BULLETIN №082Last updated · 31 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.4%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 10 Jul 2025 | dottoressa Monica Maria FerrariThe doctor was fined for recording conversations with a patient during a specialist visit without proper consent. The authority also found a failure to provide required information, breaching transparency and information obligations. | IT | Garante | GDPR | €7,000 | ↗ |
| 25 Oct 2016 | CENTROS COMERCIALES CARREFOUR, S.A.CENTROS COMERCIALES CARREFOUR, S.A. was fined EUR 7,000 by the AEPD for sending unsolicited commercial emails. The authority also found that the company failed to provide a proper opt-out mechanism, breaching Article 21 of the LSSI. | ES | AEPD | ePrivacy | €7,000 | ↗ |
| 29 Dec 2025 | SOCIETE EXERCANT UNE ACTIVITE D'EDITION DE JOURNAUX (procédure simplifiée)The CNIL imposed an administrative fine of EUR 7,000 on SOCIETE EXERCANT UNE ACTIVITE D'EDITION DE JOURNAUX and issued an injunction. The case concerns a breach of rules supervised by the CNIL. | FR | CNIL | GDPR | €7,000 | ↗ |
| 16 Jun 2021 | MARBELLA RESORTS, S.L.MARBELLA RESORTS, S.L. was fined EUR 7,000 by the AEPD for non-compliance with data protection rules. The breaches concerned the handling of personal data and the website cookie policy. | ES | AEPD | ePrivacy | €7,000 | ↗ |
| 14 Mar 2017 | GABINETE PARAPSICOLOGICO MYSTIC S.L.GABINETE PARAPSICOLOGICO MYSTIC S.L. was fined by the AEPD for sending unsolicited commercial SMS messages. The authority found that recipients were not given a simple and free opt-out mechanism, in breach of the LSSI. | ES | AEPD | ePrivacy | €7,100 | ↗ |
| 11 Jun 2021 | Anonymisé (CNPD decision-22-fr-2021)The company failed to comply with GDPR requirements on data minimization and transparency. It also did not adequately inform individuals about video surveillance and geolocation systems, breaching Articles 5(1)(c), 5(1)(e), 13, and 32(1) of the GDPR. | LU | CNPD | GDPR | €7,200 | ↗ |
| 11 Jul 2018 | General Market di E. Barcio & Fratelli s.n.c.General Market di E. Barcio & Fratelli s.n.c. was fined by the Garante 7,200 EUR for failing to provide adequate information to people entering its stores about data processing through video surveillance systems. The authority found that the required notice obligations for monitored individuals were not met. | IT | Garante | GDPR | €7,200 | ↗ |
| 16 Dec 2025 | Anonymisé (CNPD decision-05-fr-2025)The company did not maintain a complete and accurate record of processing activities under Article 30 GDPR. The record lacked or contained incomplete information on data categories and transfers to third countries. | LU | CNPD | GDPR | €7,341 | ↗ |
| 07 Nov 2014 | MASTOCADOS S.L.MASTOCADOS S.L. was fined by the AEPD 7,400 EUR for sending unauthorized commercial emails to individuals without a prior contractual relationship. The conduct breached Article 21 of the LSSI on electronic marketing communications. | ES | AEPD | ePrivacy | €7,400 | ↗ |
| 01 Jan 2015 | JAZZ TELECOM, SAUJAZZ TELECOM, SAU was fined by the AEPD in the amount of 7,400 EUR for sending unsolicited commercial emails to a complainant. The conduct occurred after the cancellation of the complainant’s personal data had been confirmed and breached Article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €7,400 | ↗ |
| 13 Jan 2022 | Azienda Sanitaria Locale FrosinoneAzienda Sanitaria Locale Frosinone was fined by the Italian supervisory authority, Garante, in the amount of EUR 7,500. The case concerned breaches of transparency and information duties in personal data processing under GDPR Articles 12 and 13. | IT | Garante | GDPR | €7,500 | ↗ |
| 31 May 2024 | CUMACA MOTOR, S.L.CUMACA MOTOR, S.L. was fined EUR 7,500 by the AEPD for requiring customers to provide a copy of their identity document without a valid justification. The authority found that this breached the GDPR data minimization principle. | ES | AEPD | GDPR | €7,500 | ↗ |
| 08 Aug 2014 | INFOASSIST A.E.INFOASSIST A.E. was fined by the HDPA 7,500 EUR for processing personal data without consent. The authority found breaches of legality and data minimization principles. | GR | HDPA | GDPR | €7,500 | ↗ |
| 08 Aug 2014 | Hummingbird EPEHummingbird EPE was fined by the HDPA for processing publicly available personal data without the consent of the data subjects. The authority found a breach of the principles of data relevance and proportionality. | GR | HDPA | GDPR | €7,500 | ↗ |
| 06 Mar 2024 | The Central Young Men’s Christian AssociationThe Central YMCA sent an email to participants in a programme for people living with HIV using “CC” instead of “BCC”, which exposed recipients’ email addresses to all recipients. From those addresses, 166 individuals could be identified or potentially identified, allowing an inference that they were likely living with HIV. The ICO imposed a £7,500 fine and issued a reprimand. | GB | ICO | GDPR | €8,772 | ↗ |
| 11 May 2021 | Stichting Ondersteuning Provinciale Fractie Overijssel Partij voor de Vrijheid (PVV Overijssel)PVV Overijssel was fined by the AP EUR 7,500 for failing to report a personal data breach within the required 72-hour period. The case concerns a delayed notification to the supervisory authority about a security incident. | NL | AP | GDPR | €7,500 | ↗ |
| 17 Jul 2025 | Perla Odontoiatria Veneta S.r.l.The Garante fined Perla Odontoiatria Veneta S.r.l. EUR 7,500 for failing to meet information and transparency obligations in the processing of health data. The authority cited breaches of GDPR Articles 5, 9, and 15. | IT | Garante | GDPR | €7,500 | ↗ |
| 09 Aug 2012 | Iatriko AthinonThe fine was imposed for failing to respond to a data subject's request for access to their medical records. The authority treated this as a violation of the right to information. | GR | HDPA | GDPR | €7,500 | ↗ |
| 09 Aug 2012 | Iatriko AthinonThe fine was imposed for failing to implement appropriate organizational and technical measures to secure sensitive medical data. The case concerned insufficient protection of special-category personal data. | GR | HDPA | GDPR | €7,500 | ↗ |
| 02 Apr 2026 | SOCIÉTÉ EXPLOITANT DES BOUTIQUES TOILETTES (procédure simplifiée)CNIL imposed an administrative fine of EUR 7,500 on SOCIÉTÉ EXPLOITANT DES BOUTIQUES TOILETTES under a simplified procedure. The case concerns a breach of rules covered by the authority’s decision. | FR | CNIL | GDPR | €7,500 | ↗ |