BULLETIN №082Last updated · 03 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 05 Sept 2024 | SOCIETE SPECIALISEE DANS LAFABRICATION ET POSE DE CLOTURES (procédure simplifiée)The CNIL imposed an administrative fine of EUR 10,000 on SOCIETE SPECIALISEE DANS LAFABRICATION ET POSE DE CLOTURES and issued an injunction. The case was handled under a simplified procedure. | FR | CNIL | GDPR | €10,000 | ↗ |
| 17 May 2023 | Santander Consumer Bank S.p.A.Santander Consumer Bank S.p.A. was fined by the Garante EUR 10,000 for failing to provide timely and adequate access to personal data. The authority also found that prejudicial information related to a loan was not deleted, constituting a breach of GDPR Article 15. | IT | Garante | GDPR | €10,000 | ↗ |
| 30 Jan 2025 | Azienda Unità Sanitaria locale di ModenaAzienda Unità Sanitaria locale di Modena was fined by the Garante €10,000 for processing personal data concerning health and other sensitive information without a proper legal basis. The case involved unlawful processing of special-category data, which raises heightened compliance and privacy risks. | IT | Garante | GDPR | €10,000 | ↗ |
| 30 Oct 2024 | COLEGIO NOTARIAL DE ARAGÓNCOLEGIO NOTARIAL DE ARAGÓN was fined by the AEPD for implementing a fingerprint-based time control system without carrying out a data protection impact assessment. The authority found breaches of GDPR Articles 9 and 35. | ES | AEPD | GDPR | €10,000 | ↗ |
| 12 Feb 2018 | Анонимизирано (CPDP решение-по-жалба-с-рег-№-ж-453-05-10-201)The Commission fined an individual for unlawfully processing personal data by including it in a list supporting registration for a referendum campaign without consent. The case concerned a breach of the legal basis requirements for personal data processing. | BG | CPDP | GDPR | €5,113 | ↗ |
| 24 Apr 2025 | Dante International SAIn April 2025, ANSPDCP completed an investigation into Dante International SA and found violations of GDPR provisions. As a result, a fine of 10,000 EUR was imposed. | RO | ANSPDCP | GDPR | €10,000 | ↗ |
| 01 Jan 2024 | EMPRENDEDORES ONLINE, LLCEMPRENDEDORES ONLINE, LLC was fined by the AEPD 10,000 EUR for recording and sharing course participants’ personal data without consent. The authority found a breach of GDPR Articles 5(1)(f) and 6(1), indicating unlawful processing and insufficient legal basis. | ES | AEPD | GDPR | €10,000 | ↗ |
| 01 Jan 2019 | EL PERIODICO DE CATALUNYA, S.L.EL PERIODICO DE CATALUNYA, S.L. was fined by the AEPD 10,000 EUR for sending a commercial email after a data deletion request. The authority found this conduct to be in breach of Article 6 of the GDPR. | ES | AEPD | GDPR | €10,000 | ↗ |
| 05 Apr 2018 | Comune di Magliano SabinaThe Municipality of Magliano Sabina was fined 10,000 EUR by the Garante for unlawfully disclosing personal data to a private educational institution without a valid legal basis. The authority found that this conduct breached the Italian Privacy Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 06 Apr 2017 | Effepì Credit s.r.l.Effepì Credit s.r.l. was fined by the Garante in the amount of EUR 10,000 for inadequate security measures. The authority cited weak and outdated passwords as a breach of data protection rules. | IT | Garante | GDPR | €10,000 | ↗ |
| 19 Jul 2018 | Anonymizováno (ÚOOÚ UOOU-00944/18-13)The entity processed sensitive personal data about users’ sexual orientation on a website without a valid legal basis. It also failed to provide the required information to data subjects, which breached Czech data protection rules. | CZ | UOOU | GDPR | €386 | ↗ |
| 11 Mar 2021 | Università degli Studi di Napoli Federico IIUniversità degli Studi di Napoli Federico II was fined by the Garante in the amount of 10,000 EUR for breaches of data protection principles. The authority found violations of lawfulness, fairness, transparency, and data minimization in the processing of personal data. | IT | Garante | GDPR | €10,000 | ↗ |
| 26 Jun 2026 | Artmark Holding SRLArtmark Holding SRL was fined by ANSPDCP 10,000 RON for sending unsolicited commercial emails without obtaining prior explicit consent from recipients. The case concerns a breach of rules on electronic marketing communications and consent requirements. | RO | ANSPDCP | ePrivacy | €1,908 | ↗ |
| 08 Oct 2019 | Министър на вътрешните работиThe Ministry of Interior was fined for unlawfully processing and sharing the personal data of a Finnish citizen with Togo authorities without a legal basis. The authority found a breach of GDPR principles on lawful processing and data disclosure. | BG | CPDP | GDPR | €5,113 | ↗ |
| 13 Feb 2025 | Thomas FeroDr Thomas Fero was fined by the Garante EUR 10,000 for sending patients electoral campaign emails without their consent. The authority found this to be a breach of GDPR rules on personal data processing. | IT | Garante | GDPR | €10,000 | ↗ |
| 24 Nov 2016 | Aurora Jonica soc. coop.Aurora Jonica soc. coop. was fined by the Garante 10,000 EUR for making an unsolicited promotional call. The phone number was registered in the public opt-out list, which breached data protection rules. | IT | Garante | GDPR | €10,000 | ↗ |
| 16 May 2018 | Ordinanza ingiunzione - 16 maggio 2018 [9023208]A general practitioner was fined for failing to implement minimum security measures to protect patients' personal and sensitive data. This failure allowed unauthorized access to the healthcare system. | IT | Garante | GDPR | €10,000 | ↗ |
| 01 May 2025 | CURENERGÍA COMERCIALIZADOR DE ÚLTIMO RECURSO S.A.U.CURENERGÍA was fined EUR 10,000 by the AEPD for sharing personal data with IBERDROLA without the data subject’s consent. The disclosure led to a contract offer at a higher price than requested. | ES | AEPD | GDPR | €10,000 | ↗ |
| 25 Sept 2023 | UAT Comuna AlbeniANSPDCP imposed a 10,000 RON fine on UAT Comuna Albeni for failing to implement measures previously ordered by the authority. The entity also did not respond to the authority’s requests. | RO | ANSPDCP | GDPR | €2,013 | ↗ |
| 10 Nov 2016 | Marketing & Comunicazione s.r.l.Marketing & Comunicazione s.r.l. was fined by the Garante for making an unsolicited promotional call to a number listed in the public opposition registry. The conduct breached data protection rules. | IT | Garante | GDPR | €10,000 | ↗ |