BULLETIN №082Last updated · 02 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 01 Aug 2012 | Spazio S s.r.l.Spazio S s.r.l. was fined by the Garante 10,400 EUR for sending unsolicited commercial emails. The authority found that the company failed to provide adequate information and did not obtain valid consent from recipients, breaching privacy rules. | IT | Garante | GDPR | €10,400 | ↗ |
| 13 Apr 2026 | Dane anonimowe (Pana L. A. prowadzącego działalność gospodarczą pod nazwą: A.)UODO issued a reprimand to the controller, two agents and a sub-agent, and imposed an administrative fine on the sub-agent. The case concerned GDPR breaches related to processing security, verification of processors, and the principles of confidentiality and accountability. | PL | UODO | GDPR | €2,385 | ↗ |
| 06 Oct 2022 | Poste Italiane S.p.a.Poste Italiane S.p.a. was fined 10,000 EUR by the Garante. The authority found a breach of Article 15 GDPR due to failure to respond to a data access request. | IT | Garante | GDPR | €10,000 | ↗ |
| 30 Oct 2024 | Untold SRLIn September 2024, ANSPDCP completed an investigation at Untold SRL and found violations of GDPR provisions. As a result, the company was fined EUR 10,000. | RO | ANSPDCP | GDPR | €10,000 | ↗ |
| 21 Mar 2024 | Azienda sanitaria locale Roma 3The Garante fined Azienda sanitaria locale Roma 3 10,000 EUR for failing to adequately protect personal data. The breach led to attempted unauthorized access to user accounts and indicated insufficient cybersecurity controls. | IT | Garante | GDPR | €10,000 | ↗ |
| 23 Jun 2023 | LINKEDIN IRELAND LIMITEDThe AEPD fined LinkedIn Ireland Limited EUR 10,000 for sending advertising emails after the recipient had opted out. The authority found a breach of Article 21.1 of the LSSI governing unsolicited marketing communications. | ES | AEPD | ePrivacy | €10,000 | ↗ |
| 09 Mar 2023 | EASYJET AIRLINE COMPANY LIMITEDEasyJet Airline Company Limited was fined by the AEPD 10,000 EUR for failing to provide timely access to personal data requested by an individual. The authority found a breach of Article 15 GDPR, which governs the right of access. | ES | AEPD | GDPR | €10,000 | ↗ |
| 24 Oct 2013 | Comune di Torre CajetaniComune di Torre Cajetani was fined by the Garante for unlawfully publishing an individual's health data on a public notice board. The conduct breached privacy and personal data protection rules. | IT | Garante | GDPR | €10,000 | ↗ |
| 14 Sept 2006 | Asl n. 8 di Asolo (TV)Asl n. 8 di Asolo was fined by the Garante for failing to notify the processing of personal data revealing health and sexual life. The notification was required under the Italian Privacy Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 26 Nov 2020 | Reti Televisive Italiane S.p.a.Reti Televisive Italiane S.p.a. was fined EUR 10,000 by the Garante for broadcasting a segment on “Le Iene” that included footage of an individual recorded without consent. The person was identifiable, which constituted a breach of data protection rules. | IT | Garante | GDPR | €10,000 | ↗ |
| 01 Jan 2019 | IKEA IBERICA, S.A.U.The AEPD fined IKEA IBERICA, S.A.U. 10,000 EUR for installing cookies on users’ devices without obtaining prior informed consent. The authority found this breached Article 22.2 of the LSSI. | ES | AEPD | ePrivacy | €10,000 | ↗ |
| 06 Jul 2022 | Uniwersyteckie CentrumThe Polish DPA (UODO) imposed an administrative fine of PLN 10,000 on Uniwersyteckie Centrum Kliniczne Uniwersytetu Medycznego. The authority found that the entity failed to report the personal data breach without undue delay and did not notify the affected individuals without undue delay. | PL | UODO | GDPR | €2,096 | ↗ |
| 01 Mar 2017 | CENTROS COMERCIALES CARREFOUR S.A.CENTROS COMERCIALES CARREFOUR S.A. was fined by the AEPD €10,000 for sending commercial emails without a valid unsubscribe link. The case concerned non-compliance with electronic communications rules and recipients’ right to opt out easily. | ES | AEPD | ePrivacy | €10,000 | ↗ |
| 26 May 2022 | Comune di AfragolaComune di Afragola was fined EUR 10,000 by the Garante for breaching data protection principles, including lawfulness, fairness, transparency, and data minimization. The authority found that personal data had been handled improperly. | IT | Garante | GDPR | €10,000 | ↗ |
| 28 Jul 2016 | IMPACTING EMAIL MARKETING SOLUTIONS, S.L.IMPACTING EMAIL MARKETING SOLUTIONS, S.L. was fined by the AEPD 10,000 EUR for sending unsolicited commercial communications by SMS without recipient consent. The case concerns a breach of data protection and direct marketing rules. | ES | AEPD | ePrivacy | €10,000 | ↗ |
| 13 Mar 2025 | IV Casa Firenze Sud di Benedetti Francesco & C. S.a.s.IV Casa Firenze Sud di Benedetti Francesco & C. S.a.s. was fined by the Garante EUR 10,000 for making unsolicited marketing calls without proper consent. The authority found a breach of GDPR rules on data processing and consent. | IT | Garante | GDPR | €10,000 | ↗ |
| 27 May 2021 | Poste Italiane S.p.a.Poste Italiane S.p.a. was fined by the Garante 10,000 EUR for unlawfully communicating a customer's financial data related to a Postepay card to an unauthorized third party. The case concerns a breach of personal data protection and financial confidentiality requirements. | IT | Garante | GDPR | €10,000 | ↗ |
| 01 Jan 2022 | ALPA 57 PRODUCCIONES, S.L.ALPA 57 PRODUCCIONES, S.L. was fined by the AEPD 10,000 EUR for processing personal data without a legal basis. The company impersonated another energy provider and used personal data without consent. | ES | AEPD | GDPR | €10,000 | ↗ |
| 12 Dec 2024 | SOCIETE EXERCANT UNE ACTIVITE DE COMPARATEUR D'AUTO-ECOLES (procédure simplifiée)The CNIL imposed an administrative fine of EUR 10,000 on SOCIETE EXERCANT UNE ACTIVITE DE COMPARATEUR D'AUTO-ECOLES. The case was handled under a simplified procedure. | FR | CNIL | GDPR | €10,000 | ↗ |
| 10 Apr 2025 | Tensa Art Design S.A.Tensa Art Design S.A. was fined by ANSPDCP EUR 10,000 for GDPR violations related to its website www.lensa.ro. The case concerned non-compliant processing of personal data under data protection requirements. | RO | ANSPDCP | GDPR | €10,000 | ↗ |