BULLETIN №082Last updated · 04 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 01 Jan 2015 | GROUPALIA COMPRA COLECTIVA, S.L.GROUPALIA COMPRA COLECTIVA, S.L. was fined by the AEPD 1,000 EUR for sending an unsolicited commercial email to a user who had previously requested to unsubscribe from such communications. The authority found a breach of Article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €1,000 | ↗ |
| 12 Jan 2024 | Grocery Delivery E-Services UK Ltd t/a HelloFreshThe ICO fined Grocery Delivery E-Services UK Ltd t/a HelloFresh 140,000 GBP for sending 79 million spam emails and 1 million spam texts over seven months. The marketing consent was inadequate because it did not mention text messages and was bundled with an age confirmation statement that may have unfairly encouraged agreement. Customers were also not clearly told that their data would continue to be used for marketing for up to 24 months after cancelling subscriptions. | GB | ICO | GDPR | €162,000 | ↗ |
| 17 May 2023 | Grizzaffi Management S.r.l.Grizzaffi Management S.r.l. was fined by the Garante in the amount of 10,000 EUR for sending unsolicited promotional emails without recipient consent. The conduct breached GDPR rules on electronic marketing and consent for commercial communications. | IT | Garante | GDPR | €10,000 | ↗ |
| 26 Jan 2021 | Grindr LLCThe Norwegian DPA intends to fine Grindr 100 million NOK for sharing user data with third parties without valid consent. The conduct was assessed as a breach of GDPR consent requirements. | NO | Datatilsynet | GDPR | €9,627,000 | ↗ |
| 01 Dec 2021 | GrindrThe Norwegian DPA, Datatilsynet, fined Grindr NOK 65 million for sharing user data with third parties for marketing purposes without a legal basis. The authority found a breach of GDPR consent requirements. | NO | Datatilsynet | GDPR | €6,360,000 | ↗ |
| 15 Dec 2021 | GrindrNorway's Datatilsynet imposed an administrative fine of NOK 65 million on Grindr on 15.12.2021. The case concerned violations of the GDPR consent requirements. | NO | Datatilsynet | GDPR | €6,355,000 | ↗ |
| 23 Apr 2023 | GRIMEY WEAR, S.L.GRIMEY WEAR, S.L. did not delete the complainant’s personal data after a request and continued sending promotional emails. The AEPD found this to be a breach of Article 17 GDPR and imposed a fine of 10,000 EUR. | ES | AEPD | GDPR | €10,000 | ↗ |
| 04 Dec 2023 | GRIMEY WEAR, S.L.GRIMEY WEAR, S.L. was fined by the AEPD 5,000 EUR for failing to delete a customer's personal data within the legal timeframe. The case concerns a breach of data protection rules and the controller's obligation to comply with a deletion request. | ES | AEPD | ePrivacy | €5,000 | ↗ |
| 07 Mar 2013 | Greentel Soc. Coop.Greentel Soc. Coop. was fined by the Garante 10,400 EUR for sending promotional communications by fax without providing adequate information or obtaining explicit consent. The authority found violations of Articles 13 and 130 of the Italian Data Protection Code. | IT | Garante | GDPR | €10,400 | ↗ |
| 09 Jun 2011 | GREEN TAL, S.A.GREEN TAL, S.A. was fined by the AEPD in the amount of EUR 1,200 for sending unsolicited commercial emails. The conduct breached Article 21 of the LSSI, which restricts marketing communications without prior consent. | ES | AEPD | ePrivacy | €1,200 | ↗ |
| 28 Aug 2025 | Green Spark Energy LtdThe ICO investigated Green Spark Energy Ltd as part of a wider operation focused on complaint trends in the energy and home improvements sector. It found that between May 2023 and May 2024 the company initiated 9,587,050 automated recorded marketing calls in breach of regulation 19 of PECR, leading to 497 complaints. The recordings used misleading claims to pressure homeowners, and some recipients believed the calls were a scam. | GB | ICO | ePrivacy | €289,000 | ↗ |
| 11 Apr 2013 | Green Paradise S.r.l.Green Paradise S.r.l. was fined 2,400 EUR by the Garante. The authority found that the company collected personal data through its website without providing the required privacy notice, in breach of Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 14 Apr 2023 | Green Network S.p.a.Green Network S.p.a. was fined by the Garante for illegal telemarketing practices in the energy sector. The authority found a breach of data protection principles. | IT | Garante | GDPR | €237,000 | ↗ |
| 23 May 2024 | Green Land African MinimarketThe Garante fined Green Land African Minimarket EUR 1,000 for improper use of a video surveillance system. The system captured areas beyond the company's premises and recorded employees without meeting the required legal conditions. | IT | Garante | GDPR | €1,000 | ↗ |
| 19 Nov 2025 | Greencorp S.R.L.Greencorp S.R.L. was fined EUR 3,000 by ANSPDCP. The authority found that the company failed to notify a personal data security breach. | RO | ANSPDCP | GDPR | €3,000 | ↗ |
| 16 May 2018 | Greco LuigiGreco Luigi, a general practitioner, was fined for failing to implement minimum security measures to protect patients’ personal and sensitive data. This allowed unauthorized access to the healthcare system. | IT | Garante | GDPR | €10,000 | ↗ |
| 19 Oct 2017 | Grant Change s.r.l.Grant Change s.r.l. was fined €32,000 by the Italian data protection authority, Garante. The penalty concerned the sending of promotional SMS messages and emails without valid consent from recipients, in breach of data protection rules. | IT | Garante | GDPR | €32,000 | ↗ |
| 11 Dec 2024 | Granit Bostad Beritsholm ABGranit Bostad Beritsholm AB was fined by IMY for conducting video surveillance without a lawful basis. The authority also found that required information was not provided to affected individuals, constituting a GDPR breach. | SE | IMY | GDPR | €17,366 | ↗ |
| 30 Mar 2017 | Grand Hotel Des Bains s.r.l.Grand Hotel Des Bains s.r.l. was fined by the Garante 12,000 EUR for retaining surveillance footage longer than permitted under the video surveillance guidelines. The case concerns a breach of data retention rules for CCTV recordings. | IT | Garante | GDPR | €12,000 | ↗ |
| 05 Mar 2012 | GRANDES ALMACENES FNAC ESPAÑA S.A.The AEPD fined GRANDES ALMACENES FNAC ESPAÑA S.A. 36,000 EUR for sending unsolicited marketing emails to a customer who had opted out. The conduct breached the LSSI rules on electronic communications and recipient consent. | ES | AEPD | ePrivacy | €36,000 | ↗ |