BULLETIN №082Last updated · 31 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.4%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 28 Oct 2021 | OTTO s.r.l.OTTO s.r.l. was fined by the Italian data protection authority, Garante, in the amount of 2,000 EUR. The case concerned a video surveillance system operated without the required privacy notice, which constitutes a breach of Article 13 GDPR. | IT | Garante | GDPR | €2,000 | ↗ |
| 13 May 2015 | Ottodue s.r.l.Ottodue s.r.l. was fined EUR 12,000 by the Garante for retaining surveillance footage for 98 days. This exceeded the 7-day retention limit set out in the video surveillance guidelines. | IT | Garante | GDPR | €12,000 | ↗ |
| 25 Nov 2022 | OTP LEASING ROMANIA IFN SAOTP LEASING ROMANIA IFN SA was fined by ANSPDCP for breaching data security provisions. The penalty followed a data breach notification indicating that personal data had not been adequately protected. | RO | ANSPDCP | GDPR | €3,000 | ↗ |
| 03 Nov 2023 | OTP BANK ROMANIA SAThe National Supervisory Authority for Personal Data Processing imposed a fine of EUR 3,000 on OTP BANK ROMANIA SA for GDPR violations. The case concerned non-compliance with personal data protection requirements. | RO | ANSPDCP | GDPR | €3,000 | ↗ |
| 08 Jan 2015 | OTEThe Hellenic Data Protection Authority fined OTE EUR 60,000 for failing to implement adequate security measures. The deficiency led to a data breach involving personal data of a large number of subscribers. | GR | HDPA | ePrivacy | €60,000 | ↗ |
| 07 Oct 2019 | OTEOTE was fined by the HDPA EUR 200,000 for failing to process unsubscribe requests from marketing emails due to a technical error. The issue affected about 8,000 subscribers and had been ongoing since 2013. | GR | HDPA | GDPR | €200,000 | ↗ |
| 09 Oct 2018 | OTEThe Hellenic Data Protection Authority imposed a fine of EUR 150,000 on OTE. The case concerned unsolicited promotional calls made to subscribers who had previously opted out of such contact. | GR | HDPA | ePrivacy | €150,000 | ↗ |
| 21 Feb 2025 | Österreichische Post AGThe Austrian Federal Administrative Court upheld a major GDPR fine against Österreichische Post AG for unlawful processing of political affinity data and other personal data used in direct marketing. The court reduced the penalty from EUR 18 million to EUR 16 million, while confirming the underlying data protection breaches. | AT | Österreichische Datenschutzbehörde | GDPR | €16,000,000 | ↗ |
| 22 Feb 2024 | Ossitocina24 di Patrono AntonellaOssitocina24 di Patrono Antonella was fined 5,000 EUR by the Italian Garante. The case concerned the failure to delete personal data from its website after a contract termination request, which breached GDPR data processing requirements. | IT | Garante | GDPR | €5,000 | ↗ |
| 24 Jun 2021 | Ospedale Pediatrico Bambino GesùOspedale Pediatrico Bambino Gesù was fined by the Garante 15,000 EUR for breaches involving a data incident and improper handling of patient health data. The authority cited violations of GDPR Articles 5 and 32 on lawful processing and security of personal data. | IT | Garante | GDPR | €15,000 | ↗ |
| 01 Sept 2025 | Osnovna škola XThe school unlawfully forwarded personal data of 18 employees to the City of Y, breaching GDPR Articles 5 and 6. AZOP imposed a fine of EUR 2,000. | HR | AZOP | GDPR | €2,000 | ↗ |
| 01 Sept 2025 | Osnovna škola XAZOP imposed a fine of EUR 2,000 on Osnovna škola X for breaching GDPR rules on personal data processing. The case involved unlawful processing of personal data, indicating a compliance failure under data protection requirements. | HR | AZOP | GDPR | €2,000 | ↗ |
| 14 Jun 2018 | Osimo Servizi s.p.a.Osimo Servizi s.p.a. was fined EUR 8,000 by the Garante. The breach concerned the failure to notify the processing of biometric data used in an employee attendance system. | IT | Garante | GDPR | €8,000 | ↗ |
| 22 Nov 2023 | ORTHOPHONISTE (procédure simplifiée)CNIL imposed a EUR 5,000 fine on ORTHOPHONISTE under a simplified procedure and issued an injunction. The case concerns a breach of the data protection authority’s requirements. | FR | CNIL | GDPR | €5,000 | ↗ |
| 11 Oct 2024 | ORTHOPHONISTE (procédure simplifiée)The CNIL imposed a 4,000 EUR penalty on ORTHOPHONISTE (procédure simplifiée) in connection with the liquidation of an astreinte. The case concerns compliance with a prior obligation under the data protection authority’s supervision. | FR | CNIL | GDPR | €4,000 | ↗ |
| 10 Jun 2021 | orthodontiepraktijkThe entity failed to implement appropriate technical and organizational measures to secure personal data, which constitutes a breach of Article 32 GDPR. Sensitive data on the website was not transmitted over encrypted connections, increasing the risk of disclosure. | NL | AP | GDPR | €12,000 | ↗ |
| 30 Jan 2014 | Orovicenza di Picaro CristinaOrovicenza di Picaro Cristina was fined EUR 4,800 by the Garante. The authority found that the website’s contact and registration forms did not provide the required data protection information, in breach of the Italian data protection code. | IT | Garante | GDPR | €4,800 | ↗ |
| 06 Aug 2025 | ORNITOLÓGICA DE ANDALUCÍA FOAORNITOLÓGICA DE ANDALUCÍA FOA was fined EUR 1,500 by the AEPD for sending a mass email that contained personal data, including names and DNI numbers, without adequate security measures. The authority found this to be a breach of data protection rules. | ES | AEPD | GDPR | €1,500 | ↗ |
| 16 Apr 2022 | ORI, S.l.ORI, S.l. was fined by the AEPD 2,000 EUR for failing to provide a privacy policy on its website. Personal data was collected through multiple forms, which constituted a breach of data protection rules. | ES | AEPD | GDPR | €2,000 | ↗ |
| 18 Dec 2018 | ORGANIZACION NACIONAL DE CIEGOS (ONCE)ONCE was fined EUR 40,000 by the AEPD for sending more than 200 unsolicited commercial emails without prior consent. The authority found this to be a breach of Article 21 of the LSSI governing electronic marketing communications. | ES | AEPD | ePrivacy | €40,000 | ↗ |