BULLETIN №082Last updated · 01 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.1%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 08 Apr 2022 | B.B.B.The entity was fined for installing security cameras that recorded audio and covered areas such as the restroom without proper notice to employees or customers. The authority found this breached GDPR rules on data processing and transparency of information. | ES | AEPD | GDPR | €3,000 | ↗ |
| 08 Apr 2022 | AVALIA ARAGÓN SOCIEDAD DE GARANTÍA RECÍPROCAAVALIA ARAGÓN SOCIEDAD DE GARANTÍA RECÍPROCA was fined by the AEPD for failing to implement robust access controls. The weakness enabled attackers to encrypt files and demand a ransom, indicating significant gaps in technical and organizational safeguards. | ES | AEPD | GDPR | €40,000 | ↗ |
| 08 Apr 2022 | SECURITAS DIRECT ESPAÑA, S.A.SECURITAS DIRECT ESPAÑA, S.A. was fined by the AEPD 50,000 EUR for disclosing a customer's personal information to another client via email. The authority found a breach of confidentiality and insufficient security measures under the GDPR. | ES | AEPD | GDPR | €50,000 | ↗ |
| 08 Apr 2022 | CARTERA VIVANTA, S.L.U.CARTERA VIVANTA, S.L.U. was fined EUR 1,000 by the AEPD for sending a commercial SMS to an individual who had already exercised the right to erasure. The authority found this conduct to be a breach of data protection rules. | ES | AEPD | ePrivacy | €1,000 | ↗ |
| 08 Apr 2022 | B.B.B.The entity was fined by the AEPD for recording audio through a video surveillance system without informing the employee. The authority treated this as a breach of data protection rules. | ES | AEPD | GDPR | €6,000 | ↗ |
| 07 Apr 2022 | Made in Italy s.r.l.s.Made in Italy s.r.l.s. was fined EUR 20,000 by the Garante for carrying out promotional contacts without obtaining consent. The authority also found that the company failed to respond to data subject rights requests, which is a breach of data protection obligations. | IT | Garante | GDPR | €20,000 | ↗ |
| 07 Apr 2022 | Tecnomed Trento s.r.l.Tecnomed Trento s.r.l. was fined by the Garante 10,000 EUR for operating a video surveillance system that did not comply with GDPR and the Italian Privacy Code. The authority found breaches of information duties and general data processing principles. | IT | Garante | GDPR | €10,000 | ↗ |
| 07 Apr 2022 | Rebirth s.r.l.Rebirth s.r.l. was fined by the Garante EUR 15,000 for operating a video surveillance system at “Caffè Antica Roma” in a manner that did not comply with data protection rules. The conduct breached the GDPR and provisions of the Italian Privacy Code. | IT | Garante | GDPR | €15,000 | ↗ |
| 07 Apr 2022 | Comune di OrteComune di Orte was fined for improper handling of personal data collected through video surveillance. The authority found a lack of transparency and insufficient data protection measures. | IT | Garante | GDPR | €5,000 | ↗ |
| 07 Apr 2022 | Azienda ospedaliera di PerugiaAzienda ospedaliera di Perugia was fined by the Garante EUR 40,000 for breaches related to the protection of whistleblower identities. The authority found that adequate personal data protection measures were not in place. | IT | Garante | GDPR | €40,000 | ↗ |
| 07 Apr 2022 | ISWEB S.p.A.ISWEB S.p.A. was fined EUR 40,000 by the Italian supervisory authority, Garante. The authority found that the company failed to properly regulate its relationship with the hosting service provider in relation to data processing for Azienda ospedaliera di Perugia, in breach of Article 28 GDPR. | IT | Garante | GDPR | €40,000 | ↗ |
| 07 Apr 2022 | Анонимизирано (CPDP решение-по-жалба-с-рег-№-ппн-01-101136-0)The CPDP imposed fines on two individuals for unlawful video surveillance in a co-owned property. The authority found breaches of GDPR principles of lawfulness and data minimization. | BG | CPDP | GDPR | €1,534 | ↗ |
| 07 Apr 2022 | Findomestic Banca spaFindomestic Banca spa was fined by the Garante 10,000 EUR for improperly contacting a third party, namely the debtor’s spouse, about a financial obligation. The authority found that this conduct constituted a GDPR violation. | IT | Garante | GDPR | €10,000 | ↗ |
| 07 Apr 2022 | Asociația de Proprietari din Str. Soporului 17, municipiul Cluj-NapocaThe homeowners' association was fined by ANSPDCP for failing to provide requested information to the supervisory authority. The breach concerned obligations under the GDPR. | RO | ANSPDCP | GDPR | €500 | ↗ |
| 07 Apr 2022 | Törlési jog a Központi Hitelinformációs Rendszerben tárolt mulasztási adatokkal összefüggésbenThe controller was fined for unlawful data processing and for failing to properly handle a data subject request. The authority found breaches of GDPR Articles 6, 12, and 17 in connection with default data stored in the Central Credit Information System. | HU | NAIH | GDPR | €2,640 | ↗ |
| 06 Apr 2022 | VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD EUR 70,000 for processing personal data without consent. The case concerned a contract being formalized without the complainant’s consent, which breached lawful processing requirements. | ES | AEPD | GDPR | €70,000 | ↗ |
| 06 Apr 2022 | BANKINTER, S.A.BANKINTER, S.A. was fined EUR 70,000 by the AEPD for a data protection breach. The case involved the unauthorized disclosure of sensitive banking information caused by an isolated IT error. | ES | AEPD | GDPR | €70,000 | ↗ |
| 06 Apr 2022 | Minister van Buitenlandse ZakenThe Dutch Data Protection Authority fined the Minister of Foreign Affairs for failing to provide adequate information to data subjects and for insufficient security measures. The issues concerned the processing of personal data in connection with Schengen visa applications. | NL | AP | GDPR | €565,000 | ↗ |
| 05 Apr 2022 | B.B.B.B.B.B. was fined 300 EUR for installing a surveillance camera that recorded public areas and private property. The authority found this to be a breach of data protection rules. | ES | AEPD | GDPR | €300 | ↗ |
| 04 Apr 2022 | Piraeus Bank S.A.Piraeus Bank S.A. was fined by the HDPA 10,000 EUR for breaching the principle of data confidentiality. The bank sent debit card transaction notifications to incorrect email addresses, failed to notify the authority of the breach, and did not take timely corrective action. | GR | HDPA | GDPR | €10,000 | ↗ |