BULLETIN №082Last updated · 31 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.4%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 01 Jan 2024 | a small recruitment bureauA small recruitment bureau in the Netherlands was fined EUR 6,000 by the Autoriteit Persoonsgegevens for failing to respond on time to an ex-candidate’s request to delete personal data. The Raad van State upheld the fine in case ECLI:NL:RVS:2024:2221. | NL | Autoriteit Persoonsgegevens | GDPR | €6,000 | ↗ |
| 29 Jan 2015 | Iper Market Yi-Gou s.r.l.Iper Market Yi-Gou s.r.l. was fined EUR 6,000 by the Italian supervisory authority, Garante. The case concerned the failure to provide the required information to data subjects about personal data processing through a video surveillance system. | IT | Garante | GDPR | €6,000 | ↗ |
| 27 Mar 2025 | SOCIETE DE CONSEILS POUR LES AFFAIRES ET AUTRES CONSEILS DE GESTION (procédure simplifiée)The CNIL imposed an administrative fine of EUR 6,000 on SOCIETE DE CONSEILS POUR LES AFFAIRES ET AUTRES CONSEILS DE GESTION. The case was handled under a simplified procedure. | FR | CNIL | GDPR | €6,000 | ↗ |
| 10 Apr 2025 | SOCIETE EXERCANT UNE ACTIVITE DE RESTAURATION (procédure simplifiée)The CNIL imposed an administrative fine of EUR 6,000 on SOCIETE EXERCANT UNE ACTIVITE DE RESTAURATION. The case was handled under a simplified procedure. | FR | CNIL | GDPR | €6,000 | ↗ |
| 31 Aug 2025 | DELAFRUIT, S.L.DELAFRUIT, S.L. was fined by the AEPD in the amount of 6,000 EUR for installing cameras in a break area without proper notice to affected individuals. The authority treated this as a breach of data protection rules. | ES | AEPD | GDPR | €6,000 | ↗ |
| 08 Nov 2024 | AECORP 005, S.L.AECORP 005, S.L. was fined EUR 6,000 by the AEPD for failing to provide access to information requested during an investigation. The authority found a breach of Article 58.1 GDPR. | ES | AEPD | GDPR | €6,000 | ↗ |
| 12 Sept 2024 | Ordine delle Professioni Infermieristiche di PordenoneOrdine delle Professioni Infermieristiche di Pordenone was fined 6,000 EUR by the Garante for breaching data protection rules. The authority found that the organization mishandled a data subject request and failed to respect privacy rights. | IT | Garante | GDPR | €6,000 | ↗ |
| 23 Oct 2025 | Geturhotels SrlGeturhotels Srl was fined EUR 6,000 by the Garante for sending unsolicited SMS messages to a complainant despite their objection. The authority found that the company’s conduct breached GDPR rules on processing personal data for promotional purposes. | IT | Garante | GDPR | €6,000 | ↗ |
| 12 Sept 2022 | ROMESTONE, S.L.ROMESTONE, S.L. was fined by the AEPD 6,000 EUR for installing a surveillance camera in a shared rental property without tenant consent. The case concerns a privacy breach in the context of personal data processing. | ES | AEPD | GDPR | €6,000 | ↗ |
| 12 Dec 2024 | Comune di Corte FrancaComune di Corte Franca was fined EUR 6,000 for publishing personal data online without a proper legal basis. The authority found breaches of GDPR Articles 5 and 6 and Article 2-ter of the Italian Privacy Code. | IT | Garante | GDPR | €6,000 | ↗ |
| 23 Oct 2025 | Emera SrlEmera Srl was fined by the Garante EUR 6,000 for sending unsolicited promotional SMS messages despite the recipient's repeated requests for data deletion. The authority also found inadequate data retention and organizational procedures to ensure respect for data subject rights. | IT | Garante | GDPR | €6,000 | ↗ |
| 14 Mar 2013 | Vinci s.r.l.Vinci s.r.l. was fined €6,000 by the Italian data protection authority, Garante. The case concerned the failure to provide the required privacy notice on the website contact form, in breach of Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €6,000 | ↗ |
| 08 Aug 2014 | Anonymised (HDPA 104/2014)The supervisory authority found that the controller processed personal data without the data subjects' consent. The breach concerned the principles governing data processing under Greek law. | GR | HDPA | GDPR | €6,000 | ↗ |
| 11 Feb 2016 | Vito Roma s.r.l.Vito Roma s.r.l. was fined by the Garante for operating a video surveillance system without providing the required data protection notice. The authority found a breach of Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €6,000 | ↗ |
| 20 Feb 2025 | BLUE TEAM FLIGHT SCHOOL, S.L.BLUE TEAM FLIGHT SCHOOL, S.L. was fined 6,000 EUR by the AEPD. The authority found that the company failed to provide access to personal data and information requested by the data protection authority, in breach of Article 58.1 of the GDPR. | ES | AEPD | GDPR | €6,000 | ↗ |
| 16 Apr 2021 | CREATOR ENERGY, S.L.CREATOR ENERGY, S.L. was fined by the AEPD 6,000 EUR for using personal data without consent to contract gas, electricity, and maintenance services. The authority found this conduct breached Article 6(1)(b) GDPR. | ES | AEPD | GDPR | €6,000 | ↗ |
| 05 Sept 2013 | Maria Vita PezzellaMaria Vita Pezzella was fined EUR 6,000 by Garante for failing to provide the required privacy notice in a video surveillance system. The case concerned a breach of the Italian Privacy Code and the duty to inform individuals subject to monitoring. | IT | Garante | GDPR | €6,000 | ↗ |
| 01 Jan 2016 | VODAFONE ONO, S.A.U.Vodafone Ono, S.A.U. was fined by the AEPD 6,000 EUR for sending unsolicited advertising SMS messages to a complainant. The complainant's data had previously been canceled, indicating a breach of data handling and marketing communication rules. | ES | AEPD | ePrivacy | €6,000 | ↗ |
| 10 Jan 2026 | MULTISPORTS GALICIA, S.L.MULTISPORTS GALICIA, S.L. was fined by the AEPD EUR 6,000 for failing to implement appropriate technical and organizational measures proportionate to the risk. The weakness allowed easy access to personal data of race participants through its website. | ES | AEPD | GDPR | €6,000 | ↗ |
| 30 Jan 2025 | Azienda Ospedaliero - Universitaria Città della Salute e della Scienza di TorinoThe Garante fined Azienda Ospedaliero - Universitaria Città della Salute e della Scienza di Torino 6,000 EUR for unlawful processing of personal data, including health data. The authority found that the processing lacked an appropriate legal basis. The case concerned sensitive data handling in the healthcare sector. | IT | Garante | GDPR | €6,000 | ↗ |