BULLETIN №082Last updated · 30 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 02 Dec 2020 | Sahlgrenska UniversitetssjukhusetSahlgrenska University Hospital was fined SEK 3.5 million for failing to perform the required needs and risk analysis before granting access rights in its medical record systems. The authority found this breached GDPR requirements on data security and accountability. | SE | IMY | GDPR | €340,000 | ↗ |
| 19 Jan 2023 | Sąd Rejonowy Szczecin-Centrum z siedzibą w Szczecinie przy ul.The UODO imposed an administrative fine of PLN 30,000 on the Szczecin-Centrum District Court. The authority found that appropriate technical and organizational measures were not implemented to match the risk of processing data using portable storage devices. | PL | UODO | GDPR | €6,374 | ↗ |
| 19 Dec 2023 | Sąd Okręgowy w Krakowie za naruszenie art. 33 ust. 1 i ust. 2 oraz art. 34 ust. 1 i ust. 2 rozporządzenia 2016/679UODO imposed an administrative fine of 10,000 PLN on the Regional Court in Kraków. The case concerns breaches of obligations related to personal data breach notification and informing affected individuals. | PL | UODO | GDPR | €2,306 | ↗ |
| 23 Oct 2014 | S.A.B. Alberghi di Baveno s.p.a.S.A.B. Alberghi di Baveno s.p.a. was fined by the Garante in the amount of €2,400 for processing personal data connected with job applications without providing the required information notice. The case concerned the information duty under Article 13 of the Italian Privacy Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 05 Mar 2020 | S.Á.Á.S.Á.Á. was fined for a data breach in which a former employee received sensitive patient information. The authority found that technical and organizational measures were inadequate. | IS | Persónuvernd | GDPR | €21,090 | ↗ |
| 13 Sept 2012 | Ruzzo Reti S.p.a.Ruzzo Reti S.p.a. was fined EUR 4,000 by the Italian Garante. The authority found that the company failed to designate data processors, meaning it did not adopt the minimum security measures required by the Italian Privacy Code. | IT | Garante | GDPR | €4,000 | ↗ |
| 23 Jan 2020 | Runwhip s.r.l.Runwhip s.r.l. was fined €80,000 by the Italian supervisory authority, Garante. The sanction concerned failure to respond to information requests, which was treated as a breach of GDPR Article 5. | IT | Garante | GDPR | €80,000 | ↗ |
| 12 Nov 2014 | Ruggiero FerdinandoRuggiero Ferdinando was fined EUR 10,000 by the Garante. The sanction concerned failing to provide a complete response to a request for information during a privacy investigation. | IT | Garante | GDPR | €10,000 | ↗ |
| 06 Feb 2020 | R.T.I. - Reti Televisive Italiane s.p.a.R.T.I. - Reti Televisive Italiane s.p.a. was fined EUR 20,000 by the Garante for broadcasting a segment on “Le Iene”. The segment made the complainant identifiable through her voice and personal information, breaching data protection rules. | IT | Garante | GDPR | €20,000 | ↗ |
| 09 May 2025 | ROUMASPORT SRLIn April 2025, Romania’s data protection authority ANSPDCP completed an investigation at ROUMASPORT SRL. The authority found GDPR violations and imposed a fine of 5,000 EUR. | RO | ANSPDCP | GDPR | €5,000 | ↗ |
| 30 Dec 2025 | Roumasport S.R.LRoumasport S.R.L was fined EUR 10,000 by ANSPDCP for violating GDPR provisions. The case concerns non-compliant processing of personal data. | RO | ANSPDCP | GDPR | €10,000 | ↗ |
| 25 May 2022 | Roularta Media GroupRoularta Media Group was fined EUR 50,000 by the APD for using cookies on its media websites without obtaining valid user consent. The authority found this practice breached GDPR and ePrivacy Directive requirements. | BE | APD | ePrivacy | €50,000 | ↗ |
| 25 May 2022 | RoulartaThe Belgian data protection authority, APD, sanctioned Roularta in decision 85/2022 of 25 May 2022. The case concerned the placement of non-essential cookies on its press websites without prior user consent. The fine was EUR 50,000. | BE | Autorité de protection des données | GDPR | €50,000 | ↗ |
| 04 Feb 2013 | ROTULACION Y DISEÑO ALBACETE S.L.The entity was fined for sending unsolicited commercial emails and for failing to provide the required data protection information on its website. The case concerns breaches of information duties and rules on marketing communications. | ES | AEPD | ePrivacy | €1,200 | ↗ |
| 14 Dec 2017 | Rotondi AndreaAndrea Rotondi was fined for the improper handling of banking documents that were found by a private citizen. Banca Nazionale del Lavoro was held jointly liable for the violation. | IT | Garante | GDPR | €4,000 | ↗ |
| 24 Apr 2024 | Rossi Carta S.r.l. UnipersonaleRossi Carta S.r.l. Unipersonale was fined by the Garante 30,000 EUR for sending unsolicited promotional emails and failing to respond to a data subject rights request. The authority also noted the use of an outdated content management system on the company website, which created potential security risks for personal data. | IT | Garante | GDPR | €30,000 | ↗ |
| 22 May 2013 | Romulus PopescuRomulus Popescu was fined EUR 16,000 by the Garante. The sanction concerned sending unsolicited promotional communications to a minor without proper consent. | IT | Garante | GDPR | €16,000 | ↗ |
| 13 Nov 2023 | Rompetrol Downstream SRLRompetrol Downstream SRL was fined EUR 110,000 by ANSPDCP for failing to ensure the security of personal data. The authority found a breach of Article 32 GDPR, which requires appropriate technical and organizational measures. | RO | ANSPDCP | GDPR | €110,000 | ↗ |
| 13 May 2025 | Romoffice Construct Holding Ag SRLThe company was fined by ANSPDCP €2,000 for processing personal data without a legal basis. The breach concerned the principles of lawfulness, fairness, and transparency. | RO | ANSPDCP | GDPR | €2,000 | ↗ |
| 12 Sept 2022 | ROMESTONE, S.L.ROMESTONE, S.L. was fined by the AEPD 6,000 EUR for installing a surveillance camera in a shared rental property without tenant consent. The case concerns a privacy breach in the context of personal data processing. | ES | AEPD | GDPR | €6,000 | ↗ |