BULLETIN №082Last updated · 31 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.4%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 07 Jul 2025 | AURThe Romanian data protection authority imposed two fines on AUR totaling EUR 25,000. The sanctions concerned unauthorized access to supporters' personal data in the AUR app and unlawful collection of personal data on campaign platforms. | RO | Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal | GDPR | €25,000 | ↗ |
| 19 Dec 2025 | ORANGE ESPAGNE, S.A.U.ORANGE ESPAGNE, S.A.U. was fined by the AEPD 25,000 EUR for sending invoices to a person who was not a customer and for failing to properly delete their data after a request. The authority found breaches of data accuracy and the right to erasure under GDPR Articles 5(1)(d) and 17. | ES | AEPD | GDPR | €25,000 | ↗ |
| 29 Jun 2018 | BANCO BILBAO VIZCAYA ARGENTARIA, S.A.Banco Bilbao Vizcaya Argentaria, S.A. was fined by the AEPD EUR 25,000 for sending unsolicited commercial messages. The authority found that recipients were not provided with a free opt-out mechanism. | ES | AEPD | ePrivacy | €25,000 | ↗ |
| 05 Feb 2026 | Gemeente DelftGemeente Delft processed personal data without a sufficient legal basis. It also processed special categories of personal data without a valid exception, breaching GDPR principles. | NL | AP | GDPR | €25,000 | ↗ |
| 14 Apr 2011 | Trentino Trasporti Esercizio S.p.A.Trentino Trasporti Esercizio S.p.A. was fined by the Garante 25,000 EUR for collecting personal data through web forms without providing the required privacy notice. This constituted a breach of Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €25,000 | ↗ |
| 31 Aug 2023 | Robin S.r.l.The Garante fined Robin S.r.l. 25,000 EUR for publishing a photograph of minors with insufficient anonymization. The case concerns a breach of personal data protection rules applicable to children. | IT | Garante | GDPR | €25,000 | ↗ |
| 05 Jan 2021 | DKN.5131.6.2020StatusprawomocnaTytuUODO imposed a fine of PLN 25,000 on the University for failing to report a personal data breach to the President of UODO. The institution also did not notify the affected individuals about the breach. | PL | UODO | GDPR | €5,498 | ↗ |
| 15 Nov 2012 | Gruppo Ro.Ri s.r.l.Gruppo Ro.Ri s.r.l. was fined by the Garante for failing to notify the cessation of data processing after the merger of Casa di cura S. Teresa del Bambin Gesù s.r.l. The authority found a breach of Article 38 of the Italian Data Protection Code. | IT | Garante | GDPR | €25,000 | ↗ |
| 18 Dec 2025 | TELCOM BUSINESS SOLUTIONS S.L.TELCOM BUSINESS SOLUTIONS S.L. was fined by the AEPD for attempting to process live and biometric data without prior consent. After a purchase, users were redirected to a US-based company for identity verification. | ES | AEPD | GDPR | €25,000 | ↗ |
| 05 Feb 2026 | Gemeente HilversumThe Autoriteit Persoonsgegevens found that Gemeente Hilversum processed personal data without a valid legal basis during an investigation into Muslim residents and organizations. The municipality accepted an administrative fine of 25,000 EUR and acknowledged responsibility. | NL | Autoriteit Persoonsgegevens | GDPR | €25,000 | ↗ |
| 01 Jan 2019 | GLOVOAPP23, S.L.GLOVOAPP23, S.L. was fined by the Spanish data protection authority, AEPD, in the amount of €25,000. The authority found a breach for failing to appoint a Data Protection Officer as required by Article 37 of the GDPR. | ES | AEPD | GDPR | €25,000 | ↗ |
| 01 Feb 2025 | Automobilus International S.R.L.The Romanian data protection authority fined Automobilus International S.R.L. 24,885 RON after concluding its investigation in February 2025. It found breaches of GDPR Articles 32(1) and 32(2) due to inadequate technical and organizational security measures following a personal data breach. | RO | Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal | GDPR | €5,000 | ↗ |
| 12 Nov 2024 | Dane anonimowe (X. w Y.)UODO imposed an administrative fine of PLN 24,555 on Anonymous entity (X. in Y.) for breaches of Articles 24(1), 25(1), and 32(1)-(2) of the GDPR. The authority also ordered the processing operations to be brought into compliance with Regulation (EU) 2016/679. | PL | UODO | GDPR | €5,644 | ↗ |
| 06 Feb 2014 | Oreiade s.r.l.Oreiade s.r.l. was fined by the Garante for installing a video surveillance system at Hotel Blu Inn without adequate safeguards. The authority found a breach of data protection rules. | IT | Garante | GDPR | €24,400 | ↗ |
| 17 May 2023 | Ministero delle infrastrutture e dei trasportiThe Ministry of Infrastructure and Transport was fined by the Garante for improper online disclosure of personal data. The authority found a breach of GDPR transparency obligations. | IT | Garante | GDPR | €24,000 | ↗ |
| 04 Mar 2010 | Enel s.p.a.Enel s.p.a. was fined EUR 24,000 by the Garante for failing to respond to a request for information concerning data protection. The breach concerned Articles 157 and 164 of the Italian Data Protection Code. | IT | Garante | GDPR | €24,000 | ↗ |
| 25 Jun 2015 | San Bartolo s.r.l.San Bartolo s.r.l. was fined by the Garante for processing employees’ biometric data without prior notification and without the required preliminary verification. The case concerns a breach of privacy rules governing special-category data. | IT | Garante | GDPR | €24,000 | ↗ |
| 15 Nov 2012 | Gruppo Ro.Ri. s.r.l.The Garante fined Gruppo Ro.Ri. s.r.l. 24,000 EUR for inadequate data protection measures linked to its video surveillance systems. The company also failed to provide proper information to data subjects as required by the privacy code. | IT | Garante | GDPR | €24,000 | ↗ |
| 06 Jun 2024 | Azienda Usl RomagnaThe Garante fined Azienda Usl Romagna EUR 24,000 for data protection violations related to the management of health data. The case concerned irregularities in the processing of sensitive data, which requires heightened safeguards and GDPR compliance. | IT | Garante | GDPR | €24,000 | ↗ |
| 20 Apr 2023 | Dane anonimowe (Rzecznika Dyscyplinarnego Izby Adwokackiej w X.)UODO imposed a fine of PLN 23,580 on an anonymous entity for failing to implement appropriate technical and organizational measures. The authority also found a lack of regular testing, measuring, and evaluation of the effectiveness of those measures in relation to processing data using external storage media. | PL | UODO | GDPR | €5,114 | ↗ |