BULLETIN №081Last updated · 26 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -20.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 12 Feb 2026 | Klab s.r.l.Klab s.r.l. was fined by the Garante in the amount of 1,000 EUR for failing to obtain valid consent for marketing purposes. The authority also found that the company did not provide adequate information about the legal basis for data processing, in breach of GDPR requirements. | IT | Garante | GDPR | €1,000 | ↗ |
| 12 Feb 2026 | Provvedimento del 12 febbraio 2026 [10226120]The Garante imposed a fine of EUR 1,500 for unlawful processing of personal data through a video surveillance system at a commercial establishment. The cameras captured public streets and private residences, and the data subjects were not properly notified. | IT | Garante | GDPR | €1,500 | ↗ |
| 12 Feb 2026 | Lex Iuris S.r.l.Lex Iuris S.r.l. was fined by the Garante in the amount of 15,000 EUR for sending unsolicited promotional emails. The authority also found that the company failed to respond to data access requests, breaching transparency and data subject rights obligations. | IT | Garante | GDPR | €15,000 | ↗ |
| 12 Feb 2026 | Velletri ServiziVelletri Servizi was fined EUR 2,500 by the Garante for inadequate technical and organizational measures in data processing. The authority found that the company did not meet the requirements of GDPR Article 32. | IT | Garante | GDPR | €2,500 | ↗ |
| 12 Feb 2026 | Ordine dei Medici Chirurghi e degli Odontoiatri della Provincia di MacerataOrdine dei Medici Chirurghi e degli Odontoiatri della Provincia di Macerata was fined EUR 4,000 by the Garante. The authority found breaches of the principles of lawfulness, fairness, transparency, and data minimization. The case indicates non-compliance with core GDPR processing requirements. | IT | Garante | GDPR | €4,000 | ↗ |
| 12 Feb 2026 | Based s.r.l.Based s.r.l. was fined by the Garante EUR 12,000 for providing an inadequate response to a data subject’s request for access to and deletion of email account data. The authority found that the company failed to comply with GDPR requirements on data subject rights. | IT | Garante | GDPR | €12,000 | ↗ |
| 12 Feb 2026 | Bressanelli Galli Gelpi Porta & C. S.r.l.The company was fined EUR 15,000 by the Garante for sending promotional emails without prior consent from recipients. The authority found this to be a breach of GDPR principles, including Article 5. | IT | Garante | GDPR | €15,000 | ↗ |
| 12 Feb 2026 | Anconambiente S.P.A.Anconambiente S.P.A. was fined by the Garante for failing to ensure that personal data processing was lawful, fair, and transparent. The authority also found that the company did not have a proper contract with a data processor, as required by Article 28 GDPR. | IT | Garante | GDPR | €2,500 | ↗ |
| 10 Feb 2026 | Dane anonimowe (R.)The UODO imposed a PLN 6,700 fine on Anonymous data (R.) for failing to notify a personal data breach within 72 hours and for not informing affected individuals without undue delay. The authority also found deficiencies in the appointment of the data protection officer, including missing contact details, failure to notify the supervisory authority, and a conflict of interest because the role was assigned to a board member. | PL | UODO | GDPR | €1,589 | ↗ |
| 05 Feb 2026 | Óbudai EgyetemÓbudai Egyetem was fined by the NAIH 1,500,000 HUF for breaching the principles of transparency and data minimization. The authority also found no lawful basis for processing and that the conditions for processing special categories of data were not met. | HU | NAIH | GDPR | €3,945 | ↗ |
| 05 Feb 2026 | Tensa Art Design S.AThe National Supervisory Authority for Personal Data Processing completed an investigation in January 2026 at Tensa Art Design S.A. It found violations of GDPR provisions and imposed a fine of EUR 20,000. | RO | ANSPDCP | GDPR | €20,000 | ↗ |
| 05 Feb 2026 | Dane anonimowe (pana H. G., prowadzącego działalność gospodarczą pod firmą H.)The President of the Polish DPA (UODO) imposed a fine of PLN 16,804 on an anonymous sole proprietor. The sanction resulted from failure to cooperate with the authority and from not providing access to personal data and information necessary for the performance of its duties. | PL | UODO | GDPR | €3,982 | ↗ |
| 05 Feb 2026 | AVOCAT (procédure simplifiée)The CNIL imposed a fine of EUR 1,000 on AVOCAT (procédure simplifiée) in connection with the liquidation of astreinte. The case concerns enforcement of a prior obligation and the amount due for failure to comply on time. | FR | CNIL | GDPR | €1,000 | ↗ |
| 05 Feb 2026 | Dane anonimowe (X.)UODO imposed an administrative fine of PLN 6,251,471 on Dane anonimowe (X.) for breaching Article 28(3) GDPR. The company used external transport providers without prior data processing agreements and without implementing adequate organizational measures to ensure data security. | PL | UODO | GDPR | €1,481,000 | ↗ |
| 05 Feb 2026 | Gemeente DelftGemeente Delft processed personal data without a sufficient legal basis. It also processed special categories of personal data without a valid exception, breaching GDPR principles. | NL | AP | GDPR | €25,000 | ↗ |
| 05 Feb 2026 | MÉDECIN (procédure simplifiée)The CNIL imposed EUR 1,000 on MÉDECIN (simplified procedure) as a liquidation of an astreinte. The case concerns compliance with a prior obligation set by the supervisory authority. | FR | CNIL | GDPR | €1,000 | ↗ |
| 05 Feb 2026 | Gemeente HilversumThe Autoriteit Persoonsgegevens found that Gemeente Hilversum processed personal data without a valid legal basis during an investigation into Muslim residents and organizations. The municipality accepted an administrative fine of 25,000 EUR and acknowledged responsibility. | NL | Autoriteit Persoonsgegevens | GDPR | €25,000 | ↗ |
| 04 Feb 2026 | GENPACT ROMANIA SRLThe National Supervisory Authority for Personal Data Processing completed an investigation into GENPACT ROMANIA SRL and found a GDPR violation. The company was fined EUR 10,000 due to the severity of the circumstances. | RO | ANSPDCP | GDPR | €10,000 | ↗ |
| 04 Feb 2026 | E-RETAIL ADVERTISING, S.L.E-RETAIL ADVERTISING, S.L. was fined by the AEPD in the amount of 5,000 EUR for installing non-exempt cookies on its website without prior user consent. The case concerns non-compliance with cookie consent requirements and user privacy obligations. | ES | AEPD | ePrivacy | €5,000 | ↗ |
| 04 Feb 2026 | MediaLab.AI, Inc.The ICO imposed a 247,590 GBP penalty on MediaLab.AI, Inc. for breaches of Articles 5(1)(a), 6, 8 and 35 UK GDPR. The company operated Imgur in the UK and allowed children under 13 to access the platform without a reliable way to verify age or obtain the required parental consent. It also failed to carry out a DPIA before high-risk processing involving children under 18. | GB | ICO | GDPR | €287,000 | ↗ |