13,604 | ↗ |
| 30 Aug 2023 | Dane anonimowe (A. S.A. z siedzibą w W. przy ul.)The President of UODO imposed an administrative fine of PLN 56,592 on the company. The sanction resulted from failure to cooperate with the authority and from not providing access to personal data and information necessary for its tasks. | PL | UODO | GDPR | €12,652 | ↗ |
| 05 May 2022 | LYCAMOBILE S.L.U.LYCAMOBILE S.L.U. was fined by the AEPD 56,000 EUR for processing personal data without consent. The case involved unauthorized phone number portability, which could create a risk of identity theft. | ES | AEPD | GDPR | €56,000 | ↗ |
| 25 Apr 2019 | Dane anonimowe (E. z siedzibą w O. przy ul.)The UODO found a breach of rules on the security and confidentiality of processed personal data. As a result, a fine of PLN 55,750.50 was imposed. | PL | UODO | GDPR | €12,980 | ↗ |
| 19 Jun 2015 | TEKOA CANALTV, S.L.TEKOA CANALTV, S.L. was fined by the AEPD in the amount of 55,000 EUR for sending 25 commercial SMS messages without prior consent from recipients. The authority also noted the absence of an opt-out mechanism, in breach of the LSSI. | ES | AEPD | ePrivacy | €55,000 | ↗ |
| 28 May 2026 | AgID – Agenzia per l’Italia digitaleThe Italian Data Protection Authority fined AgID €55,000 for failing to adequately inform professionals about the automatic registration of their digital domiciles. The authority found breaches of transparency and data processing principles. | IT | Garante | GDPR | €55,000 | ↗ |
| 15 Dec 2022 | Azienda Universitaria Friuli OccidentaleAzienda Universitaria Friuli Occidentale was fined EUR 55,000 by the Garante for processing personal data without a legal basis. The authority also found that the organization failed to provide required information about data deletion, in breach of the GDPR and national privacy rules. | IT | Garante | GDPR | €55,000 | ↗ |
| 03 Sept 2019 | Национална агенция за приходитеThe National Revenue Agency was fined 55,000 BGN for processing personal data without a lawful basis. The authority found that data were collected and used in enforcement proceedings in breach of Article 6 GDPR. | BG | CPDP | GDPR | €28,122 | ↗ |
| 21 Sept 2023 | House Hold Appliances 247 LtdHouse Hold Appliances 247 Ltd made 19,069 marketing calls to individuals in breach of regulation 21 of PECR. The ICO fined the company 55,000 GBP and issued an enforcement notice. | GB | ICO | ePrivacy | €63,426 | ↗ |
| 15 Dec 2022 | Azienda Universitaria Friuli CentraleAzienda Universitaria Friuli Centrale was fined EUR 55,000 by the Garante for processing personal data without a legal basis. The authority also found failures to provide instructions for data deletion and to stop unauthorized processing by Insiel spa. | IT | Garante | GDPR | €55,000 | ↗ |
| 11 Jun 2020 | XFERA MÓVILES, S.A. (YOIGO)XFERA MÓVILES, S.A. (YOIGO) was fined EUR 55,000 by the AEPD for linking a phone number to a third party’s data. This created unauthorized access and a risk of data alteration, breaching data protection rules. | ES | AEPD | GDPR | €55,000 | ↗ |
| 16 Jul 2020 | TELEFÓNICA DE ESPAÑA, S.A.U.TELEFÓNICA DE ESPAÑA, S.A.U. was fined EUR 55,000 by the AEPD for processing personal data without consent. The company registered phone lines and charged invoices to an individual who had not authorized these actions. | ES | AEPD | GDPR | €55,000 | ↗ |
| 01 Jan 2019 | VODAFONE ESPAÑA, S.A.U.The AEPD imposed a fine of EUR 55,000 on Vodafone España, S.A.U. for breaching data protection principles. The case involved sending a customer's personal data to a third party without adequate security measures. | ES | AEPD | GDPR | €55,000 | ↗ |
| 28 Sept 2023 | MCP Online LtdThe ICO fined MCP Online Ltd 55,000 GBP after finding that 20,939 calls were made between 1 January 2022 and 28 September 2022 to numbers registered with the CTPS or TPS. The conduct breached Regulations 21 and 24 of PECR and came to light through Operation Torc, which investigates unsolicited pensions calls. | GB | ICO | ePrivacy | €63,707 | ↗ |