BULLETIN №081Last updated · 26 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -20.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 02 Jul 2024 | ALDI MAGYARORSZÁG ÉLELMISZER Élelmiszer Kereskedelmi Betéti TársaságNAIH imposed a HUF 95,000,000 fine on ALDI Magyarország for GDPR violations linked to data processing during alcohol purchases. The authority cited improper age verification and insufficient personal data protection measures. | HU | NAIH | GDPR | €240,000 | ↗ |
| 02 Dec 2020 | Aleris Närsjukvård ABAleris Närsjukvård AB was fined by IMY for failing to conduct a needs and risk analysis before granting access rights in its medical record systems. The authority found this breached GDPR data security requirements. | SE | IMY | GDPR | €1,167,000 | ↗ |
| 02 Dec 2020 | Aleris Sjukvård ABAleris Sjukvård AB was fined by IMY for failing to conduct a needs and risk analysis before granting access rights in its TakeCare journal system. The authority found this breached GDPR security requirements. | SE | IMY | GDPR | €1,458,000 | ↗ |
| 02 Apr 2015 | Ales Groupe Italia S.p.A.Ales Groupe Italia S.p.A. was fined EUR 20,000 by the Garante for violations related to data processing on its website. Users were asked to provide personal data without proper consent mechanisms. | IT | Garante | GDPR | €20,000 | ↗ |
| 22 May 2018 | Alessandro SabatiniAlessandro Sabatini, a general practitioner, was fined EUR 10,000 by the Garante. The authority found that minimum personal data security measures were not implemented, which allowed unauthorized access to a health information system. | IT | Garante | GDPR | €10,000 | ↗ |
| 24 Mar 2021 | Ålesund kommuneÅlesund kommune was fined by Datatilsynet for using the Strava app in schools without conducting a risk assessment. As a result, students’ personal data was processed without adequate controls and safeguards. | NO | Datatilsynet | GDPR | €4,923 | ↗ |
| 29 Apr 2021 | Alfa Shipyard s.r.l.Alfa Shipyard s.r.l. was fined by the Garante in the amount of €5,000 for failing to respond to a data subject's request for information. The authority found this to be a breach of GDPR obligations. | IT | Garante | GDPR | €5,000 | ↗ |
| 21 Jan 2016 | Alfonso EspositoAlfonso Esposito, a gynecologist, was fined by the Garante for processing clients’ personal data for medical purposes without obtaining their consent. The authority found this to be a breach of the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 18 Feb 2026 | ALÍA GESTIÓN INTEGRAL DE SERVICIOS, S.L.ALÍA GESTIÓN INTEGRAL DE SERVICIOS, S.L. was fined EUR 250,000 by the AEPD for a data protection breach. The incident involved unauthorized access to the internal network after VPN credentials were compromised. | ES | AEPD | GDPR | €250,000 | ↗ |
| 15 Mar 2023 | Alianța pentru Unirea RomânilorThe fine was imposed for collecting personal data through a website without informing the data subjects and without meeting the conditions for lawful processing. The breach affected a significant number of individuals and indicates non-compliance with basic transparency and legality requirements. | RO | ANSPDCP | GDPR | €10,000 | ↗ |
| 12 Jan 2024 | Alior Bank SA Varșovia Sucursala BucureștiAlior Bank SA, through its Romanian branch, was fined EUR 17,000 by ANSPDCP. The sanction followed an investigation that identified GDPR violations. | RO | ANSPDCP | GDPR | €17,000 | ↗ |
| 14 Aug 2025 | ALIQUAM SOFTWARE DEVELOPMENT, S.R.L.UALIQUAM SOFTWARE DEVELOPMENT, S.R.L.U was fined by the AEPD 1,400 EUR for sending unsolicited marketing emails despite requests to stop. The case concerns a breach of the LSSI rules on commercial communications. | ES | AEPD | ePrivacy | €1,400 | ↗ |
| 10 Apr 2025 | Aliseo s.r.l.Aliseo s.r.l. was fined by the Garante for operating a video surveillance system without proper notice and for monitoring employees, including audio recording. The authority found the monitoring disproportionate to the stated security purpose. | IT | Garante | GDPR | €5,000 | ↗ |
| 12 Apr 2012 | Alitalia – Compagnia Aerea Italiana s.p.a.Alitalia was fined by the Garante for inadequate data protection measures and for failing to provide proper information to customers during call center interactions. The authority found that these practices breached Italian data protection law. | IT | Garante | GDPR | €120,000 | ↗ |
| 15 Jan 2018 | Alkis Alqi Zarbala ZarballaA fine was imposed for operating a video surveillance system without the required notification and for monitoring employee workspaces. These actions breached data protection rules. | GR | HDPA | GDPR | €1,000 | ↗ |
| 23 May 2019 | Alkotmányjogi panasz elbírálása a NAIH/2019/1189/11. sz. ügyben (IV/1561/2020.)The controller did not comply with a data subject access request under the GDPR. NAIH imposed a fine of HUF 300,000 for unlawful data processing. | HU | NAIH | GDPR | €918 | ↗ |
| 15 Jan 2026 | Allay Claims Ltd The ICO issued an MPN and EN to Allay Claims Ltd after a large volume of unsolicited SMS messages promoting PPI tax refund services. The case indicates a breach of direct marketing and electronic communications rules. | GB | ICO | GDPR | €138,000 | ↗ |
| 01 Jan 2013 | ALLCUPONE ESPAÑA S.L.ALLCUPONE ESPAÑA S.L. was fined by the AEPD in the amount of 600 EUR for sending unsolicited commercial emails. This conduct breached Article 21 of Spain’s LSSI, which restricts marketing communications without prior consent. | ES | AEPD | ePrivacy | €600 | ↗ |
| 11 Jun 2015 | Allevi BortoloAllevi Bortolo was fined EUR 15,000 by the Garante for activating fourteen phone cards in the names of five individuals without their knowledge. The conduct breached data protection rules and led to supervisory enforcement. | IT | Garante | GDPR | €15,000 | ↗ |
| 24 Mar 2021 | ALLIANZ COMPAÑIA DE SEGUROS Y REASEGUROS, S.A.ALLIANZ COMPAÑIA DE SEGUROS Y REASEGUROS, S.A. was fined EUR 30,000 by the AEPD. The authority found that after a policy was canceled, the company continued processing personal data without a lawful basis, in breach of Article 6 GDPR. | ES | AEPD | GDPR | €30,000 | ↗ |