BULLETIN №082Last updated · 01 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.1%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 21 Sept 2022 | LISMARTSA, S.L.LISMARTSA, S.L. was fined EUR 1,200 by the AEPD for sending emails to multiple recipients without using BCC. This exposed personal email addresses and breached data protection and security requirements. | ES | AEPD | GDPR | €1,200 | ↗ |
| 19 Sept 2022 | Banca Comercială Română SAThe supervisory authority completed an investigation into Banca Comercială Română SA and found a breach of data processing security requirements. The issue was caused by a technical error in the operator’s IT application, which led to improper data processing. | RO | ANSPDCP | GDPR | €2,000 | ↗ |
| 19 Sept 2022 | Vodafone România SAVodafone România SA was fined by ANSPDCP in the amount of EUR 2,000 for violating GDPR provisions. The case concerns non-compliance with personal data protection requirements. | RO | ANSPDCP | GDPR | €2,000 | ↗ |
| 16 Sept 2022 | B.B.B.B.B.B. was fined EUR 300 by the AEPD for installing a surveillance camera. The authority found that the device may have recorded images of a neighboring property without consent, potentially breaching data protection rules. | ES | AEPD | GDPR | €300 | ↗ |
| 16 Sept 2022 | D.A.S. DEFENSA DEL AUTOMOVILISTA Y DE SINIESTROS-INTERNACIONAL, S.A. DE SEGUROS Y REASEGUROSD.A.S. Seguros was fined by the AEPD 50,000 EUR for breaching data protection principles. The company improperly disclosed personal and financial data related to an insurance policy to a third party. | ES | AEPD | GDPR | €50,000 | ↗ |
| 16 Sept 2022 | SUPER 24H LOS ROSALES, S.L.The company was fined EUR 300 by the AEPD for operating an external surveillance camera without visible signage. It also failed to provide information on the data controller and data subject rights required under GDPR. | ES | AEPD | GDPR | €300 | ↗ |
| 15 Sept 2022 | Regione LazioThe Garante imposed a 100,000 EUR fine on Regione Lazio for improper processing of health data in the SIPSOweb system. The authority found that sensitive health information was processed without a proper legal basis and with incorrect role designation. | IT | Garante | GDPR | €100,000 | ↗ |
| 15 Sept 2022 | Immobiliare Riscostruzione Meloria s.r.l.The company was fined by the Garante in the amount of 2,000 EUR for installing a video surveillance system without the required informational signage. This breached GDPR rules on transparency and the duty to inform individuals subject to monitoring. | IT | Garante | GDPR | €2,000 | ↗ |
| 15 Sept 2022 | Bper Banca S.p.A.Bper Banca S.p.A. was fined by the Garante for a delayed and inadequate response to requests for deletion of personal data. The authority found breaches of GDPR Articles 12 and 17. | IT | Garante | GDPR | €10,000 | ↗ |
| 15 Sept 2022 | FCA Italy S.p.A.FCA Italy S.p.A. was fined by the Garante for failing to respond to a data subject's request for access to personal data related to employment. The authority found a breach of GDPR Article 15. | IT | Garante | GDPR | €40,000 | ↗ |
| 15 Sept 2022 | Sofisticated Luxury Flats s.r.l.Sofisticated Luxury Flats s.r.l. was fined €2,000 by the Garante for using a biometric device to monitor employee attendance without a proper legal basis. The authority found that this practice breached data protection rules. | IT | Garante | GDPR | €2,000 | ↗ |
| 15 Sept 2022 | Comune di ThieneComune di Thiene was fined EUR 3,000 by the Garante for violating data protection principles. The authority found that personal data related to a disciplinary dismissal case was improperly disclosed online. | IT | Garante | GDPR | €3,000 | ↗ |
| 15 Sept 2022 | HOTEL VILLA SORO, S.L.The company was fined by the AEPD EUR 1,000 for installing surveillance cameras that could capture public areas without proper signage. The authority considered this a breach of data protection rules. | ES | AEPD | GDPR | €1,000 | ↗ |
| 15 Sept 2022 | ADENET SYSTEMS, S.L.ADENET SYSTEMS, S.L. was fined by the AEPD for obstructing the data protection authority’s inspection. The conduct breached Article 58(1) GDPR. | ES | AEPD | GDPR | €3,000 | ↗ |
| 15 Sept 2022 | EDITORIAL RIBADEO S.L.EDITORIAL RIBADEO S.L. was fined EUR 1,000 by the AEPD for failing to meet the information obligations under Articles 12 and 13 of the GDPR. The authority also noted non-compliance with previous data protection decisions. | ES | AEPD | GDPR | €1,000 | ↗ |
| 12 Sept 2022 | Magyar Éremkibocsátó Kft.The Hungarian data protection authority, NAIH, imposed a fine of 30,000,000 HUF on Magyar Éremkibocsátó Kft. The authority found that personal data were processed without a proper legal basis, specific purpose, or valid consent, and that GDPR transparency and information obligations were breached. | HU | NAIH | GDPR | €75,900 | ↗ |
| 12 Sept 2022 | ROMESTONE, S.L.ROMESTONE, S.L. was fined by the AEPD 6,000 EUR for installing a surveillance camera in a shared rental property without tenant consent. The case concerns a privacy breach in the context of personal data processing. | ES | AEPD | GDPR | €6,000 | ↗ |
| 09 Sept 2022 | MAPFRE ESPAÑA COMPAÑÍA DE SEGUROS Y REASEGUROS, S.A.MAPFRE España was fined by the AEPD for processing personal data without a lawful basis. The company failed to respond properly to a data access request and incorrectly linked an individual to insurance policies and claims. | ES | AEPD | GDPR | €30,000 | ↗ |
| 09 Sept 2022 | COMUNIDAD PROPIETARIO R.R.R.The entity installed a video surveillance system without approval from the property owners' association. The authority found this to be a breach of data protection rules and imposed a fine of 1,500 EUR. | ES | AEPD | GDPR | €1,500 | ↗ |
| 09 Sept 2022 | B.B.B.A private individual was fined 600 EUR by the AEPD for using a webcam oriented toward a public street without prior authorization. The authority treated this as a breach of data protection rules. | ES | AEPD | GDPR | €600 | ↗ |