BULLETIN №082Last updated · 04 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 03 Sept 2019 | Национална агенция за приходитеThe National Revenue Agency was fined 55,000 BGN for processing personal data without a lawful basis. The authority found that data were collected and used in enforcement proceedings in breach of Article 6 GDPR. | BG | CPDP | GDPR | €28,122 | ↗ |
| 03 Sept 2019 | ЧСИThe CPDP fined a private bailiff (ЧСИ) for failing to provide a data subject with access to personal data collected through video surveillance. The authority found a breach of Article 12 GDPR. | BG | CPDP | GDPR | €1,790 | ↗ |
| 30 Jul 2018 | А.С.К. УМБАЛ ЕООДThe CPDP found that “А.С.К. УМБАЛ ЕООD” unlawfully processed personal data by providing it to “МБАЛ-В. ЕООD” without consent. This breached data protection rules and resulted in a fine of BGN 1,000. | BG | CPDP | GDPR | €511 | ↗ |
| 05 May 2022 | РТК ЕООДThe company processed personal data without a lawful basis by including an individual's data in a public register without a valid contract or consent. The authority found this to be a breach of data protection principles and imposed a fine. | BG | CPDP | GDPR | €5,113 | ↗ |
| 27 Sept 2021 | Сиела Норма АДThe CPDP found that Сиела Норма АД violated the GDPR by inaccurately processing personal data. The error led to an individual being misidentified as a liquidator of companies, and a fine of 5,000 BGN was imposed. | BG | CPDP | GDPR | €2,557 | ↗ |
| 11 Feb 2021 | Политическа партия „Д.П.Б.“Political party “D.P.B.” was fined 1,000 BGN by CPDP for processing personal data without the consent of the data subjects. The breach occurred during the registration of election commission members and violated Article 6 GDPR. | BG | CPDP | GDPR | €511 | ↗ |
| 07 Apr 2022 | Анонимизирано (CPDP решение-по-жалба-с-рег-№-ппн-01-101136-0)The CPDP imposed fines on two individuals for unlawful video surveillance in a co-owned property. The authority found breaches of GDPR principles of lawfulness and data minimization. | BG | CPDP | GDPR | €1,534 | ↗ |
| 23 Jul 2019 | община К.The Municipality of K. unlawfully processed the complainant’s personal data by sharing it with third parties without consent. The authority found a GDPR breach and imposed a 500 BGN fine. | BG | CPDP | GDPR | €256 | ↗ |
| 03 Sept 2019 | А.Т.The CPDP imposed a fine of 23,000 BGN on A.T. for processing personal data without consent, in breach of Article 6 GDPR. The case concerned the creation of financial obligations for the complainant without a valid contract. | BG | CPDP | GDPR | €11,760 | ↗ |
| 17 Jan 2019 | Учебно заведениеThe school was fined 1,000 BGN by the CPDP for unlawfully processing students' personal data. It shared the data with a financial institution without proper consent, which breached GDPR requirements. | BG | CPDP | GDPR | €511 | ↗ |
| 12 Sept 2019 | Anonymised (CyDPC ΑΝΩΝΥΜΟΠΟΙΗΜΕΝΗ ΑΠΟΦΑΣΗ ΔΗΜΟΠΡ)A complaint was filed against an individual for using personal data without consent to contact the complainant about a property sale. The Commissioner found a breach of Article 6 GDPR and imposed a fine of EUR 2,000. | CY | CyDPC | GDPR | €2,000 | ↗ |
| 10 Mar 2025 | Οργανισμός Χρηματοδοτήσεως ΣτέγηςThe Housing Finance Corporation was fined by the CyDPC in the amount of €10,000 for retaining personal data beyond the legal retention period. The authority found this breached GDPR storage limitation and data accuracy requirements. | CY | CyDPC | GDPR | €10,000 | ↗ |
| 21 Sept 2022 | Αρχή Ηλεκτρισμού ΚύπρουThe Cyprus DPA fined the Cyprus Electricity Authority €5,000 for a personal data breach involving unauthorized disclosure to a third party. The authority found violations of GDPR Articles 5(1)(f), 24(1), and 32. | CY | CyDPC | GDPR | €5,000 | ↗ |
| 31 Mar 2022 | Anonymised (CyDPC Απόφαση για λειτουργία ΚΚΒΠ.pd)The case concerned the unlawful installation and operation of a CCTV system in a shared waiting area of a pediatric and dental clinic. A fine of EUR 1,500 was imposed for failure to cooperate with the supervisory authority under GDPR Article 31. | CY | CyDPC | GDPR | €1,500 | ↗ |
| 03 Feb 2022 | Κοινοτικό Συμβούλιο ΒορόκληνηςThe Community Council of Voroklini was fined by the CyDPC for failing to exercise due diligence in the processing of personal data. This led to unauthorized changes to mailing addresses without proper consent. | CY | CyDPC | GDPR | €2,000 | ↗ |
| 07 Dec 2023 | Anonymised (CyDPC ΑΠΟΦΑΣΗ ΓεΣΥ 77.pdf)A doctor accessed a patient's health records in the General Health System (GHS) without proper authorization or referral. The authority found this breached GDPR principles of lawful and transparent processing of personal data. | CY | CyDPC | GDPR | €1,500 | ↗ |
| 03 Feb 2023 | Epic LtdEpic Ltd was fined by the CyDPC in the amount of 3,250 EUR for making unsolicited calls to former customers without a legal basis. The authority also found insufficient technical and organizational measures to ensure compliant data processing and inadequate data security controls. | CY | CyDPC | GDPR | €3,250 | ↗ |
| 17 Sept 2021 | Mediterranean Hospital of CyprusMediterranean Hospital of Cyprus was fined 10,000 EUR by the CyDPC for failing to comply with a data access request. The authority also found a lack of cooperation with the supervisory authority, constituting a breach of Article 31 GDPR. | CY | CyDPC | GDPR | €10,000 | ↗ |
| 16 Jan 2023 | Εκδόσεις Αρκτίνος ΛτδThe decision concerns the unlawful publication of names and photos of police investigators by the newspaper “Politis”. The authority found a breach of the data minimization principle under the GDPR. | CY | CyDPC | GDPR | €10,000 | ↗ |
| 06 Sept 2019 | Anonymised (CyDPC ΑΝΟΝΥΜΟΠΟΙΗΜΕΝΗ ΑΠΟΦΑΣΗ δημοσί)A medical practice was fined EUR 14,000 for posting a patient's pre- and post-surgery images on Instagram without consent. The authority found a breach of GDPR rules on personal data processing and the protection of special-category data. | CY | CyDPC | GDPR | €14,000 | ↗ |