BULLETIN №082Last updated · 31 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.4%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 25 Mar 2021 | TECNOMEDICAL S.r.l.TECNOMEDICAL S.r.l. was fined by the Garante for violating data protection rules related to the processing of health data. The case concerned non-compliance in the handling of sensitive personal data. | IT | Garante | GDPR | €7,000 | ↗ |
| 01 Dec 2017 | BILUA E-COMMERCE S.L (CARETHY y BIUKY)BILUA E-COMMERCE S.L. was fined by the AEPD EUR 7,000 for sending unsolicited commercial emails. The messages were sent despite the recipient's request to unsubscribe, which breached Article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €7,000 | ↗ |
| 01 Jan 2012 | MAIL MARKETING SERVICIOS INFORMATICOS, S.LMAIL MARKETING SERVICIOS INFORMATICOS, S.L was fined by the AEPD in the amount of 7,000 EUR for sending unsolicited commercial emails. The case concerned a breach of Article 21 of the LSSI, which governs electronic marketing communications. | ES | AEPD | ePrivacy | €7,000 | ↗ |
| 15 Mar 2022 | CLÍNICA DENTAL SAN FRANCISCO, S.L.The entity continued sending advertising messages to a former patient despite multiple requests to unsubscribe. AEPD found this to be a breach of data protection rules and imposed a EUR 7,000 fine. | ES | AEPD | ePrivacy | €7,000 | ↗ |
| 02 Dec 2021 | Società Med Store Saronno s.r.l.The Garante fined Società Med Store Saronno s.r.l. EUR 7,000 for inadequate data protection measures. The authority found insufficient password security and no HTTPS protocol, affecting personal health data. | IT | Garante | GDPR | €7,000 | ↗ |
| 12 Sept 2017 | Little Kook - K. Tzortzis – I. Thanos I.K.EThe company was fined EUR 7,000 by the HDPA for operating a video surveillance system without proper notification to the authority. It also monitored employee workspaces, which breached privacy requirements. | GR | HDPA | GDPR | €7,000 | ↗ |
| 01 Jan 2015 | GEDESCO SERVICES SPAIN, S.A.GEDESCO SERVICES SPAIN, S.A. was fined EUR 7,000 by the AEPD for sending unsolicited commercial communications by email and SMS. This conduct breached Article 21 of the LSSI. | ES | AEPD | ePrivacy | €7,000 | ↗ |
| 18 Dec 2025 | SOCIETE AYANT POUR ACTIVITE L'AMENAGEMENT PAYSAGER, L'INSTALLATION DE JARDINS ET DE TERRAINS DE SPORT (procédure simplifiée)The CNIL imposed an administrative fine of EUR 7,000 on the company engaged in landscaping, garden installation, and sports field installation. The case was handled under a simplified procedure. | FR | CNIL | GDPR | €7,000 | ↗ |
| 21 Feb 2022 | RECICLAJES ECOLÓGICOS MELJACAN, S.L.The company was fined by the AEPD for breaching data protection rules. The authority found that the website did not meet the required information and consent standards for data processing and cookie policies. | ES | AEPD | ePrivacy | €7,000 | ↗ |
| 21 Feb 2024 | DIBEA ESTETIC, S.L.DIBEA ESTETIC, S.L. was fined EUR 7,000 by the AEPD for transferring personal data without the data subject’s consent. The authority found this conduct to be contrary to Article 6(1) of the GDPR. | ES | AEPD | GDPR | €7,000 | ↗ |
| 04 Jul 2024 | Comune di TrevisoThe Garante fined Comune di Treviso EUR 7,000 for failing to adopt internal measures governing data processing in connection with the TrevisoSicura application. The authority also found that the municipality incorrectly assumed the role of data processor instead of properly defining its data protection responsibilities. | IT | Garante | GDPR | €7,000 | ↗ |
| 23 Jul 2020 | Anonymisoitu (TSV 632)The controller failed to implement data subject rights under GDPR Articles 12, 15, 17, and 21. It also did not obtain valid consent for electronic direct marketing. A fine of EUR 7,000 was imposed. | FI | TSV | GDPR | €7,000 | ↗ |
| 21 May 2025 | Agenzia di Tutela della Salute, della Città Metropolitana di Milano, Servizio Prevenzione e Sicurezza Ambienti di Lavoro Milano Città NordAgenzia di Tutela della Salute was fined EUR 7,000 by the Garante for improperly sending medical reports and certificates. The authority found a breach of data protection rules. | IT | Garante | GDPR | €7,000 | ↗ |
| 04 Sept 2025 | SOCIETE DEVELOPPANT ET COMMERCIALISANT UN LOGICIEL D'AIDE AU RECRUTEMENT (procédure simplifiée)CNIL imposed an administrative fine of EUR 7,000 on SOCIETE DEVELOPPANT ET COMMERCIALISANT UN LOGICIEL D'AIDE AU RECRUTEMENT. The case was handled under a simplified procedure. | FR | CNIL | GDPR | €7,000 | ↗ |
| 07 Nov 2025 | Klass Wagen S.R.L.Klass Wagen S.R.L. was fined by ANSPDCP EUR 7,000 for failing to promptly report a personal data breach. The incident involved unauthorized access to its contract management system after a former employee disclosed credentials, affecting personal data of many individuals, including data subjects from other EU member states. | RO | ANSPDCP | GDPR | €7,000 | ↗ |
| 06 Jul 2023 | Regione SicilianaThe Garante fined Regione Siciliana EUR 7,000 for publishing personal data of numerous individuals, including sensitive employment-related information. The authority found breaches of lawfulness, fairness, transparency, and data minimization principles. | IT | Garante | GDPR | €7,000 | ↗ |
| 17 Oct 2024 | la SocietàThe company was fined EUR 7,000 by the Garante for violations related to security measures in handling online medical reports and data. The case concerned insufficient safeguards for processed medical information. | IT | Garante | GDPR | €7,000 | ↗ |
| 01 Jan 2017 | SOCIEDAD AIR FRANCE, S.A.Air France was fined by the AEPD EUR 7,000 for sending emails to a complainant despite a request to delete the personal data. The case concerns a breach of data protection rules and improper processing after a deletion request. | ES | AEPD | ePrivacy | €7,000 | ↗ |
| 26 May 2011 | DVDR.it s.r.l.DVDR.it s.r.l. was fined EUR 7,000 by the Garante. The authority found that the company sent unsolicited commercial emails without consent, in breach of data protection rules. | IT | Garante | GDPR | €7,000 | ↗ |
| 09 Aug 2022 | CDI Transport Intern și Internațional SRLThe company was fined for failing to provide requested information within the legal deadline. The authority treated this as a breach of GDPR requirements. | RO | ANSPDCP | GDPR | €7,000 | ↗ |