BULLETIN №083Last updated · 07 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 07 Apr 2022 | Rebirth s.r.l.Rebirth s.r.l. was fined by the Garante EUR 15,000 for operating a video surveillance system at “Caffè Antica Roma” in a manner that did not comply with data protection rules. The conduct breached the GDPR and provisions of the Italian Privacy Code. | IT | Garante | GDPR | €15,000 | ↗ |
| 07 Apr 2022 | Comune di OrteComune di Orte was fined for improper handling of personal data collected through video surveillance. The authority found a lack of transparency and insufficient data protection measures. | IT | Garante | GDPR | €5,000 | ↗ |
| 07 Apr 2022 | Azienda ospedaliera di PerugiaAzienda ospedaliera di Perugia was fined by the Garante EUR 40,000 for breaches related to the protection of whistleblower identities. The authority found that adequate personal data protection measures were not in place. | IT | Garante | GDPR | €40,000 | ↗ |
| 07 Apr 2022 | ISWEB S.p.A.ISWEB S.p.A. was fined EUR 40,000 by the Italian supervisory authority, Garante. The authority found that the company failed to properly regulate its relationship with the hosting service provider in relation to data processing for Azienda ospedaliera di Perugia, in breach of Article 28 GDPR. | IT | Garante | GDPR | €40,000 | ↗ |
| 07 Apr 2022 | Анонимизирано (CPDP решение-по-жалба-с-рег-№-ппн-01-101136-0)The CPDP imposed fines on two individuals for unlawful video surveillance in a co-owned property. The authority found breaches of GDPR principles of lawfulness and data minimization. | BG | CPDP | GDPR | €1,534 | ↗ |
| 07 Apr 2022 | Findomestic Banca spaFindomestic Banca spa was fined by the Garante 10,000 EUR for improperly contacting a third party, namely the debtor’s spouse, about a financial obligation. The authority found that this conduct constituted a GDPR violation. | IT | Garante | GDPR | €10,000 | ↗ |
| 07 Apr 2022 | Asociația de Proprietari din Str. Soporului 17, municipiul Cluj-NapocaThe homeowners' association was fined by ANSPDCP for failing to provide requested information to the supervisory authority. The breach concerned obligations under the GDPR. | RO | ANSPDCP | GDPR | €500 | ↗ |
| 07 Apr 2022 | Törlési jog a Központi Hitelinformációs Rendszerben tárolt mulasztási adatokkal összefüggésbenThe controller was fined for unlawful data processing and for failing to properly handle a data subject request. The authority found breaches of GDPR Articles 6, 12, and 17 in connection with default data stored in the Central Credit Information System. | HU | NAIH | GDPR | €2,640 | ↗ |
| 08 Apr 2022 | B.B.B.The entity was fined for installing security cameras that recorded audio and covered areas such as the restroom without proper notice to employees or customers. The authority found this breached GDPR rules on data processing and transparency of information. | ES | AEPD | GDPR | €3,000 | ↗ |
| 08 Apr 2022 | AVALIA ARAGÓN SOCIEDAD DE GARANTÍA RECÍPROCAAVALIA ARAGÓN SOCIEDAD DE GARANTÍA RECÍPROCA was fined by the AEPD for failing to implement robust access controls. The weakness enabled attackers to encrypt files and demand a ransom, indicating significant gaps in technical and organizational safeguards. | ES | AEPD | GDPR | €40,000 | ↗ |
| 08 Apr 2022 | SECURITAS DIRECT ESPAÑA, S.A.SECURITAS DIRECT ESPAÑA, S.A. was fined by the AEPD 50,000 EUR for disclosing a customer's personal information to another client via email. The authority found a breach of confidentiality and insufficient security measures under the GDPR. | ES | AEPD | GDPR | €50,000 | ↗ |
| 08 Apr 2022 | CARTERA VIVANTA, S.L.U.CARTERA VIVANTA, S.L.U. was fined EUR 1,000 by the AEPD for sending a commercial SMS to an individual who had already exercised the right to erasure. The authority found this conduct to be a breach of data protection rules. | ES | AEPD | ePrivacy | €1,000 | ↗ |
| 08 Apr 2022 | B.B.B.The entity was fined by the AEPD for recording audio through a video surveillance system without informing the employee. The authority treated this as a breach of data protection rules. | ES | AEPD | GDPR | €6,000 | ↗ |
| 12 Apr 2022 | Minister van FinanciënThe Dutch Data Protection Authority imposed a fine on the Minister of Finance for improper processing of personal data in the Fraud Signaling Facility (FSV) application by the Tax and Customs Administration. The authority found breaches of lawfulness, purpose limitation, accuracy, and storage limitation principles. | NL | AP | GDPR | €3,700,000 | ↗ |
| 13 Apr 2022 | PYRAMID CONSULTINGPYRAMID CONSULTING was fined by the AEPD EUR 30,000 for unlawful processing of personal data. The company incorrectly identified an individual as responsible for a traffic violation, which led to an improper administrative sanction. | ES | AEPD | GDPR | €30,000 | ↗ |
| 15 Apr 2022 | SOCIETE D'EDITION DE LOGICIELS APPLICATIFSCNIL imposed a fine of 1,500,000 EUR on SOCIETE D'EDITION DE LOGICIELS APPLICATIFS. The record indicates a regulatory breach, but no further details are provided. | FR | CNIL | GDPR | €1,500,000 | ↗ |
| 16 Apr 2022 | ORI, S.l.ORI, S.l. was fined by the AEPD 2,000 EUR for failing to provide a privacy policy on its website. Personal data was collected through multiple forms, which constituted a breach of data protection rules. | ES | AEPD | GDPR | €2,000 | ↗ |
| 18 Apr 2022 | SUMINISTRADOR IBÉRICO DE ENERGÍA, S.L.The company changed the electricity and gas supplier without the customer's consent. This constituted a breach of data protection rules and led to a fine imposed by the AEPD. | ES | AEPD | GDPR | €30,000 | ↗ |
| 19 Apr 2022 | INGENIERÍA Y TELECOM JAÉN, S.L.INGENIERÍA Y TELECOM JAÉN, S.L. was fined 10,000 EUR by the AEPD. The authority found that the company renewed a customer's service promotion without consent, in breach of Article 6 GDPR. | ES | AEPD | GDPR | €10,000 | ↗ |
| 20 Apr 2022 | Anonymisé (CNPD decision-09-fr-2022)The CNPD fined the company EUR 2,000 for failing to respond in time to a data subject access request and for not providing all required information under GDPR Articles 12 and 15. The company also failed to cooperate with the supervisory authority, contrary to Article 31 GDPR. | LU | CNPD | GDPR | €2,000 | ↗ |