BULLETIN №082Last updated · 31 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.4%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 17 Apr 2023 | WIZINK BANK, S.A.WIZINK BANK, S.A. was fined 5,000 EUR by the AEPD for sending commercial emails to a complainant who had opted out of receiving such communications. The authority found this conduct to be a breach of Article 21 of the LSSI. | ES | AEPD | ePrivacy | €5,000 | ↗ |
| 01 Jan 2022 | UNIQUEDESIGN & DECOR, S.L.UNIQUEDESIGN & DECOR, S.L. was fined by the AEPD 5,000 EUR for not having an accessible privacy policy on its website. The authority found a breach of Article 13 GDPR because users were not properly provided with the required information. | ES | AEPD | GDPR | €5,000 | ↗ |
| 14 Feb 2024 | ALL IN DIGITAL MARKETING SLALL IN DIGITAL MARKETING SL was fined by the AEPD €5,000 for continuing to send commercial emails despite repeated requests to unsubscribe. The authority found this conduct breached Article 21 of the LSSI. | ES | AEPD | ePrivacy | €5,000 | ↗ |
| 01 Jan 2016 | AUTOCLUB MUTUA MADRILEÑA S.L.AUTOCLUB MUTUA MADRILEÑA S.L. was fined by the AEPD 5,000 EUR for sending an unsolicited commercial SMS without prior consent. The authority also found that no opt-out mechanism was provided, in breach of Article 21 of the LSSI. | ES | AEPD | ePrivacy | €5,000 | ↗ |
| 03 May 2024 | D.D.D.The entity published images of a minor on its Telegram channel without consent, breaching data protection rules. AEPD imposed a fine of EUR 5,000. | ES | AEPD | GDPR | €5,000 | ↗ |
| 24 Jun 2023 | BANCO BILBAO VIZCAYA ARGENTARIA, S.A.BBVA was fined EUR 5,000 by the AEPD for repeatedly sending commercial emails to a client despite requests to unsubscribe. The authority found this breached Article 21 of the LSSI on unsolicited commercial communications. | ES | AEPD | ePrivacy | €5,000 | ↗ |
| 11 Jan 2023 | AXEL SPRINGER ESPAÑA S.AAXEL SPRINGER ESPAÑA S.A was fined 5,000 EUR by the AEPD for non-compliance with data protection rules in its cookie policy. The website required users to disable providers individually and did not offer an option to disable all cookies at once. | ES | AEPD | ePrivacy | €5,000 | ↗ |
| 20 Dec 2025 | KVIKU SPAIN, S.L.KVIKU SPAIN, S.L. was fined by the AEPD 5,000 EUR for processing personal data without a legal basis. The case concerned debt collection related to a loan that the complainant had neither consented to nor requested. | ES | AEPD | GDPR | €5,000 | ↗ |
| 15 Jan 2024 | AVOCAT (procédure simplifiée)The CNIL imposed an administrative fine of EUR 5,000 on AVOCAT (procédure simplifiée). The case concerned a confirmed regulatory breach, with no further details provided in the record. | FR | CNIL | GDPR | €5,000 | ↗ |
| 11 Mar 2021 | Plurima s.r.l.Plurima s.r.l. was fined EUR 5,000 by the Italian data protection authority, Garante. The sanction concerned unsolicited promotional calls made to individuals whose consent was not recorded in the consent database. This conduct breached GDPR requirements for marketing-related processing. | IT | Garante | GDPR | €5,000 | ↗ |
| 16 Jun 2025 | SC Kashto Concept SRLANSPDCP completed an investigation at SC Kashto Concept SRL and found a breach of the GDPR. The operator was fined 5,000 RON. | RO | ANSPDCP | GDPR | €995 | ↗ |
| 16 May 2019 | ANANEOSI MONOPROSOPI E.P.E.The company was fined for making unsolicited marketing calls to subscribers registered on the opt-out list. It also failed to properly identify itself during the calls, which hindered data subjects’ ability to exercise their rights. | GR | HDPA | ePrivacy | €5,000 | ↗ |
| 30 Jul 2013 | GLOBAL GREECE M.E.P.EThe company was fined for sending marketing emails without obtaining subscribers' consent. The authority found a breach of Article 11 of Law 3471/2006. | GR | HDPA | ePrivacy | €5,000 | ↗ |
| 27 Sept 2021 | Сиела Норма АДThe CPDP found that Сиела Норма АД violated the GDPR by inaccurately processing personal data. The error led to an individual being misidentified as a liquidator of companies, and a fine of 5,000 BGN was imposed. | BG | CPDP | GDPR | €2,557 | ↗ |
| 20 Jun 2024 | Max & Mix Ferrara s.r.l.Max & Mix Ferrara s.r.l. was fined €5,000 by the Garante for operating a video surveillance system with 32 cameras without the required informational signage. The authority found this to be a breach of GDPR information obligations. | IT | Garante | GDPR | €5,000 | ↗ |
| 01 Jan 2024 | ACTIVOS INTELIGENTES, S.L.ACTIVOS INTELIGENTES, S.L. was fined by the AEPD 5,000 EUR for requiring guests to submit selfies with their ID cards during check-in. The authority found the data collection excessive and not properly justified or explained in terms of processing purposes. | ES | AEPD | GDPR | €5,000 | ↗ |
| 01 Jan 2021 | JUBASER DE CONTROL, S.L.JUBASER DE CONTROL, S.L. was fined by the AEPD 5,000 EUR for unlawful processing of personal data. The case concerned improper handling of a customer's ID and personal information, which later appeared on an adult contact website. | ES | AEPD | GDPR | €5,000 | ↗ |
| 10 Jun 2024 | BOULANGERIE (procédure simplifiée)CNIL imposed an administrative fine of EUR 5,000 on BOULANGERIE under a simplified procedure. The record does not provide further details on the underlying infringement. | FR | CNIL | GDPR | €5,000 | ↗ |
| 16 Sept 2021 | Comune di Montalbano JonicoThe Garante fined Comune di Montalbano Jonico 5,000 EUR for breaching the data minimization principle. The municipality published excessive personal data on its website, including health-related information. | IT | Garante | GDPR | €5,000 | ↗ |
| 31 Dec 2024 | PARTICULIERS (procédure simplifiée)An administrative fine of EUR 5,000 was imposed by the CNIL. The case was handled under a simplified procedure. | FR | CNIL | GDPR | €5,000 | ↗ |