BULLETIN №082Last updated · 02 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 14 Apr 2025 | niegoAn administrative fine of 25,255 PLN was imposed for failure to comply with an order contained in an administrative decision of the President of UODO. The case concerns non-fulfilment of an obligation imposed by the supervisory authority. | PL | UODO | GDPR | €5,893 | ↗ |
| 18 Aug 2022 | niegoThe Polish DPA (UODO) imposed an administrative fine of PLN 4,569 on an individual. The authority found a failure to cooperate with the President of UODO and a failure to provide access to information necessary for the performance of its duties. | PL | UODO | GDPR | €967 | ↗ |
| 31 Aug 2022 | niegoThe President of UODO imposed a fine of PLN 6,854 on an individual for processing the complainant’s image through video surveillance. The breach consisted of failing to cooperate with the authority and not providing information necessary for it to perform its duties. | PL | UODO | GDPR | €1,450 | ↗ |
| 17 Mar 2016 | Nico MannelliNico Mannelli was fined by the Garante EUR 2,400 for inadequate video surveillance signage and for failing to inform individuals about the purpose of processing and the data controller. The authority found a breach of Article 13 of the Italian Privacy Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 18 Jul 2023 | Nicola PetrolitoThe Garante imposed a EUR 400 fine on Nicola Petrolito for operating a video surveillance system that captured areas owned by third parties and public passageways. The authority found that the required informational signage was missing, constituting a GDPR breach. | IT | Garante | GDPR | €400 | ↗ |
| 01 Jun 2023 | NH Italia S.p.A.NH Italia S.p.A. was fined EUR 200,000 by the Garante for failing to appoint specific data processors responsible for the installation and maintenance of video surveillance systems. The authority found this breached the GDPR principles of lawful, fair, and transparent processing of personal data. | IT | Garante | GDPR | €200,000 | ↗ |
| 22 Mar 2024 | NH HOTEL GROUP S.A.NH HOTEL GROUP S.A. was fined by the AEPD EUR 10,000 for using cookies on its website without obtaining user consent. The authority found this to be a breach of the LSSI rules on cookie consent. | ES | AEPD | ePrivacy | €10,000 | ↗ |
| 13 Jul 2012 | NH HOTELES, S.A.NH HOTELES, S.A. was fined by the AEPD for sending unsolicited commercial emails to a complainant after confirming the cancellation of their personal data. The authority found a breach of Article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €33,001 | ↗ |
| 04 Oct 2011 | NGI s.p.a.NGI s.p.a. was fined by the Garante 50,000 EUR for breaches of data protection rules. The authority found that the company failed to designate data processing officers, did not prepare the required security program document, and improperly retained traffic data. | IT | Garante | GDPR | €50,000 | ↗ |
| 07 Dec 2023 | N*** Gastronomie GmbHN*** Gastronomie GmbH was fined by the DSB EUR 20,000 for unlawfully processing personal data through video surveillance without a legal basis. The authority also found that the company failed to maintain a record of processing activities required under the GDPR. | AT | DSB | GDPR | €20,000 | ↗ |
| 04 Jan 2024 | N*** -FußballvereinigungThe football association failed to implement appropriate technical and organizational measures for handling data deletion requests. The authority found breaches of Articles 25 and 17 GDPR and imposed a fine of EUR 11,000. | AT | DSB | GDPR | €11,000 | ↗ |
| 05 Feb 2021 | NEXTSTEPAGENCY, S.L.NEXTSTEPAGENCY, S.L. was fined by the AEPD in the amount of 1,000 EUR for failing to provide reliable ownership information and details about data transfers to China on its website. The authority found a breach of the information obligations under Article 13 GDPR. | ES | AEPD | GDPR | €1,000 | ↗ |
| 24 Jun 2021 | NEXTGEN FINANCIAL SERVICES S.L.NEXTGEN FINANCIAL SERVICES S.L. failed to update the address in a loan contract and did not correct inaccurate data in a credit file. The AEPD found this to be a breach of the right to data rectification and imposed a fine of 50,000 EUR. | ES | AEPD | GDPR | €50,000 | ↗ |
| 22 Dec 2025 | NEXPUBLICA FRANCECNIL imposed a fine of 1,700,000 EUR on NEXPUBLICA FRANCE on 2025-12-22. The decision concerns serious security failures under Article 32 GDPR in the PCRM software used by public social action bodies, which processed sensitive personal data. | FR | CNIL | GDPR | €1,700,000 | ↗ |
| 29 Jun 2020 | NEW YORK COLLEGE A.ENEW YORK COLLEGE A.E was fined EUR 5,000 by the HDPA for conducting targeted phone calls without providing the required GDPR information. The authority found breaches of data processing principles and accountability obligations. | GR | HDPA | GDPR | €5,000 | ↗ |
| 30 Jun 2011 | New Stereo In srlNew Stereo In srl was fined by the Garante 15,000 EUR for unlawful processing of personal data. The case concerned the activation of two unsolicited phone cards, in breach of Article 157 of the Italian Data Protection Code. | IT | Garante | GDPR | €15,000 | ↗ |
| 11 Apr 2025 | NEW GAMBLING SOLUTIONS S.R.L.In March 2025, ANSPDCP completed an investigation into NEW GAMBLING SOLUTIONS S.R.L. and found a GDPR violation. The company was fined EUR 2,000. | RO | ANSPDCP | GDPR | €2,000 | ↗ |
| 27 Jun 2013 | New Company di Scattolin LorisNew Company di Scattolin Loris was fined EUR 6,400 by the Garante for making unsolicited promotional phone calls without proper consent. The conduct breached Articles 13 and 130 of the Italian Data Protection Code. | IT | Garante | GDPR | €6,400 | ↗ |
| 14 May 2010 | NEW CENTER SYSTEM, S.L.NEW CENTER SYSTEM, S.L. was fined by the AEPD 1,200 EUR for sending an unsolicited commercial email. The authority found that recipients were not given a simple and free way to object to the use of their data for advertising, in breach of Article 21 of the LSSI. | ES | AEPD | ePrivacy | €1,200 | ↗ |
| 16 Nov 2023 | NEW BUY GOLD DI EMANUELE VITA & C. S.A.S.The company was fined EUR 1,000 by the Italian supervisory authority, Garante. The penalty was imposed because it operated a video surveillance system without the required information notice for data subjects, in breach of Article 13 GDPR. | IT | Garante | GDPR | €1,000 | ↗ |