BULLETIN №082Last updated · 01 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.1%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 18 Jun 2025 | SUNERIS, S.A.SUNERIS, S.A. was fined by the AEPD in the amount of 9,000 EUR for improper handling of personal data. The case involved copying a guest’s information without consent and leaving a master key card accessible, which breached data protection principles. | ES | AEPD | GDPR | €9,000 | ↗ |
| 11 Mar 2010 | Teleservizi s.r.l.Teleservizi s.r.l. was fined EUR 9,000 by the Garante for processing personal data without providing the required information to data subjects. The case concerned a breach of Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €9,000 | ↗ |
| 03 Feb 2011 | Able Tech s.r.l.Able Tech s.r.l. was fined EUR 9,000 by the Garante for failing to provide timely information to the data subject. The breach concerned the obligation under Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €9,000 | ↗ |
| 10 Apr 2025 | Agenzia Mobilità Ambiente e Territorio S.r.l.The Garante fined Agenzia Mobilità Ambiente e Territorio S.r.l. 9,000 EUR for failing to provide sufficient transparency to data subjects. The authority found a breach of the GDPR principles of lawfulness, fairness, and transparency. | IT | Garante | GDPR | €9,000 | ↗ |
| 22 May 2014 | COMERCIAL POLINDUS 21, S.L.COMERCIAL POLINDUS 21, S.L. was fined by the AEPD 9,000 EUR for sending unsolicited commercial SMS messages. The authority found that recipients were not given an opt-out option, which breached Article 21 of the LSSI. | ES | AEPD | ePrivacy | €9,000 | ↗ |
| 16 Feb 2011 | Bioacqua s.r.l.Bioacqua s.r.l. was fined EUR 9,000 by the Garante for using phone numbers for commercial communications without explicit consent and without providing the required information notice. The conduct breached Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €9,000 | ↗ |
| 06 Aug 2025 | YUNEXPRESS SPAIN, S.L.YUNEXPRESS SPAIN, S.L. was fined EUR 9,000 by the AEPD for failing to formalize a data processing agreement and for inaccuracies in data handling. The authority found breaches of GDPR Articles 28(3) and 5(1)(d). | ES | AEPD | GDPR | €9,000 | ↗ |
| 22 Oct 2025 | εκδοτικός οίκοςThe Greek Data Protection Authority fined a publishing house EUR 9,000 for disclosing an author's personal and special-category data in an email sent to 55 recipients. It also found failures to implement data protection by design and to notify both the authority and the data subject of the breach. | GR | Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα | GDPR | €9,000 | ↗ |
| 19 Sept 2024 | CRIDOLMA BARCELONA S.L.CRIDOLMA BARCELONA S.L. was fined €9,000 by the AEPD for failing to properly handle a data subject access request. The case concerned a breach of Article 15 GDPR and non-compliance with a data protection authority resolution. | ES | AEPD | GDPR | €9,000 | ↗ |
| 15 Jun 2011 | Azienda Multiservizi e Igiene Urbana S.p.A.Azienda Multiservizi e Igiene Urbana S.p.A. was fined for collecting personal data through a web form without providing users with the required privacy notice. The authority found this to be a breach of Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €9,000 | ↗ |
| 05 Oct 2022 | Dane anonimowe (D. sp. z o.o. sp. k. z siedzibą w P. przy ul.)The President of UODO imposed a fine of PLN 9,139 on the company. The sanction was issued because the company failed to comply with an order contained in an administrative decision of the data protection authority. | PL | UODO | GDPR | €1,907 | ↗ |
| 11 Dec 2023 | C*** Bank AGC*** Bank AG was fined by the DSB EUR 9,500 for breaching Article 15 GDPR. The bank treated an access request as a deletion request and deleted the data instead of providing the requested information. | AT | DSB | GDPR | €9,500 | ↗ |
| 19 Jan 2017 | D’Agostino Domenico FedeleD’Agostino Domenico Fedele was fined EUR 9,600 by the Garante for failing to provide individuals with the required data protection information. The breach concerned Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €9,600 | ↗ |
| 04 Sept 2025 | Owner of the studentenkotenThe Belgian Data Protection Authority (GBA) imposed a total fine of EUR 9,700 on the owner of a student house. The case concerned the unlawful use of surveillance cameras inside and around the property to monitor students. | BE | Gegevensbeschermingsautoriteit (GBA) | GDPR | €9,700 | ↗ |
| 18 Jan 2024 | Dane anonimowe (przez Pana B.W. prowadzącego działalność gospodarczą pod firmą: B.)UODO imposed an administrative fine on B. for failing to notify the supervisory authority of a personal data breach without undue delay. The authority also found that the affected individuals were not informed of the breach without undue delay. | PL | UODO | GDPR | €2,251 | ↗ |
| 06 Oct 2022 | Poste Italiane S.p.a.Poste Italiane S.p.a. was fined 10,000 EUR by the Garante. The authority found a breach of Article 15 GDPR due to failure to respond to a data access request. | IT | Garante | GDPR | €10,000 | ↗ |
| 30 Oct 2024 | Untold SRLIn September 2024, ANSPDCP completed an investigation at Untold SRL and found violations of GDPR provisions. As a result, the company was fined EUR 10,000. | RO | ANSPDCP | GDPR | €10,000 | ↗ |
| 21 Mar 2024 | Azienda sanitaria locale Roma 3The Garante fined Azienda sanitaria locale Roma 3 10,000 EUR for failing to adequately protect personal data. The breach led to attempted unauthorized access to user accounts and indicated insufficient cybersecurity controls. | IT | Garante | GDPR | €10,000 | ↗ |
| 23 Jun 2023 | LINKEDIN IRELAND LIMITEDThe AEPD fined LinkedIn Ireland Limited EUR 10,000 for sending advertising emails after the recipient had opted out. The authority found a breach of Article 21.1 of the LSSI governing unsolicited marketing communications. | ES | AEPD | ePrivacy | €10,000 | ↗ |
| 09 Mar 2023 | EASYJET AIRLINE COMPANY LIMITEDEasyJet Airline Company Limited was fined by the AEPD 10,000 EUR for failing to provide timely access to personal data requested by an individual. The authority found a breach of Article 15 GDPR, which governs the right of access. | ES | AEPD | GDPR | €10,000 | ↗ |