BULLETIN №082Last updated · 31 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.4%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 29 Dec 2022 | MEDECIN (procédure simplifiée)The CNIL imposed a EUR 5,000 fine on MEDECIN under a simplified procedure. The authority also issued an injunction subject to a penalty payment, indicating the need for prompt remediation. | FR | CNIL | GDPR | €5,000 | ↗ |
| 05 Mar 2024 | EURO MINI STORAGE ROMANIA SRLEURO MINI STORAGE ROMANIA SRL was fined by ANSPDCP EUR 5,000 for a data security breach caused by a cyber attack. The incident led to unauthorized access to personal data and affected data availability for several weeks. | RO | ANSPDCP | GDPR | €5,000 | ↗ |
| 22 Feb 2024 | Ordine dei Medici Chirurghi e Odontoiatri di PadovaOrdine dei Medici Chirurghi e Odontoiatri di Padova was fined 5,000 EUR by the Garante. The authority found breaches of lawfulness, fairness, transparency, and data minimization in the handling of personal data. | IT | Garante | GDPR | €5,000 | ↗ |
| 23 May 2024 | 20 AÑOS DE MÚSICA A.I.E.The entity was fined for collecting copies of identity documents and personal data without proper data protection information. The authority found breaches of the data minimization and transparency principles. | ES | AEPD | GDPR | €5,000 | ↗ |
| 15 Nov 2024 | AXARQUIA VELEZ DENTAL, S.L.AXARQUIA VELEZ DENTAL, S.L. was fined by the AEPD 5,000 EUR for failing to properly signpost the video surveillance system inside its premises. The authority found a breach of GDPR transparency requirements. | ES | AEPD | GDPR | €5,000 | ↗ |
| 20 Apr 2021 | EB CREATIVE LABEB CREATIVE LAB was fined by the AEPD EUR 5,000 for failing to provide information or obtain consent for cookies on its website. The breach concerned Article 22.2 of the LSSI. | ES | AEPD | ePrivacy | €5,000 | ↗ |
| 19 Jun 2019 | VF JEANSWEAR ESPAÑA S.L.VF Jeanswear España S.L. was fined by the AEPD 5,000 EUR for using cookies on its website without obtaining user consent. The case concerns a breach of data protection rules and consent requirements for cookies. | ES | AEPD | ePrivacy | €5,000 | ↗ |
| 05 Jan 2022 | CARTERA VIVANTA, S.L.U.CARTERA VIVANTA, S.L.U. was fined by the AEPD in the amount of EUR 5,000 for sending commercial SMS messages without the recipient’s consent. The conduct breached Article 21 of the LSSI, which governs unsolicited electronic marketing. | ES | AEPD | ePrivacy | €5,000 | ↗ |
| 09 Sept 2025 | Unita Turism Holding S.A.In August 2025, the National Supervisory Authority for Personal Data Processing completed an investigation at Unita Turism Holding S.A. and found violations of GDPR provisions. As a result, the operator was fined EUR 5,000. | RO | ANSPDCP | GDPR | €5,000 | ↗ |
| 19 Dec 2024 | SOCIETE SPECIALISEE DANS LE SECTEUR D'ACTIVITE DES PORTAILS INTERNET (procédure simplifiée)CNIL imposed an administrative fine of EUR 5,000 on SOCIETE SPECIALISEE DANS LE SECTEUR D'ACTIVITE DES PORTAILS INTERNET under a simplified procedure. The decision concerns a data protection breach identified by the authority. | FR | CNIL | GDPR | €5,000 | ↗ |
| 21 Aug 2018 | National Bank of GreeceNational Bank of Greece was fined EUR 5,000 by the HDPA for failing to maintain accurate data about its debtors. The case concerned compliance with data protection obligations. | GR | HDPA | GDPR | €5,000 | ↗ |
| 02 Dec 2021 | Azienda USL di ParmaAzienda USL di Parma was fined by the Garante for a data breach involving the unauthorized disclosure of health data. The incident affected one individual and did not result in significant harm, but it was still treated as a GDPR violation. | IT | Garante | GDPR | €5,000 | ↗ |
| 27 May 2024 | Anna-Michelle AsimakopoulouAnna-Michelle Asimakopoulou was fined by the HDPA for sending unsolicited political communications by email to individuals who had registered their email addresses for official use with the Greek government. The case concerned the use of those addresses for political outreach, despite being collected for a different purpose. | GR | HDPA | GDPR | €5,000 | ↗ |
| 23 May 2024 | Associazione Medica Chirone s.c.r.l.The Garante fined Associazione Medica Chirone s.c.r.l. 5,000 EUR for improperly accessing and using an employee's vaccination status data. The authority found that the data were not properly anonymized, resulting in a breach of data protection rules. | IT | Garante | GDPR | €5,000 | ↗ |
| 17 Dec 2024 | UNICREDIT CONSUMER FINANCING IFN S.A.UNICREDIT CONSUMER FINANCING IFN S.A. was fined EUR 5,000 by ANSPDCP for processing former employees’ personal data without a legal basis. The authority found breaches of legality, security, and protection against unauthorized or unlawful processing arising from operational errors. | RO | ANSPDCP | GDPR | €5,000 | ↗ |
| 29 Sept 2020 | Geanonimiseerd (APD 64/2020)The Litigation Chamber fined the data controller for failing to close email accounts after employees left the company. The authority found breaches of GDPR principles of purpose limitation, data minimization, and storage limitation. | BE | APD | GDPR | €5,000 | ↗ |
| 15 Dec 2022 | Comune di BorgiaComune di Borgia was fined by the Garante 5,000 EUR for processing employees’ biometric data for attendance tracking without appropriate legislative measures and specific safeguards. The authority found this to be a breach of GDPR rules on special-category data. | IT | Garante | GDPR | €5,000 | ↗ |
| 01 Jan 2015 | BANCO SANTANDER, S.A.Banco Santander was fined EUR 5,000 by the AEPD for sending an unsolicited commercial email to an individual who had not consented to receive such communications. The case concerns a breach of rules on marketing communications and recipient consent. | ES | AEPD | ePrivacy | €5,000 | ↗ |
| 01 Oct 2023 | Anonymised (IDPC CDP_COMP_259_2022)The IDPC imposed a EUR 5,000 fine on Anonymised (IDPC CDP_COMP_259_2022) for breaches of Articles 5(1)(a), 5(1)(b), 5(1)(c) and 6 GDPR. The case concerned personal data processing that did not comply with the principles of lawfulness, fairness, data minimisation and purpose limitation. | MT | IDPC | GDPR | €5,000 | ↗ |
| 01 Oct 2024 | CONSULTORIA INTEGRAL DE ENERGÍA ECOLÓGICA, S.L.The company was fined by the AEPD in the amount of 5,000 EUR for sending unsolicited advertising messages to a complainant. The authority found this conduct breached Article 21 of the LSSI. | ES | AEPD | ePrivacy | €5,000 | ↗ |