BULLETIN №082Last updated · 30 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.2%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 17 Apr 2026 | Poste Italiane S.p.a. e PostePay S.p.a.Poste Italiane S.p.a. and PostePay S.p.a. were sanctioned for unlawful processing of personal data in their Bancoposta and PostePay apps on Android devices. The apps required users to authorize access to data to detect malicious software, which breached GDPR principles. | IT | Garante | GDPR | €6,624,000 | ↗ |
| 06 Oct 2022 | Poste Italiane S.p.a.Poste Italiane S.p.a. was fined 10,000 EUR by the Garante. The authority found a breach of Article 15 GDPR due to failure to respond to a data access request. | IT | Garante | GDPR | €10,000 | ↗ |
| 27 May 2021 | Poste Italiane S.p.a.Poste Italiane S.p.a. was fined by the Garante 10,000 EUR for unlawfully communicating a customer's financial data related to a Postepay card to an unauthorized third party. The case concerns a breach of personal data protection and financial confidentiality requirements. | IT | Garante | GDPR | €10,000 | ↗ |
| 06 Oct 2022 | Poste Italiane S.p.a.Poste Italiane S.p.a. was fined by the Garante in the amount of 10,000 EUR for failing to respond to a data access request. The authority found a breach of Article 15 of the GDPR. | IT | Garante | GDPR | €10,000 | ↗ |
| 10 Jan 2023 | POSADA DE LLERENA, S.L.POSADA DE LLERENA, S.L. was fined 2,000 EUR by the AEPD for requesting excessive personal data from customers, including copies of ID documents, as a condition for accommodation. The authority found this practice breached the GDPR data minimization principle. | ES | AEPD | GDPR | €2,000 | ↗ |
| 28 Apr 2026 | POSADA DEL LEÓN DE ORO, C.B.POSADA DEL LEÓN DE ORO, C.B. was fined EUR 400 by the AEPD for improper use of a surveillance system that recorded audio and video. The authority found violations of employee privacy and of the duty to inform data subjects about processing, contrary to GDPR Articles 5(1)(c) and 13. | ES | AEPD | GDPR | €400 | ↗ |
| 30 Jun 2011 | Porto di Tropea s.p.a.Porto di Tropea s.p.a. was fined by the Garante 10,000 EUR for failing to provide adequate information about video surveillance. The authority also found that data processors were not formally appointed for customer data collected through mooring contracts. | IT | Garante | GDPR | €10,000 | ↗ |
| 27 Oct 2016 | Porto di Imperia s.p.a.Porto di Imperia s.p.a. was fined by the Italian Garante in the amount of €2,400. The authority found a data protection breach linked to the use of a video surveillance system because individuals entering the port were not provided with simplified information. | IT | Garante | GDPR | €2,400 | ↗ |
| 25 Jan 2012 | Porto 2000 società cooperativa a r. l.Porto 2000 società cooperativa a r. l. was fined EUR 30,000 by the Garante. The authority found that the company had not appointed data processing officers and had failed to implement minimum security measures for the video surveillance system at the Ancona tourist port. | IT | Garante | GDPR | €30,000 | ↗ |
| 05 Oct 2020 | Pontosság elvének megsértéseThe controller was fined for processing inaccurate personal data, in breach of the accuracy principle under GDPR Art. 5(1)(d). The authority also ordered correction of the complainant’s address data. | HU | NAIH | GDPR | €1,674 | ↗ |
| 14 Mar 2013 | PONTE EN FORMA ONLINE, S.L.PONTE EN FORMA ONLINE, S.L. was fined by the AEPD EUR 50,000 for sending unsolicited commercial email communications. The conduct breached Article 21 of the LSSI, which restricts marketing emails sent without prior consent. | ES | AEPD | ePrivacy | €50,000 | ↗ |
| 05 May 2016 | Polo scolastico paritario Scuola Domani s.r.l.The private school Polo scolastico paritario Scuola Domani s.r.l. was fined EUR 2,400 by the Garante. The authority found that the website did not provide the required privacy information to users submitting inquiries or job applications. | IT | Garante | GDPR | €2,400 | ↗ |
| 21 Mar 2013 | Pologest s.r.l.Pologest s.r.l. was fined by the Garante €6,400 for sending unsolicited promotional communications by fax. The conduct breached data protection rules governing marketing communications. | IT | Garante | GDPR | €6,400 | ↗ |
| 21 Dec 2022 | Politie NederlandThe Dutch Data Protection Authority fined the police chief for failing to carry out a data protection impact assessment before using mobile camera cars in Rotterdam. The measure created a high risk to individuals' rights and freedoms. | NL | AP | GDPR | €50,000 | ↗ |
| 22 Oct 2024 | political partyThe Hellenic Data Protection Authority imposed a 10,000 EUR fine on a political party for unlawful processing of the personal data of overseas voters. The case concerns data protection breaches in the handling of electoral information. | GR | Hellenic Data Protection Authority | GDPR | €10,000 | ↗ |
| 09 May 2024 | Polisportiva Mimmo Ferrito s.r.l.The Garante fined Polisportiva Mimmo Ferrito s.r.l. EUR 3,000 for failing to respond to a data subject's request to exercise their rights. The case concerns non-compliance with data protection obligations. | IT | Garante | GDPR | €3,000 | ↗ |
| 16 Dec 2009 | Polisportiva Eschilo 1 società sportiva dilettantistica a r.l.Polisportiva Eschilo 1 was fined EUR 10,000 by the Italian Garante. The case concerned processing biometric data without prior notification to the supervisory authority, which breached data protection rules. | IT | Garante | GDPR | €10,000 | ↗ |
| 10 Feb 2021 | Polismyndigheten, Clearview AIThe Swedish Police Authority was fined for using the Clearview AI application. The authority found that the processing of personal data violated the Swedish Criminal Data Act. | SE | IMY | ePrivacy | €248,000 | ↗ |
| 12 Jun 2014 | Poligrafici Editoriale s.p.a.Poligrafici Editoriale s.p.a. was fined by the Garante 12,400 EUR for failing to provide adequate simplified information about its video surveillance system. The authority also found improper collection of personal data through subscription coupons. | IT | Garante | GDPR | €12,400 | ↗ |
| 20 Sept 2012 | Policlinico Sassarese s.p.a.Policlinico Sassarese s.p.a. was fined EUR 64,000 by the Garante for inadequate data protection measures. The authority cited insufficient video surveillance notices and missing consent documentation for the processing of sensitive data. | IT | Garante | GDPR | €64,000 | ↗ |