BULLETIN №082Last updated · 31 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.4%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 29 Jan 2020 | COLEGIO ARENALES CARABANCHELThe school was fined by the AEPD 5,000 EUR for unlawfully sharing and publishing images of children without consent. The case involved a breach of data protection rules and the need for valid consent to process minors’ images. | ES | AEPD | GDPR | €5,000 | ↗ |
| 27 Apr 2023 | B.B.B.The entity installed a surveillance camera without informing tenants or obtaining their consent. The camera captured shared areas, which constituted a breach of data protection rules. | ES | AEPD | GDPR | €5,000 | ↗ |
| 26 Mar 2026 | PSK AD Network S.r.l.PSK AD Network S.r.l. was fined EUR 5,000 by the Garante. The case concerned the failure to respond to a data subject’s deletion request and the failure to provide information requested by the authority, in breach of Article 157 of the Codice. | IT | Garante | GDPR | €5,000 | ↗ |
| 31 Mar 2022 | FUNDACIÓ ESCOLA PRIVADA DE GESTIÓThe entity was fined by the AEPD 5,000 EUR for failing to implement adequate security measures under Article 32 of the GDPR. This deficiency led to a personal data breach. | ES | AEPD | GDPR | €5,000 | ↗ |
| 16 Oct 2024 | D**** GmbHThe company appointed its managing director as the data protection officer, creating a conflict of interest. The DSB found this breached Article 38(6) GDPR and imposed a fine of EUR 5,000. | AT | DSB | GDPR | €5,000 | ↗ |
| 28 Nov 2021 | INCOPROSOL, S.L.INCOPROSOL, S.L. was fined EUR 5,000 by the AEPD for recording a customer's phone conversation without informing them. The authority treated this as a breach of data protection principles. | ES | AEPD | GDPR | €5,000 | ↗ |
| 03 Oct 2024 | ALL IN DIGITAL MARKETING SLALL IN DIGITAL MARKETING SL was fined EUR 5,000 by the AEPD for continuing to send marketing emails despite the recipient's unsubscribe requests. The authority found a breach of Article 21 of the LSSI. | ES | AEPD | ePrivacy | €5,000 | ↗ |
| 11 Dec 2025 | SOCIETE EXERCANT UNE ACTIVITE D'ARTS DU SPECTACLE VIVANT (procédure simplifiée)The CNIL imposed an administrative fine of EUR 5,000 on SOCIETE EXERCANT UNE ACTIVITE D'ARTS DU SPECTACLE VIVANT and issued an injunction. The case concerns a breach of regulatory obligations under the data protection authority's supervision. | FR | CNIL | GDPR | €5,000 | ↗ |
| 16 Sept 2021 | Istituto per Ciechi Ardizzone GioeniIstituto per Ciechi Ardizzone Gioeni was fined by the Garante EUR 5,000 for failing to provide adequate data protection information about the activation of a video surveillance system. The case involved vulnerable guests, including blind and visually impaired persons, who were not properly informed about the processing of their personal data. | IT | Garante | GDPR | €5,000 | ↗ |
| 20 Dec 2022 | HAYS PERSONNEL SERVICE ESPAÑA, S.A.HAYS PERSONNEL SERVICE ESPAÑA, S.A. was fined by the AEPD 5,000 EUR for sending marketing emails without the recipient’s consent. The conduct breached Article 21 of the LSSI, which requires prior consent for such communications. | ES | AEPD | ePrivacy | €5,000 | ↗ |
| 23 Jan 2023 | SOCIETE DE CONSEIL EN SYSTEMES ET LOGICIELS INFORMATIQUES (procédure simplifiée)CNIL imposed a EUR 5,000 fine on SOCIETE DE CONSEIL EN SYSTEMES ET LOGICIELS INFORMATIQUES under a simplified procedure. The authority also issued an injunction to remedy the identified non-compliance. | FR | CNIL | GDPR | €5,000 | ↗ |
| 25 Jan 2021 | PATIO ANCESTRAL, S.L.PATIO ANCESTRAL, S.L. was fined by the AEPD in the amount of EUR 5,000 for sending a letter containing personal data to the complainant's workplace. The authority found this to be a breach of data protection rules. | ES | AEPD | GDPR | €5,000 | ↗ |
| 09 Nov 2021 | Cyrana España General S.L.Cyrana España General S.L. was fined by the AEPD in the amount of 5,000 EUR for processing personal data without consent. The conduct resulted in unauthorized charges to a customer's bank account. | ES | AEPD | GDPR | €5,000 | ↗ |
| 29 Apr 2022 | Fire Brigade HeadquartersFire Brigade Headquarters was fined EUR 5,000 by the HDPA. The authority found a failure to fulfill data protection officer duties required under national law. | GR | HDPA | GDPR | €5,000 | ↗ |
| 29 Apr 2026 | dottoressa GuzzoThe Garante imposed a fine of EUR 5,000 on dottoressa Guzzo for unlawfully processing personal data by publishing images of a deceased minor without consent. The authority found that this breached core data protection principles. | IT | Garante | GDPR | €5,000 | ↗ |
| 18 Jul 2023 | Ermeslink di Giovanni Di StefanoThe Garante imposed a fine of EUR 5,000 on Ermeslink di Giovanni Di Stefano for improperly handling video surveillance data. The breach concerned data protection rules and could have affected all residents and non-residents of the Municipality of Modica. | IT | Garante | GDPR | €5,000 | ↗ |
| 14 Nov 2024 | D’Anna Assicurazioni S.r.l.D’Anna Assicurazioni S.r.l. was fined by the Garante 5,000 EUR for sending unsolicited promotional emails despite the recipient’s objection. The authority found this breached GDPR rules on data subject rights and transparency. | IT | Garante | GDPR | €5,000 | ↗ |
| 01 Jan 2014 | TELEFÓNICA MÓVILES ESPAÑA S.A.U.TELEFÓNICA MÓVILES ESPAÑA S.A.U. was fined by the AEPD in the amount of 5,000 EUR. The case concerned unsolicited commercial communications sent via SMS in breach of Article 21 of the LSSI. | ES | AEPD | ePrivacy | €5,000 | ↗ |
| 16 Sept 2021 | Consorzio di Bonifica dell’OristaneseConsorzio di Bonifica dell’Oristanese was fined EUR 5,000 by the Garante for publishing a disciplinary measure on its website that included an employee’s health information. The authority found breaches of lawfulness, fairness, transparency, and data minimization principles. | IT | Garante | GDPR | €5,000 | ↗ |
| 31 Dec 2024 | SOCIETE GERANT UN ROBOT CONVERSATIONNEL UTILISANT L'INTELLIGENCE ARTIFICELLE (procédure simplifiée)The CNIL imposed an administrative fine of 5,000 EUR on the company operating an AI-based conversational robot. The case was handled under a simplified procedure. | FR | CNIL | GDPR | €5,000 | ↗ |