BULLETIN №082Last updated · 04 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 09 Aug 2012 | Iatriko AthinonThe fine was imposed for failing to respond to a data subject's request for access to their medical records. The authority treated this as a violation of the right to information. | GR | HDPA | GDPR | €7,500 | ↗ |
| 09 Aug 2012 | Iatriko AthinonThe fine was imposed for failing to implement appropriate organizational and technical measures to secure sensitive medical data. The case concerned insufficient protection of special-category personal data. | GR | HDPA | GDPR | €7,500 | ↗ |
| 24 Jun 2025 | I ASPIDA TOU DAVIDThe entity did not inform data subjects about the processing of their personal data. The authority treated this as a GDPR breach and imposed a monetary fine. | GR | HDPA | GDPR | €3,000 | ↗ |
| 24 Jun 2025 | I ASPIDA TOU DAVIDThe entity failed to provide the required information and to implement adequate data protection measures. HDPA imposed a fine of EUR 3,000 for breach of GDPR principles. | GR | HDPA | GDPR | €3,000 | ↗ |
| 24 Jun 2025 | I ASPIDA TOU DAVIDThe entity did not satisfy a minor's request to access personal data, which constitutes a breach of GDPR principles. HDPA imposed a fine of EUR 3,000. | GR | HDPA | GDPR | €3,000 | ↗ |
| 24 Jun 2025 | I ASPIDA TOU DAVIDThe HDPA imposed a EUR 1,000 fine on I ASPIDA TOU DAVID. The authority found that the entity failed to cooperate, which breaches GDPR requirements. | GR | HDPA | GDPR | €1,000 | ↗ |
| 20 Mar 2015 | IANO OIKONOMIKE EKDOSEIS AEIANO OIKONOMIKE EKDOSEIS AE was fined EUR 30,000 by the HDPA for sending unsolicited electronic communications. The company collected a large number of email addresses without consent, breaching data protection rules. | GR | HDPA | ePrivacy | €30,000 | ↗ |
| 22 Jan 2015 | Iama Consulting s.r.l.Iama Consulting s.r.l. was fined by the Garante for collecting email addresses through a website form without providing the required privacy notice. The authority found a breach of Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 14 Sept 2018 | IAHORRO BUSINESS SOLUTIONS SLIAHORRO BUSINESS SOLUTIONS SL was fined by the AEPD €1,000 for sending unsolicited commercial electronic communications. The company also failed to provide a procedure for exercising rights of access, rectification, cancellation, or objection. | ES | AEPD | ePrivacy | €1,000 | ↗ |
| 25 Oct 2024 | IA BILET SRLThe operator was fined EUR 1,000 by ANSPDCP for violating GDPR provisions. The case concerns non-compliant processing of personal data. | RO | ANSPDCP | GDPR | €1,000 | ↗ |
| 25 Oct 2024 | IA BILET SRLThe operator was fined EUR 1,000 by ANSPDCP for violating GDPR provisions. The case concerns non-compliance with personal data protection requirements. | RO | ANSPDCP | GDPR | €1,000 | ↗ |
| 14 May 2025 | IAB EuropeThe Gegevensbeschermingsautoriteit’s decision concerned IAB Europe and the Transparency and Consent Framework. A fine of EUR 250,000 was imposed for GDPR breaches related to the processing of personal data, and the Brussels Market Court confirmed the violations and sanctions while noting procedural grounds for annulling the original decision. | BE | Gegevensbeschermingsautoriteit (GBA) | GDPR | €250,000 | ↗ |
| 02 Feb 2022 | IAB EuropeIAB Europe was fined EUR 250,000 by the Belgian APD for violations related to its Transparency & Consent Framework. The authority identified issues with transparency, the legal basis for processing, and the security of personal data. | BE | APD | GDPR | €250,000 | ↗ |
| 02 Feb 2022 | IAB EuropeIAB Europe was fined EUR 250,000 by the Belgian APD for violations related to its Transparency & Consent Framework. The authority cited lack of transparency, improper processing of personal data, and failure to meet GDPR obligations. | BE | APD | GDPR | €250,000 | ↗ |
| 13 Mar 2015 | HYUNDAY MOTOR ESPAÑA, S.L.U.HYUNDAY MOTOR ESPAÑA, S.L.U. was fined 10,000 EUR by the AEPD. The sanction concerned sending unsolicited commercial emails without recipient consent, in breach of the LSSI. | ES | AEPD | ePrivacy | €10,000 | ↗ |
| 23 Dec 2024 | HYUNDAI MOTOR ESPAÑA S.L.U.HYUNDAI MOTOR ESPAÑA S.L.U. was fined EUR 2,000,000 by the AEPD for a data security incident. Unauthorized access to customer data occurred, breaching data protection principles. | ES | AEPD | GDPR | €2,000,000 | ↗ |
| 10 Sept 2024 | HWM PSI, S.L.HWM PSI, S.L. was fined by the AEPD 100 EUR for sending an email to multiple recipients without using BCC. This exposed recipients’ personal email addresses and breached data protection rules. | ES | AEPD | GDPR | €100 | ↗ |
| 22 Jan 2024 | Hvidovre KommuneHvidovre Kommune was fined by Datatilsynet for failing to maintain an appropriate level of security. The issue allowed unauthorized access to protected addresses of children through the municipal dental service's self-service solution, which incorrectly extended access to both custodial parents. | DK | Datatilsynet | GDPR | €26,816 | ↗ |
| 21 Mar 2013 | HU YunteHU Yunte was fined by the Garante for failing to provide the required data protection notice in connection with a video surveillance system. The breach concerned Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 18 Jul 2013 | Hu YonglianHu Yonglian was fined by the Garante in the amount of EUR 2,400 for inadequate data protection notice in a retail store video surveillance system. The authority found a breach of the Italian Privacy Code. | IT | Garante | GDPR | €2,400 | ↗ |