BULLETIN №082Last updated · 03 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 01 Jan 2012 | LET’s BONUS, S.L.LET’s BONUS, S.L. was fined EUR 34,001 by the AEPD for sending unsolicited commercial emails to a user. The conduct continued despite multiple requests to stop, which breached Article 21 of the LSSI. | ES | AEPD | ePrivacy | €34,001 | ↗ |
| 13 Jan 2015 | LEROY MERLIN ESPAÑA S.L.U.LEROY MERLIN ESPAÑA S.L.U. was fined by the AEPD EUR 3,900 for sending unsolicited commercial SMS messages without recipient consent. The authority found this conduct breached Article 21 of the LSSI. | ES | AEPD | ePrivacy | €3,900 | ↗ |
| 29 Apr 2026 | Lepida S.c.p.A.Lepida S.c.p.A. was fined by the Italian supervisory authority Garante €100,000 for unauthorized access and data handling violations linked to SPID digital identity management. The authority found breaches of GDPR Articles 25 and 32, covering data protection by design and security of processing. | IT | Garante | GDPR | €100,000 | ↗ |
| 05 Sept 2013 | Leon d'oro Shi e Shi di Shi Deshao e C. S.n.cThe company was fined by the Garante 2,400 EUR for operating a video surveillance system without the required privacy notice. This breached the Italian Privacy Code because individuals under surveillance were not properly informed. | IT | Garante | GDPR | €2,400 | ↗ |
| 12 May 2016 | Leonardo SestaLeonardo Sesta, a lawyer, was fined by the Italian data protection authority, Garante. The violation concerned transmitting personal data by email instead of registered mail, contrary to data protection rules. | IT | Garante | GDPR | €4,000 | ↗ |
| 26 Mar 2010 | Lenzi automobili s.p.a.Lenzi automobili s.p.a. was fined by the Garante for using a biometric system to verify employee attendance without the required authorization. This constituted a breach of data protection rules. | IT | Garante | GDPR | €10,000 | ↗ |
| — | Lensa.roLensa.ro, operated by Tensa Art Design, was fined EUR 20,000 by Romania’s data protection authority, ANSPDCP. The case involved cookie-based tracking and behavioral advertising without clear user consent, as well as failure to respond to the authority’s official information requests. | RO | Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal | GDPR | €20,000 | ↗ |
| 11 Sept 2025 | Lenjeria Magică SRLLenjeria Magică SRL was fined by ANSPDCP in the amount of 15,000 RON for violating the national ePrivacy law. The breach concerned articles a)-l), n), o) and q). | RO | ANSPDCP | ePrivacy | €2,958 | ↗ |
| 30 Jun 2020 | Lejre KommuneLejre Kommune was fined by Datatilsynet for failing to implement appropriate security measures. This led to unauthorized access to sensitive personal data, including information about minors. | DK | Datatilsynet | GDPR | €6,709 | ↗ |
| 18 Jul 2025 | LEIVA BUS, S.L.LEIVA BUS, S.L. was fined by the AEPD 3,000 EUR for disclosing the personal data of a claimant and a third party in a damage assessment document. The case concerned a breach of data protection rules and unauthorized disclosure of information. | ES | AEPD | GDPR | €3,000 | ↗ |
| 29 Jul 2015 | LEIPZIG COMUNICACIONES, S.L.LEIPZIG COMUNICACIONES, S.L. was fined by the AEPD for sending six unsolicited advertising SMS messages without prior consent. The authority also found that no opt-out mechanism was provided, which breached Article 21 of the LSSI. | ES | AEPD | ePrivacy | €3,000 | ↗ |
| 21 Nov 2018 | Legea s.p.a.Legea s.p.a. was fined for processing personal data through forms on its website without providing the required information notice to data subjects. The case concerned a breach of Article 13 of the Italian Privacy Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 07 Sept 2022 | LEGAL TRAINING GROUP, S.L.LEGAL TRAINING GROUP, S.L. was fined by the AEPD €1,000 for sending unsolicited commercial communications. The conduct occurred after the complainant had exercised the right to data deletion. | ES | AEPD | ePrivacy | €1,000 | ↗ |
| 12 Jul 2022 | LEGAL TRAINING GROUP, S.L.LEGAL TRAINING GROUP, S.L. was fined by the AEPD €6,000 for sending commercial emails without the recipients’ consent. The case concerned a breach of Article 21 of the LSSI and reflects unlawful direct marketing activity. | ES | AEPD | ePrivacy | €6,000 | ↗ |
| 28 Oct 2013 | LEGALITAS ASISTENCIA LEGAL, S.L.LEGALITAS ASISTENCIA LEGAL, S.L. was fined by the AEPD 33,000 EUR for sending unsolicited commercial communications. The conduct continued despite requests for data cancellation, which breached Article 21 of the LSSI. | ES | AEPD | ePrivacy | €33,000 | ↗ |
| 08 Jun 2023 | L’Editoriale Nazionale S.r.l.The Garante fined L’Editoriale Nazionale S.r.l. EUR 30,000 for publishing articles that breached privacy rules. The company disclosed personal and sensitive data relating to a deceased minor without showing that the information was essential. | IT | Garante | GDPR | €30,000 | ↗ |
| 04 Aug 2022 | LEASE PLAN SERVICIOS, S.A.U.LEASE PLAN SERVICIOS, S.A.U. was fined by the AEPD EUR 1,500 for failing to properly handle a request to restrict the processing of personal data. This led to unauthorized commercial communications being sent. | ES | AEPD | ePrivacy | €1,500 | ↗ |
| 06 Nov 2025 | Lead Pronto LtdLead Pronto Ltd received an MPN and an EN from the ICO for sending unsolicited SMS messages promoting Government funded boiler grants. The case indicates a breach of direct marketing rules and consent requirements. | GB | ICO | GDPR | €34,065 | ↗ |
| 15 Mar 2024 | LEADDESK, S.L.LEADDESK, S.L. was fined by the AEPD for failing to provide information requested by the data protection authority during an investigation. The conduct breached Article 58(1) GDPR and hindered supervisory oversight. | ES | AEPD | GDPR | €6,000 | ↗ |
| 12 Sept 2023 | LEADDESK, S.L.LEADDESK, S.L. was fined by the AEPD for failing to provide access to information required under Article 58(1) of the GDPR. The conduct was treated as an obstruction of the data protection authority’s investigative functions. | ES | AEPD | GDPR | €4,000 | ↗ |