BULLETIN №082Last updated · 31 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.4%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 16 Nov 2022 | Raiffeisen Bank SARaiffeisen Bank SA was fined EUR 5,000 by ANSPDCP for GDPR violations related to data security incidents. The case concerned shortcomings in the protection of personal data and required remedial action by the bank. | RO | ANSPDCP | GDPR | €5,000 | ↗ |
| 22 Jun 2023 | Maviglia Assicurazioni snc di Gherardo Maviglia & c.Maviglia Assicurazioni was fined 5,000 EUR by the Garante for failing to deactivate former employees' email accounts. This allowed unauthorized access to data and breached data protection rules. | IT | Garante | GDPR | €5,000 | ↗ |
| 11 May 2026 | Geanonimiseerd (APD 100/2026)The Litigation Chamber imposed a fine for violations related to camera surveillance at a residential complex. It found a lack of transparency and a failure to properly facilitate data subject rights. | BE | APD | GDPR | €5,000 | ↗ |
| 11 Feb 2021 | Comando generale del Corpo delle Capitanerie di porto-Guardia CostieraThe Garante imposed a €5,000 fine on the Comando generale del Corpo delle Capitanerie di porto-Guardia Costiera for inadequate data protection measures. The breach resulted in the unlawful disclosure of personal data on its website. | IT | Garante | GDPR | €5,000 | ↗ |
| 18 Dec 2023 | MOTORSPORT NETWORK ESPAÑA, S.L.MOTORSPORT NETWORK ESPAÑA, S.L. was fined by the AEPD 5,000 EUR for using an illegal cookie consent mechanism on its website. Users were required to accept cookies to access free content or subscribe in order to avoid them. | ES | AEPD | ePrivacy | €5,000 | ↗ |
| 23 May 2024 | Radio Marte S.r.l.Radio Marte S.r.l. was fined EUR 5,000 by the Garante for unlawfully disseminating identifying data of a minor during a radio program. The authority found a breach of privacy and personal data protection rules. | IT | Garante | GDPR | €5,000 | ↗ |
| 15 Dec 2022 | Azienda Sanitaria provinciale di CataniaAzienda Sanitaria provinciale di Catania was fined 5,000 EUR by the Garante for unlawfully publishing personal data on its website concerning an employee's disciplinary and criminal proceedings. The authority found breaches of lawfulness, fairness, transparency, and data minimization principles. | IT | Garante | GDPR | €5,000 | ↗ |
| 01 Jan 2019 | CENTRO DE ESTUDIOS DIRIGIDOS DELTA, S.L.The entity sent a document via WhatsApp containing personal data of three individuals without their consent. This constituted a breach of data protection rules and led to a fine imposed by the AEPD. | ES | AEPD | GDPR | €5,000 | ↗ |
| 15 Dec 2022 | Societatea Energetică Electrica S.A.In November 2022, ANSPDCP completed an investigation at Societatea Energetică Electrica S.A. and found a GDPR violation. The operator was fined 5,000 EUR and advised to take all necessary measures to comply with the rules. | RO | ANSPDCP | GDPR | €5,000 | ↗ |
| 05 Aug 2021 | HUBSIDE IBÉRICA S.L.HUBSIDE IBÉRICA S.L. was fined by the AEPD for charging a customer for services that were not contracted. Personal and bank account data were collected during a purchase, and the penalty was reduced due to early payment. | ES | AEPD | GDPR | €5,000 | ↗ |
| 10 Apr 2025 | Aliseo s.r.l.Aliseo s.r.l. was fined by the Garante for operating a video surveillance system without proper notice and for monitoring employees, including audio recording. The authority found the monitoring disproportionate to the stated security purpose. | IT | Garante | GDPR | €5,000 | ↗ |
| 16 May 2023 | Compania Națională Poșta Română S.A.Compania Națională Poșta Română S.A. was fined EUR 5,000 by ANSPDCP for GDPR violations related to the completion of Form 230. The case arose from complaints, and the authority instructed the company to ensure personal data processing complies with processing principles. | RO | ANSPDCP | GDPR | €5,000 | ↗ |
| 09 Oct 2025 | AD Media S.r.l.AD Media S.r.l. was fined EUR 5,000 by the Garante for sending promotional emails without proper consent. The authority found a breach of the principles of lawfulness, fairness, and transparency in data processing. | IT | Garante | GDPR | €5,000 | ↗ |
| 06 Dec 2019 | VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined 5,000 EUR by the AEPD for failing to provide requested information. The case concerns a breach of obligations under data protection rules. | ES | AEPD | GDPR | €5,000 | ↗ |
| 19 Dec 2024 | ACCES AUX SOINS (procédure simplifiée)The CNIL imposed an administrative fine of EUR 5,000 on ACCES AUX SOINS under a simplified procedure. The case concerns a breach of rules supervised by the CNIL. | FR | CNIL | GDPR | €5,000 | ↗ |
| 11 Jan 2017 | WIZINK BANK, S.A.WIZINK BANK, S.A. was fined by the AEPD EUR 5,000 for sending unsolicited commercial emails despite a request to unsubscribe. The authority found a breach of Article 21 of the LSSI. | ES | AEPD | ePrivacy | €5,000 | ↗ |
| 11 Dec 2025 | UPGYMS IBERIA, S.L.UPGYMS IBERIA, S.L. was fined by the AEPD EUR 5,000 for sending unsolicited commercial SMS messages without obtaining recipient consent. The conduct breached the LSSI rules on marketing communications. | ES | AEPD | ePrivacy | €5,000 | ↗ |
| 26 Jan 2022 | ESTUDIO INMOBILIARIO SAN ISIDRO, S.L.UESTUDIO INMOBILIARIO SAN ISIDRO, S.L.U was fined by the AEPD EUR 5,000 for unlawfully obtaining personal data and visiting the complainant's home to promote real estate services without proper consent. The case concerns unlawful processing and improper direct marketing contact. | ES | AEPD | GDPR | €5,000 | ↗ |
| 25 May 2025 | ENTIDAD DE CONSERVACION TORREMIRONAThe entity was fined by the AEPD for operating a video surveillance system that excessively covered public areas. This infringed the privacy of residents and passersby. | ES | AEPD | GDPR | €5,000 | ↗ |
| 01 Jul 2021 | UNIVERSIDAD A DISTANCIA DE MADRID, S.A.UNIVERSIDAD A DISTANCIA DE MADRID, S.A. was fined by the AEPD for failing to comply with a request to delete personal data. As a result, the individual received unsolicited marketing emails, indicating a breach of data protection obligations. | ES | AEPD | GDPR | €5,000 | ↗ |