BULLETIN №082Last updated · 01 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.1%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 22 Jul 2022 | MAX2PROTECT, S.L.MAX2PROTECT, S.L. was fined EUR 4,000 by the AEPD for sending commercial emails without the required authorization. The case concerned a breach of Article 21 of the LSSI and involved unauthorized marketing communications. | ES | AEPD | ePrivacy | €4,000 | ↗ |
| 21 Jul 2022 | Comune di GinosaComune di Ginosa was fined EUR 5,000 by the Garante for violations related to the processing of personal data in the whistleblowing context. The authority found that an adequately high level of confidentiality and protection for the data subjects was not ensured. | IT | Garante | GDPR | €5,000 | ↗ |
| 21 Jul 2022 | Global Service s.r.l.Global Service s.r.l. was fined by the Garante EUR 2,000 for installing a video surveillance system without the required informational signage. The case concerned a breach of data protection rules and the duty to properly inform individuals under surveillance. | IT | Garante | GDPR | €2,000 | ↗ |
| 21 Jul 2022 | WUNSCHURLAUB S.L.WUNSCHURLAUB S.L. was fined by the AEPD 3,000 EUR for storing user passwords in plain text and sending them by email without encryption. The authority found this breached GDPR Article 32 on appropriate security measures. | ES | AEPD | GDPR | €3,000 | ↗ |
| 21 Jul 2022 | Stay Over s.r.l.Stay Over s.r.l. was fined by the Garante EUR 10,000 for a delayed and inadequate response to a data access request. The authority also found unlawful processing of a former employee's email account after employment ended. | IT | Garante | GDPR | €10,000 | ↗ |
| 21 Jul 2022 | Clio s.r.l.Clio s.r.l. was fined by the Italian Garante in the amount of 10,000 EUR for violations related to personal data processing. The case involved inadequate protection of whistleblower identities, in breach of the GDPR and national privacy code provisions. | IT | Garante | GDPR | €10,000 | ↗ |
| 21 Jul 2022 | Azienda Socio Sanitaria Territoriale RhodenseAzienda Socio Sanitaria Territoriale Rhodense was fined by the Garante EUR 3,000 for violations of data protection rules. The case concerned data breaches and inadequate security measures. | IT | Garante | GDPR | €3,000 | ↗ |
| 21 Jul 2022 | Acqua Novara.VCO S.p.a.Acqua Novara.VCO S.p.a. was fined EUR 20,000 by the Garante for breaches related to the processing of personal data. The case concerned confidentiality and the risks arising from handling sensitive data in a workplace context. | IT | Garante | GDPR | €20,000 | ↗ |
| 15 Jul 2022 | URBANO DIVERTIA, S.L.URBANO DIVERTIA, S.L. was fined by the AEPD 2,000 EUR for sending clients documents that contained personal data of third parties. The company also failed to include a reference to its privacy policy in corporate emails, which breached data protection requirements. | ES | AEPD | GDPR | €2,000 | ↗ |
| 15 Jul 2022 | FEDERACIÓN DE ATENCIÓN A LA CIUDADANÍA DE LA UNIÓN SINDICAL OBRERA (FAC-USO)The organization continued sending emails to an individual after they requested deletion of their personal data. The AEPD found a breach of Article 6 of the GDPR and imposed a EUR 3,000 fine. | ES | AEPD | GDPR | €3,000 | ↗ |
| 15 Jul 2022 | BANCO BILBAO VIZCAYA ARGENTARIA, S.A.The bank was fined for requesting a disproportionate amount of personal data, including a copy of the DNI, to process a request for information about account movements. The authority found this to be a breach of the data minimization principle. | ES | AEPD | GDPR | €70,000 | ↗ |
| 14 Jul 2022 | SIRIUS advokaterSIRIUS advokater was recommended a fine of DKK 500,000 by Datatilsynet for failing to implement basic security measures. The deficiencies led to a data breach in which sensitive personal data was compromised during a hacking incident. | DK | Datatilsynet | GDPR | €67,180 | ↗ |
| 13 Jul 2022 | GRUPO TRANSAHER, S.L.GRUPO TRANSAHER, S.L. was fined by the AEPD 50,000 EUR for installing surveillance cameras in employee rest areas. The authority found that the company did not properly inform employees and may have infringed their privacy under the GDPR. | ES | AEPD | GDPR | €50,000 | ↗ |
| 12 Jul 2022 | B.B.B.B.B.B. was fined by the AEPD EUR 800 for sending commercial emails without the recipient's consent. The authority found this breached Article 21 of the LSSI on unsolicited electronic communications. | ES | AEPD | ePrivacy | €800 | ↗ |
| 12 Jul 2022 | PUNTO ROJO LIBROS, S.LPUNTO ROJO LIBROS, S.L was fined EUR 800 by the AEPD for sending commercial emails without the recipient’s consent. The conduct breached Article 21 of the LSSI, which requires prior consent for this type of communication. | ES | AEPD | ePrivacy | €800 | ↗ |
| 12 Jul 2022 | LEGAL TRAINING GROUP, S.L.LEGAL TRAINING GROUP, S.L. was fined by the AEPD €6,000 for sending commercial emails without the recipients’ consent. The case concerned a breach of Article 21 of the LSSI and reflects unlawful direct marketing activity. | ES | AEPD | ePrivacy | €6,000 | ↗ |
| 11 Jul 2022 | Hírlevekkel kapcsolatos adatkezelésThe entity was fined by NAIH in the amount of HUF 500,000 for processing personal data for direct marketing purposes without a legal basis. The authority also found a lack of transparent information and delayed handling of data subject requests. | HU | NAIH | GDPR | €1,225 | ↗ |
| 11 Jul 2022 | S.C. (Sameday)S.C. (Sameday) was fined EUR 3,000 by ANSPDCP for failing to implement adequate technical and organizational security measures. The deficiency led to unauthorized access to the personal data of 26,566 individuals. | RO | ANSPDCP | GDPR | €3,000 | ↗ |
| 11 Jul 2022 | Anonymizováno (ÚOOÚ UOOU-04856/21-13)The entity was fined by the UOOU 250,000 CZK for sending unsolicited commercial communications by email to approximately 266,607 recipients without their consent. This conduct violated Czech rules on certain information society services. | CZ | UOOU | ePrivacy | €10,165 | ↗ |
| 08 Jul 2022 | Anonymizováno (ÚOOÚ UOOU-03988/20-54)The entity was fined for processing personal data without a legal basis. The infringement involved sending unsolicited offers using data obtained from the business register. | CZ | UOOU | GDPR | €2,844 | ↗ |