BULLETIN №082Last updated · 30 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.2%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 10 Apr 2025 | Ente di Patrocinio ed Assistenza per i Cittadini e l’Agricoltura (EPACA)EPACA was fined EUR 5,000 by the Italian Garante. The authority found that the organization retained personal data beyond the legally permitted period and accessed the INPS database without a valid mandate. | IT | Garante | GDPR | €5,000 | ↗ |
| 03 Jul 2025 | WALLAPOP, S.L.WALLAPOP, S.L. was fined by the AEPD in the amount of 5,000 EUR for using cookies without properly informing users or obtaining their consent. The authority found this conduct to be in breach of the LSSI. | ES | AEPD | ePrivacy | €5,000 | ↗ |
| 11 Jan 2024 | Euro Servizi per i Notai S.r.l.Euro Servizi per i Notai S.r.l. was fined 5,000 EUR by the Garante for processing personal data without a valid legal basis and without adequate transparency. The violations concerned reporting services provided to banks through the PIGNA portal. | IT | Garante | GDPR | €5,000 | ↗ |
| 22 Jun 2023 | More News società cooperativa a r.l.The Garante fined More News società cooperativa a r.l. 5,000 EUR for publishing a minor’s personal data without proper anonymization. The disclosure allowed acquaintances to identify the child and caused embarrassment. | IT | Garante | GDPR | €5,000 | ↗ |
| 28 Sept 2023 | Ministero dell'Ambiente e della Sicurezza EnergeticaThe Ministry of Environment and Energy Security was fined EUR 5,000 by the Garante for the online publication of personal data relating to numerous workers. The disclosure also included health-related data for some individuals. | IT | Garante | GDPR | €5,000 | ↗ |
| 02 Jul 2020 | Istituto Nazionale della Previdenza Sociale-Direzione Provinciale di BresciaThe Italian Data Protection Authority fined the INPS Brescia Provincial Directorate for failing to respond to a request for access to personal health data. The authority found a breach of data protection rules. | IT | Garante | GDPR | €5,000 | ↗ |
| 04 Dec 2019 | VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD in the amount of 5,000 EUR for failing to provide the requested information. The case concerned a breach of obligations under data protection rules. | ES | AEPD | GDPR | €5,000 | ↗ |
| 08 May 2024 | CENTRUL MEDICAL UNIREA SRLCENTRUL MEDICAL UNIREA SRL was fined EUR 5,000 by ANSPDCP for unauthorized disclosure of personal data on the internet. The case indicates a breach of data protection rules and warrants review of security controls and publication procedures. | RO | ANSPDCP | GDPR | €5,000 | ↗ |
| 21 Feb 2026 | VERTI ASEGURADORA, COMPAÑÍA DE SEGUROS Y REASEGUROS, S.A.VERTI Aseguradora was fined by the AEPD €5,000 for sending promotional emails without providing a simple and free way for recipients to opt out. The authority found this to be a breach of Article 21.2 of the LSSI. | ES | AEPD | ePrivacy | €5,000 | ↗ |
| 01 Jan 2014 | CAIXABANK, S.A.CAIXABANK, S.A. was fined by the AEPD 5,000 EUR for sending unauthorized commercial emails. The conduct occurred after the complainant had exercised the right to object to the use of their data for advertising purposes. | ES | AEPD | ePrivacy | €5,000 | ↗ |
| 17 Jul 2015 | VUELING AIRLINES, S.A.VUELING AIRLINES, S.A. was fined by the AEPD 5,000 EUR for sending unsolicited commercial emails to a user who had previously unsubscribed. The authority found this breached article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €5,000 | ↗ |
| 23 Aug 2023 | GAFAS EN RED DE ÓPTICAS, S.L.GAFAS EN RED DE ÓPTICAS, S.L. was fined by the AEPD 5,000 EUR for sending commercial emails to a complainant after they had opted out. The authority treated this as a breach of data protection rules. | ES | AEPD | ePrivacy | €5,000 | ↗ |
| 14 Jul 2017 | BARCLAYS BANK PLC Sucursal en EspañaBARCLAYS BANK PLC Sucursal en España was fined by the AEPD 5,000 EUR for sending commercial emails without meeting the requirements of Article 21 of the LSSI. The breach occurred despite the recipient's request to cancel their personal data. | ES | AEPD | ePrivacy | €5,000 | ↗ |
| 22 Mar 2023 | GRUPO MASSIMO DUTTI, S.A.The AEPD fined GRUPO MASSIMO DUTTI, S.A. EUR 5,000 for failing to provide sufficient information and adequate options regarding cookie consent on its website. The authority found a breach of Article 22.2 of the LSSI. | ES | AEPD | ePrivacy | €5,000 | ↗ |
| 11 Jan 2023 | Associazione Nazionale MagistratiAssociazione Nazionale Magistrati was fined by the Garante for improper handling of personal data. An official email address was used instead of a personal one to notify a disciplinary proceeding, which breached confidentiality requirements. | IT | Garante | GDPR | €5,000 | ↗ |
| 23 Jan 2025 | Softtehnica S.R.LIn December 2024, ANSPDCP completed an investigation at Softtehnica S.R.L. The authority found a GDPR violation and imposed a fine of EUR 5,000. | RO | ANSPDCP | GDPR | €5,000 | ↗ |
| 01 Jan 2017 | WEWI MOBILE, S.L.WEWI MOBILE, S.L. was fined by the AEPD in the amount of €5,000 for sending unsolicited commercial messages to individuals without their prior consent. This conduct breached the LSSI rules on marketing communications. | ES | AEPD | ePrivacy | €5,000 | ↗ |
| 18 May 2022 | SERVICIOS INTEGRALES DEL HOGAR TENERIFE, S.L.The company was fined by the AEPD for unlawfully processing personal data. The breach involved sending a wage garnishment notice via WhatsApp without proper authorization or legal basis. | ES | AEPD | GDPR | €5,000 | ↗ |
| 21 Aug 2018 | Eurobank Ergasias A.E.Eurobank Ergasias A.E. was fined by the HDPA in the amount of 5,000 EUR for failing to maintain and process accurate data of its debtors. The authority found that the company’s handling of debtor information breached data protection requirements. | GR | HDPA | GDPR | €5,000 | ↗ |
| 21 Sept 2022 | Curtea Veche Publishing SRLCurtea Veche Publishing SRL was fined EUR 5,000 by ANSPDCP for violating GDPR provisions. The case concerned non-compliance with personal data protection requirements. | RO | ANSPDCP | GDPR | €5,000 | ↗ |