BULLETIN №083Last updated · 05 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -22.5%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 09 Aug 2012 | Iatriko AthinonThe fine was imposed for failing to respond to a data subject's request for access to their medical records. The authority treated this as a violation of the right to information. | GR | HDPA | GDPR | €7,500 | ↗ |
| 09 Aug 2012 | Iatriko AthinonThe fine was imposed for failing to implement appropriate organizational and technical measures to secure sensitive medical data. The case concerned insufficient protection of special-category personal data. | GR | HDPA | GDPR | €7,500 | ↗ |
| 02 Apr 2026 | SOCIÉTÉ EXPLOITANT DES BOUTIQUES TOILETTES (procédure simplifiée)CNIL imposed an administrative fine of EUR 7,500 on SOCIÉTÉ EXPLOITANT DES BOUTIQUES TOILETTES under a simplified procedure. The case concerns a breach of rules covered by the authority’s decision. | FR | CNIL | GDPR | €7,500 | ↗ |
| 07 Nov 2014 | MASTOCADOS S.L.MASTOCADOS S.L. was fined by the AEPD 7,400 EUR for sending unauthorized commercial emails to individuals without a prior contractual relationship. The conduct breached Article 21 of the LSSI on electronic marketing communications. | ES | AEPD | ePrivacy | €7,400 | ↗ |
| 01 Jan 2015 | JAZZ TELECOM, SAUJAZZ TELECOM, SAU was fined by the AEPD in the amount of 7,400 EUR for sending unsolicited commercial emails to a complainant. The conduct occurred after the cancellation of the complainant’s personal data had been confirmed and breached Article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €7,400 | ↗ |
| 16 Dec 2025 | Anonymisé (CNPD decision-05-fr-2025)The company did not maintain a complete and accurate record of processing activities under Article 30 GDPR. The record lacked or contained incomplete information on data categories and transfers to third countries. | LU | CNPD | GDPR | €7,341 | ↗ |
| 11 Jun 2021 | Anonymisé (CNPD decision-22-fr-2021)The company failed to comply with GDPR requirements on data minimization and transparency. It also did not adequately inform individuals about video surveillance and geolocation systems, breaching Articles 5(1)(c), 5(1)(e), 13, and 32(1) of the GDPR. | LU | CNPD | GDPR | €7,200 | ↗ |
| 11 Jul 2018 | General Market di E. Barcio & Fratelli s.n.c.General Market di E. Barcio & Fratelli s.n.c. was fined by the Garante 7,200 EUR for failing to provide adequate information to people entering its stores about data processing through video surveillance systems. The authority found that the required notice obligations for monitored individuals were not met. | IT | Garante | GDPR | €7,200 | ↗ |
| 14 Mar 2017 | GABINETE PARAPSICOLOGICO MYSTIC S.L.GABINETE PARAPSICOLOGICO MYSTIC S.L. was fined by the AEPD for sending unsolicited commercial SMS messages. The authority found that recipients were not given a simple and free opt-out mechanism, in breach of the LSSI. | ES | AEPD | ePrivacy | €7,100 | ↗ |
| 20 Oct 2022 | I.S.P.R.O.The Italian Data Protection Authority fined I.S.P.R.O. EUR 7,000 for violations related to the processing of health data. The case concerned improper handling of sensitive data, creating a material compliance risk. | IT | Garante | GDPR | €7,000 | ↗ |
| 11 Sept 2025 | ASSOCIATION GERANT UN LYCEE ET UN INTERNAT POUR LES JEUNES EN SITUATION DE DECROCHAGE SCOLAIRE (procédure simplifiée)CNIL imposed an administrative fine of 7,000 EUR on ASSOCIATION GERANT UN LYCEE ET UN INTERNAT POUR LES JEUNES EN SITUATION DE DECROCHAGE SCOLAIRE and issued an injunction. The case was handled under a simplified procedure. | FR | CNIL | GDPR | €7,000 | ↗ |
| 22 Feb 2023 | MUNDOVIAJES2010, S.L.MUNDOVIAJES2010, S.L. was fined by the AEPD in the amount of 7,000 EUR for processing personal data without consent. The authority also found a failure to provide the required information about data processing, in breach of GDPR Articles 6(1) and 14. | ES | AEPD | GDPR | €7,000 | ↗ |
| 01 Jan 2016 | CENTROS COMERCIALES CARREFOUR S.A.CENTROS COMERCIALES CARREFOUR S.A. was fined by the AEPD for sending unsolicited advertising emails. The authority also found that the company did not provide an easy opt-out mechanism, in breach of Article 21 of the LSSI. | ES | AEPD | ePrivacy | €7,000 | ↗ |
| 01 Jan 2023 | INSTITUTO OFTALMOLÓGICO DE ***LOCALIDAD.1 B.B.B., S.L.INSTITUTO OFTALMOLÓGICO DE ***LOCALIDAD.1 B.B.B., S.L. was fined by the AEPD EUR 7,000 for unlawfully disclosing personal data, including health information, in response to a Google review. The authority found a breach of confidentiality and of the security obligations under the GDPR. | ES | AEPD | GDPR | €7,000 | ↗ |
| 12 May 2022 | Azienda Socio Sanitaria Territoriale Dei Sette LaghiAzienda Socio Sanitaria Territoriale Dei Sette Laghi was fined by the Garante €7,000 for violations related to the processing of health data. The authority also found insufficient data security measures. | IT | Garante | GDPR | €7,000 | ↗ |
| 25 Mar 2021 | TECNOMEDICAL S.r.l.TECNOMEDICAL S.r.l. was fined by the Garante for violating data protection rules related to the processing of health data. The case concerned non-compliance in the handling of sensitive personal data. | IT | Garante | GDPR | €7,000 | ↗ |
| 01 Dec 2017 | BILUA E-COMMERCE S.L (CARETHY y BIUKY)BILUA E-COMMERCE S.L. was fined by the AEPD EUR 7,000 for sending unsolicited commercial emails. The messages were sent despite the recipient's request to unsubscribe, which breached Article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €7,000 | ↗ |
| 01 Jan 2012 | MAIL MARKETING SERVICIOS INFORMATICOS, S.LMAIL MARKETING SERVICIOS INFORMATICOS, S.L was fined by the AEPD in the amount of 7,000 EUR for sending unsolicited commercial emails. The case concerned a breach of Article 21 of the LSSI, which governs electronic marketing communications. | ES | AEPD | ePrivacy | €7,000 | ↗ |
| 15 Mar 2022 | CLÍNICA DENTAL SAN FRANCISCO, S.L.The entity continued sending advertising messages to a former patient despite multiple requests to unsubscribe. AEPD found this to be a breach of data protection rules and imposed a EUR 7,000 fine. | ES | AEPD | ePrivacy | €7,000 | ↗ |
| 02 Dec 2021 | Società Med Store Saronno s.r.l.The Garante fined Società Med Store Saronno s.r.l. EUR 7,000 for inadequate data protection measures. The authority found insufficient password security and no HTTPS protocol, affecting personal health data. | IT | Garante | GDPR | €7,000 | ↗ |