BULLETIN №082Last updated · 01 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.1%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 08 Jul 2022 | SISTEMAS TUBULARES DE INGENIERÍA CANARIAS, S.L.SISTEMAS TUBULARES DE INGENIERÍA CANARIAS, S.L. was fined by the AEPD 2,000 EUR for breaching data retention and confidentiality principles. The company improperly used personal data to file a police report and shared it with multiple parties. | ES | AEPD | GDPR | €2,000 | ↗ |
| 08 Jul 2022 | Egészségügyi dokumentáció másolatának kiadásaThe controller breached the GDPR by failing to provide adequate access to personal health data and by not ensuring transparency and information rights. As a result, the authority imposed a fine of HUF 600,000. | HU | NAIH | GDPR | €1,488 | ↗ |
| 07 Jul 2022 | Senseonics Inc.Senseonics Inc. was fined EUR 45,000 by the Garante for violations related to the processing of personal data. The authority cited issues with data integrity and confidentiality, including health data. | IT | Garante | GDPR | €45,000 | ↗ |
| 07 Jul 2022 | E Software Concept SRLE Software Concept SRL was fined EUR 3,000 by ANSPDCP. The authority found that the company had not implemented adequate technical and organizational measures to ensure a level of security appropriate to the processing risk. | RO | ANSPDCP | GDPR | €3,000 | ↗ |
| 07 Jul 2022 | SIA "DEPO DIY"DVI imposed a fine of 17,495 EUR on SIA "DEPO DIY". The decision concerns a breach of obligations and has entered into force. | LV | DVI | GDPR | €17,495 | ↗ |
| 07 Jul 2022 | Anonymisé (CNPD decision-15-fr-2022)The company was fined by the CNPD EUR 10,500 for breaching the data minimization principle and for failing to adequately inform individuals about video surveillance systems. The authority cited violations of GDPR Articles 5(1)(c) and 13. | LU | CNPD | GDPR | €10,500 | ↗ |
| 07 Jul 2022 | B.B.B.A private individual was fined 600 EUR by the AEPD for improperly positioning surveillance cameras. The cameras were directed toward public areas, which breached data protection rules. | ES | AEPD | GDPR | €600 | ↗ |
| 07 Jul 2022 | B.B.B.The entity installed a surveillance camera without proper signage, covering common areas. This breached the data protection rights of affected individuals and the applicable transparency requirements. | ES | AEPD | GDPR | €600 | ↗ |
| 07 Jul 2022 | Intesa Sanpaolo Vita S.p.a.Intesa Sanpaolo Vita S.p.a. was fined by the Garante EUR 20,000 for unlawfully disclosing personal data related to a life insurance policy to unauthorized third parties. The breach resulted from an operational error and raised concerns about personal data protection and access controls. | IT | Garante | GDPR | €20,000 | ↗ |
| 07 Jul 2022 | SOCIETE DE LOCATION DE VEHICULESCNIL imposed a fine of EUR 175,000 on SOCIETE DE LOCATION DE VEHICULES. The case concerned a breach of personal data protection rules. | FR | CNIL | GDPR | €175,000 | ↗ |
| 07 Jul 2022 | E Software Concept SRLE Software Concept SRL was fined EUR 1,000 by ANSPDCP. The sanction was imposed for failing to provide requested information to the supervisory authority. | RO | ANSPDCP | GDPR | €1,000 | ↗ |
| 07 Jul 2022 | Głównego Geodetę Kraju z siedzibą w Warszawie, przy ul.UODO imposed a PLN 60,000 administrative fine on the Chief Geodesist of Poland. The authority found that the personal data breach was not reported to the supervisory authority without undue delay and that affected individuals were not notified. | PL | UODO | GDPR | €12,573 | ↗ |
| 06 Jul 2022 | Uniwersyteckie CentrumThe Polish DPA (UODO) imposed an administrative fine of PLN 10,000 on Uniwersyteckie Centrum Kliniczne Uniwersytetu Medycznego. The authority found that the entity failed to report the personal data breach without undue delay and did not notify the affected individuals without undue delay. | PL | UODO | GDPR | €2,096 | ↗ |
| 05 Jul 2022 | Global Greece MEPEThe company was fined for sending unsolicited marketing emails without obtaining the recipients’ prior explicit consent. The authority found this conduct to be in breach of Article 11 of Law 3471/2006. | GR | HDPA | ePrivacy | €3,000 | ↗ |
| 05 Jul 2022 | Üzleti titokra való hivatkozással hanganyag korlátozott felhasználhatósággal történő rendelkezésre bocsátásaThe authority fined the controller for failing to properly handle a data subject request. The case concerned a breach of the obligations under Article 12 GDPR. | HU | NAIH | GDPR | €4,900 | ↗ |
| 05 Jul 2022 | CAIXABANK PAYMENTS & CONSUMER EFC, EP, S.A.U.CAIXABANK PAYMENTS & CONSUMER EFC, EP, S.A.U. was fined 70,000 EUR by the AEPD. The company continued to demand payment of a debt that had been annulled by a court ruling, which breached data protection rules. | ES | AEPD | GDPR | €70,000 | ↗ |
| 01 Jul 2022 | RCI BANQUE, S.A. SUCURSAL EN ESPAÑARCI Banque, S.A. Sucursal en España was fined by the AEPD for failing to properly handle a request for erasure under Article 17 GDPR. As a result, the data subject received unwanted communications about a debt they did not owe. | ES | AEPD | GDPR | €20,000 | ↗ |
| 30 Jun 2022 | Anonymisé (CNPD decision-14-fr-2022)The company did not provide data subjects with adequate information about video surveillance, breaching GDPR transparency requirements. CNPD found violations of Articles 5, 12, and 13 GDPR and imposed a 1,000 EUR fine. | LU | CNPD | GDPR | €1,000 | ↗ |
| 30 Jun 2022 | B.B.B.The entity was fined EUR 300 by the AEPD for failing to display the required signage informing individuals about video surveillance at its premises. The authority treated this as a breach of the information obligations under Article 13 GDPR. | ES | AEPD | GDPR | €300 | ↗ |
| 30 Jun 2022 | Federazione Italiana Sommelier, Albergatori e RistoratoriFederazione Italiana Sommelier, Albergatori e Ristoratori was fined by the Garante 5,000 EUR for unlawful processing of personal data. The breach involved the improper communication of one member’s data to all associates. | IT | Garante | GDPR | €5,000 | ↗ |