BULLETIN №081Last updated · 26 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -20.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 06 Jun 2024 | Eni Plenitude S.p.A. Società BenefitEni Plenitude S.p.A. was fined by the Garante 6,419,631 EUR for making unsolicited promotional calls without prior consent. The company also used numbers listed in the Public Opposition Register, which constituted a breach of GDPR rules. | IT | Garante | GDPR | €6,419,000 | ↗ |
| 05 Feb 2026 | Dane anonimowe (X.)UODO imposed an administrative fine of PLN 6,251,471 on Dane anonimowe (X.) for breaching Article 28(3) GDPR. The company used external transport providers without prior data processing agreements and without implementing adequate organizational measures to ensure data security. | PL | UODO | GDPR | €1,481,000 | ↗ |
| 01 Dec 2023 | ENDESA, S.A.The Spanish data protection authority imposed a EUR 6.1 million fine on ENDESA in December 2023. The case involved a security breach that led to the sale of customer personal data through Facebook ads. | ES | Agencia Española de Protección de Datos | GDPR | €6,100,000 | ↗ |
| 26 Feb 2025 | SportadminIMY fined Sportadmin SEK 6 million after an IT attack exposed personal data of more than 2.1 million individuals, mostly children. The authority found that the company had not maintained an appropriate security level for the personal data it processed. | SE | Integritetsskyddsmyndigheten | GDPR | €538,000 | ↗ |
| 01 Jan 2022 | CosmoteThe Greek data protection authority imposed a €6 million fine on Cosmote under decision 4/2022. The sanction concerned inadequate security measures and retaining more data than permitted after a 2020 cyberattack. | GR | Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα | GDPR | €6,000,000 | ↗ |
| 17 Jun 2024 | FÚTBOL CLUB BARCELONAFútbol Club Barcelona was fined by the AEPD for processing biometric data without explicit consent during a mandatory member census update. The authority found breaches of GDPR Articles 9 and 35, relating to special-category data processing and data protection impact assessment requirements. | ES | AEPD | GDPR | €6,000,000 | ↗ |
| 26 Aug 2020 | Anonymizováno (ÚOOÚ UOOU-03916/19-49)The entity was fined for sending unsolicited commercial communications without a valid legal basis. The conduct violated the Czech law on certain information society services. | CZ | UOOU | ePrivacy | €228,000 | ↗ |
| 26 Jan 2026 | SportAdmin i Skandinavien ABSportAdmin i Skandinavien AB was fined by IMY 6,000,000 SEK for failing to implement appropriate technical and organizational measures to ensure an adequate level of security for personal data. The deficiency resulted in a data breach. | SE | IMY | GDPR | €564,000 | ↗ |
| 16 Mar 2026 | Restaurant Partner PolskaThe Polish Data Protection Authority imposed an administrative fine of PLN 5,898,064 on Restaurant Partner Polska, the operator of Glovo in Poland. The authority found that the company unlawfully collected and processed scans and photos of users’ identity documents, in breach of GDPR requirements. | PL | Urząd Ochrony Danych Osobowych | GDPR | €1,381,000 | ↗ |
| 19 Feb 2026 | Dane anonimowe (W.)UODO imposed an administrative fine of PLN 5,898,064 on Dane anonimowe (W.). The authority found that the company processed personal data without a legal basis and in a manner that was excessive and disproportionate to the stated purpose, including by collecting photos or scans of identity cards or passports. | PL | UODO | GDPR | €1,397,000 | ↗ |
| 02 Feb 2017 | Sigue Global Service LimitedSigue Global Service Limited was fined by the Garante 5,880,000 EUR for breaches of data protection rules and anti-money laundering requirements. The authority cited money transfers carried out without proper consent, techniques used to obscure the true origin of funds, and non-compliance with AML obligations. | IT | Garante | GDPR | €5,880,000 | ↗ |
| 12 Jan 2023 | WhatsApp Ireland Ltd.The Irish DPC fined WhatsApp Ireland Ltd. EUR 5,500,000 in case IN-18-5-6. The decision is currently under appeal. | IE | DPC | GDPR | €5,500,000 | ↗ |
| 11 Jul 2024 | EOS MatrixAZOP imposed a EUR 5.47 million fine on EOS Matrix for a personal data protection breach following an incident involving the data of 181,641 debtors. The case was described as a GDPR violation and the largest fine in the authority's history. | HR | AZOP | GDPR | €5,470,000 | ↗ |
| 17 Apr 2023 | SOCIETE DEVELOPPANT UN LOGICIEL DE RECONNAISSANCE FACIALECNIL imposed a penalty of EUR 5,200,000 on SOCIETE DEVELOPPANT UN LOGICIEL DE RECONNAISSANCE FACIALE in connection with the liquidation of astreinte. The case concerns failure to comply with a prior obligation within the required timeframe, resulting in this amount being due. | FR | CNIL | GDPR | €5,200,000 | ↗ |
| 18 Oct 2019 | National Revenue Agency (Bulgaria)The Commission for Personal Data Protection imposed a fine of 5,100,000 BGN on Bulgaria’s National Revenue Agency. The sanction concerned the unauthorized disclosure and dissemination of personal data following a major security breach. | BG | Commission for Personal Data Protection | GDPR | €2,607,000 | ↗ |
| 18 Aug 2023 | Személyes adatok kezelése online közszolgáltatás nyújtása soránThe supervisory authority found that the controller did not provide adequate information about the data retention period. It also unlawfully refused access to the requested call recordings, breaching GDPR Articles 12, 13, and 15. | HU | NAIH | GDPR | €13,050 | ↗ |
| 19 Apr 2021 | BankThe Bank was fined by NAIH for breaching the principles of purpose limitation and data minimization when transferring personal data without a proper legal basis. The authority also found failures to respect the data subject's rights of access and objection. | HU | NAIH | GDPR | €13,900 | ↗ |
| 27 Oct 2021 | ImportőrImportőr was fined by the NAIH 5,000,000 HUF for processing personal data without properly informing the data subjects and without a valid legal basis. The authority found breaches of lawfulness, transparency, accountability, and data minimization principles. | HU | NAIH | GDPR | €13,750 | ↗ |
| 27 Jun 2022 | NAVThe Norwegian DPA fined NAV 5,000,000 NOK for making CVs available on arbeidsplassen.no without a lawful basis under the GDPR. The case concerned unauthorized processing of personal data relating to job seekers and employees. | NO | Datatilsynet | GDPR | €480,000 | ↗ |
| 18 Jun 2021 | Kiskorúra vonatkozó egészségügyi adatok közlése országos híradásbanThe authority found that the respondent disclosed the complainant’s personal data and special-category health data without a lawful basis. Several GDPR provisions were breached, and a fine of HUF 5,000,000 was imposed. | HU | NAIH | GDPR | €14,050 | ↗ |