BULLETIN №082Last updated · 01 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.1%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 15 Mar 2022 | PRODESSPA DECORATIUS I PINTURES, S.L.PRODESSPA DECORATIUS I PINTURES, S.L. was fined by the AEPD 15,000 EUR for unlawfully processing personal data. The company included a former employee’s data in a credit information system without proper legal justification. | ES | AEPD | GDPR | €15,000 | ↗ |
| 14 Sept 2023 | društvo XThe company processed excessive personal data, including CVC/CVV numbers and copies of identity documents, without a legal basis during hotel booking. It also failed to provide transparent information to data subjects, which constitutes a GDPR breach. | HR | AZOP | GDPR | €15,000 | ↗ |
| 28 Feb 2025 | DYNAMIC EXPRESS COURIER S.LDYNAMIC EXPRESS COURIER S.L was fined 15,000 EUR by the AEPD for subcontracting without prior authorization and for failing to put proper contracts in place with subcontractors. The authority found this conduct breached GDPR Article 28 on processor arrangements. | ES | AEPD | GDPR | €15,000 | ↗ |
| 02 Jul 2020 | Mapei S.p.A.Mapei S.p.A. was fined EUR 15,000 by the Italian authority Garante. The case concerned the failure to respond to a request for access to email communications and the failure to delete an email account after employment ended, in breach of GDPR principles. | IT | Garante | GDPR | €15,000 | ↗ |
| 29 May 2020 | Dane anonimowe (R. Sp. z o.o. z siedzibą w D. przy ul.)UODO imposed a fine of PLN 15,000 on R. Sp. z o.o. The sanction concerned the failure to provide information required by the authority. | PL | UODO | GDPR | €3,371 | ↗ |
| 29 Dec 2022 | SOCIETE DEVELOPPANT DES LOGICIELS DE GESTION ET LA COMMERCIALISATION DE LOGICIELS A DESTINATION DES COLLECTIVITES TERRITORIALES (procédure simplifiée)The CNIL imposed a fine of EUR 15,000 on SOCIETE DEVELOPPANT DES LOGICIELS DE GESTION ET LA COMMERCIALISATION DE LOGICIELS A DESTINATION DES COLLECTIVITES TERRITORIALES under a simplified procedure. The decision concerns a confirmed breach of rules supervised by the CNIL. | FR | CNIL | GDPR | €15,000 | ↗ |
| 01 Jul 2024 | Anonymised (IDPC 4794_001)The case concerns a breach of GDPR Articles 21(2) and 5(2) by Anonymised (IDPC 4794_001). The IDPC imposed an administrative fine of EUR 15,000. | MT | IDPC | GDPR | €15,000 | ↗ |
| 23 Aug 2021 | AD735 DATA MEDIA ADVERTISING S.L.AD735 DATA MEDIA ADVERTISING S.L. was fined EUR 15,000 by the AEPD for failing to comply with a resolution concerning the right of access. The authority cited a breach of Article 83(6) GDPR. | ES | AEPD | GDPR | €15,000 | ↗ |
| 11 Mar 2021 | Mediacom s.r.l.Mediacom s.r.l. was fined by the Garante for making unsolicited promotional calls without proper consent. The authority found that this conduct breached GDPR rules on the processing of personal data for marketing purposes. | IT | Garante | GDPR | €15,000 | ↗ |
| 09 Jan 2025 | SOCIETE REALISANT DES TRAVAUX D'ISOLATION, DE RENOVATION ENERGETIQUE ET DE CHAUFFAGE (procédure simplifiée)The CNIL imposed an administrative fine of 15,000 EUR on SOCIETE REALISANT DES TRAVAUX D'ISOLATION, DE RENOVATION ENERGETIQUE ET DE CHAUFFAGE and issued an injunction. The case was handled under simplified proceedings. | FR | CNIL | GDPR | €15,000 | ↗ |
| 13 Dec 2012 | Azienda sanitaria regionale MoliseThe Regional Health Company of Molise was fined for failing to designate data processing officers for each employee. The authority also found that minimum security measures for electronic processing were not implemented, including weak password policies and insufficient protection against unauthorized external access. | IT | Garante | GDPR | €15,000 | ↗ |
| 26 Feb 2026 | Ministero delle Imprese e del Made in ItalyMinistero delle Imprese e del Made in Italy was fined by the Garante €15,000 for unlawfully publishing personal data in a ranking list. The authority found breaches of data minimization and transparency principles. | IT | Garante | GDPR | €15,000 | ↗ |
| 30 Jun 2020 | VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD 15,000 EUR for incorrectly listing a customer's ex-spouse as the account holder, even though the customer's data appeared on invoices. The company acknowledged responsibility and paid the reduced fine. | ES | AEPD | GDPR | €15,000 | ↗ |
| 23 May 2024 | SOCIETE GERANT UNE PLATEFORME D'APPELS POUR LE SECRETARIAT DE PROFESSIONNELS (procédure simplifiée)The CNIL imposed an administrative fine of EUR 15,000 on SOCIETE GERANT UNE PLATEFORME D'APPELS POUR LE SECRETARIAT DE PROFESSIONNELS. The decision was issued under a simplified procedure and concerns a breach of data protection rules. | FR | CNIL | GDPR | €15,000 | ↗ |
| 24 Jan 2024 | CAJA RURAL DE ONDA, S.C.C.CAJA RURAL DE ONDA, S.C.C. was fined by the AEPD 15,000 EUR for violating data protection principles, including confidentiality and integrity. The breach resulted in unauthorized access to personal data. | ES | AEPD | GDPR | €15,000 | ↗ |
| 07 Feb 2022 | JIMBO NETWORKS, S.L.JIMBO NETWORKS, S.L. was fined by the AEPD for unlawful processing of personal data obtained from emails and for cookie policy violations on its website. The authority found that users were not properly informed and that valid consent was not obtained where required. | ES | AEPD | GDPR | €15,000 | ↗ |
| 03 Mar 2023 | SOCIETE EXERCANT UNE ACTIVITE DE SECURITE PRIVEE (procédure simplifiée)The CNIL imposed a EUR 15,000 fine on SOCIETE EXERCANT UNE ACTIVITE DE SECURITE PRIVEE under a simplified procedure. The case concerns a breach of personal data protection rules. | FR | CNIL | GDPR | €15,000 | ↗ |
| 25 Sept 2025 | Vimar S.p.A.Vimar S.p.A. was fined EUR 15,000 by the Garante for failing to provide adequate information to a complainant and for improper account handling. The account was accessible to unauthorized individuals, indicating weaknesses in access control and safeguards. | IT | Garante | GDPR | €15,000 | ↗ |
| 23 Oct 2025 | Ordine degli Avvocati di LatinaOrdine degli Avvocati di Latina was fined EUR 15,000 by the Garante for unlawful, incorrect, and non-transparent processing of personal data. The authority also found a failure to ensure data minimization. | IT | Garante | GDPR | €15,000 | ↗ |
| 06 Oct 2022 | Servizio Idrico Integrato S.c.p.a.Servizio Idrico Integrato S.c.p.a. was fined by the Garante EUR 15,000 for failing to implement adequate security measures to protect the personal data of users registered on its website. The case concerned insufficient safeguards for data processed online. | IT | Garante | GDPR | €15,000 | ↗ |