BULLETIN №082Last updated · 31 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.4%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 19 May 2025 | Maravet S.R.L.The National Supervisory Authority for Personal Data Processing completed an investigation at Maravet S.R.L. and found a violation of GDPR provisions. The operator was fined EUR 5,000. | RO | ANSPDCP | GDPR | €5,000 | ↗ |
| 26 May 2022 | Azienda sanitaria universitaria Friuli OccidentaleAzienda sanitaria universitaria Friuli Occidentale was fined EUR 5,000 by the Garante for violations related to the processing of personal data in the electronic health dossier. The authority found non-compliance with GDPR requirements. | IT | Garante | GDPR | €5,000 | ↗ |
| 12 Mar 2026 | SOCIÉTÉ EXERÇANT UNE ACTIVITÉ DE VENTE À DISTANCE SUR CATALOGUE SPECIALISÉE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 5,000 on Société exerçant une activité de vente à distance sur catalogue spécialisée. The case was handled under a simplified procedure. | FR | CNIL | GDPR | €5,000 | ↗ |
| 19 Dec 2023 | HIPERBAZAR YONGFA 2018 SLHIPERBAZAR YONGFA 2018 SL was fined by the AEPD 5,000 EUR for breaching data protection rules. The case involved the improper sharing of surveillance footage, which was later posted on Facebook, undermining confidentiality and data security requirements. | ES | AEPD | GDPR | €5,000 | ↗ |
| 17 Apr 2026 | Associazione Movimento Cinque Stelle SiciliaThe Garante fined Associazione Movimento Cinque Stelle Sicilia 5,000 EUR for failing to adopt adequate technical and organizational measures to facilitate the exercise of data protection rights. The authority also found that requests were not addressed without undue delay. | IT | Garante | GDPR | €5,000 | ↗ |
| 29 Sept 2021 | K-city srlK-city srl was fined by the Italian Garante in the amount of 5,000 EUR for breaching data protection principles. The case concerned the management of a paid parking service for the Municipality of Formia, where compliance with lawfulness, fairness, and transparency was not ensured. | IT | Garante | GDPR | €5,000 | ↗ |
| 23 Oct 2023 | EDITEUR DE SITE WEB DEDIE A LA PRESSE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 5,000 on EDITEUR DE SITE WEB DEDIE A LA PRESSE and issued an injunction. The case was handled under a simplified procedure. | FR | CNIL | GDPR | €5,000 | ↗ |
| 27 Nov 2025 | Logika Group s.r.l.Logika Group s.r.l. was fined EUR 5,000 by the Italian supervisory authority, Garante. The authority found that the company sent unsolicited commercial communications and failed to respond to a data access request, in breach of GDPR requirements. | IT | Garante | GDPR | €5,000 | ↗ |
| 16 May 2025 | ACCOUNTING & AUDIT CONSULTING SRLACCOUNTING & AUDIT CONSULTING SRL was fined by ANSPDCP €5,000 for GDPR violations. The investigation was completed in April 2025, and the decision was issued on 16 May 2025. | RO | ANSPDCP | GDPR | €5,000 | ↗ |
| 25 Feb 2021 | Mistore Canarias, S.L.U.Mistore Canarias, S.L.U. was fined by the AEPD 5,000 EUR for processing personal data without consent. The conduct resulted in unauthorized charges to a customer's bank account. | ES | AEPD | GDPR | €5,000 | ↗ |
| 17 Oct 2024 | Ente di Supporto Tecnico Amministrativo Regionale DirezionaleEnte di Supporto Tecnico Amministrativo Regionale Direzionale was fined 5,000 EUR by the Garante for improper handling of personal data during a public selection process. The issue concerned the transmission of files with incorrect names, even though the content was correct. | IT | Garante | GDPR | €5,000 | ↗ |
| 13 Oct 2025 | Vellea Home SRLIn September 2025, the National Supervisory Authority for Personal Data Processing completed an investigation at Vellea Home SRL and found violations of GDPR provisions. The operator was fined EUR 5,000. | RO | ANSPDCP | GDPR | €5,000 | ↗ |
| 29 Apr 2022 | Fire Brigade HeadquartersA fine of EUR 5,000 was imposed for failing to respond to a data access request. The breach concerned access rights under the GDPR and national law. | GR | HDPA | GDPR | €5,000 | ↗ |
| 18 May 2022 | Kredyt Inkaso Investments RO S.A.The company unlawfully processed personal data by disclosing it excessively, including health data. The authority found a breach of personal data processing principles. | RO | ANSPDCP | GDPR | €5,000 | ↗ |
| 27 Nov 2020 | CERTIME, S.A.CERTIME, S.A. was fined by the AEPD in the amount of 5,000 EUR for processing personal data for a purpose different from the one originally specified. The authority found this to be a breach of Article 5(1)(b) GDPR. | ES | AEPD | GDPR | €5,000 | ↗ |
| 04 Oct 2021 | SAKBO SPAIN, S.L.SAKBO SPAIN, S.L. was fined by the AEPD in the amount of 5,000 EUR for sending unsolicited commercial emails without recipient consent. The conduct breached Article 21 of the LSSI governing electronic marketing communications. | ES | AEPD | ePrivacy | €5,000 | ↗ |
| 21 Sept 2020 | AVATA HISPANIA, S.L.AVATA HISPANIA, S.L. was fined by the AEPD 5,000 EUR for using personal data after the contract had ended. The company acted as a data processor, and continued use of the data was inconsistent with its obligations in that role. | ES | AEPD | GDPR | €5,000 | ↗ |
| 17 Jul 2024 | Mark s.r.l.s.Mark s.r.l.s. was fined by the Garante for operating a video surveillance system without the required signage. The case concerned a breach of GDPR information obligations. | IT | Garante | GDPR | €5,000 | ↗ |
| 30 Mar 2021 | PROMOTECH DIGITAL, S.L.PROMOTECH DIGITAL, S.L. was fined by the AEPD in the amount of 5,000 EUR for sending unsolicited SMS messages without recipient consent. The authority also found that the company did not provide an easy opt-out mechanism, in breach of data protection rules. | ES | AEPD | GDPR | €5,000 | ↗ |
| 02 Jun 2021 | TENTEA ENERGY, S.L.TENTEA ENERGY, S.L. was fined by the AEPD EUR 5,000 for using personal data and a signature without consent in connection with energy service contracts. The authority also found a refusal to provide access to personal data in relation to a cancellation request. | ES | AEPD | GDPR | €5,000 | ↗ |