BULLETIN №083Last updated · 05 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -22.5%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 21 Dec 2023 | Gestioni Aziendali s.r.l.Gestioni Aziendali s.r.l. was fined by the Garante in the amount of 5,000 EUR for operating a video surveillance system at Hotel della Vittoria without appropriate informational signage. The authority found this to be a breach of GDPR transparency requirements toward monitored individuals. | IT | Garante | GDPR | €5,000 | ↗ |
| 23 Jul 2022 | GESTIONES AUTO LOW COST S. LThe entity was fined for not having a privacy policy on its website. The breach concerned Article 13 of the GDPR, which requires specific information to be provided to data subjects. | ES | AEPD | GDPR | €1,000 | ↗ |
| 06 Sept 2024 | GESTIÓN DE VENTAS IBERIA S.L.GESTIÓN DE VENTAS IBERIA S.L. was fined 4,000 EUR by the AEPD for failing to provide access as required under Article 58.1 of the GDPR. The case concerns non-compliance with a supervisory authority request. | ES | AEPD | GDPR | €4,000 | ↗ |
| 06 Feb 2024 | GESTIÓN DE PATRIMONIOS ANFIPOLIS SOCIEDAD DE RESPONSABILIDAD LIMITADAThe AEPD fined GESTIÓN DE PATRIMONIOS ANFIPOLIS SOCIEDAD DE RESPONSABILIDAD LIMITADA EUR 2,000 for sending unsolicited commercial communications without the recipient's consent. The authority noted that the messages were sent despite the recipient's opposition. | ES | AEPD | ePrivacy | €2,000 | ↗ |
| 07 Feb 2024 | GESTIÓN DE PATRIMONIOS ANFIPOLIS SOCIEDAD DE RESPONSABILIDAD LIMITADAThe entity was fined by the AEPD 4,000 EUR for failing to provide access to personal data and the information requested by the data protection authority. The case concerns non-compliance with Article 58.1 of the GDPR. | ES | AEPD | GDPR | €4,000 | ↗ |
| 08 Jan 2024 | GESTIÓN DE PATRIMONIOS ANFIPOLIS SL.The entity sent unsolicited commercial emails to an individual registered on the Robinson List. This breached Article 21 of the LSSI and led to a fine imposed by the AEPD. | ES | AEPD | ePrivacy | €2,000 | ↗ |
| 15 Nov 2022 | GESTIÓN DE PATRIMONIOS ANFIPOLIS SL.The entity was fined for sending unsolicited commercial emails despite the recipient's explicit objection. The authority found a breach of Article 21 of the LSSI. | ES | AEPD | ePrivacy | €2,000 | ↗ |
| 01 Jan 2019 | GESTIÓN DE COBROS, YO COBRO SLThe company was fined EUR 60,000 by the AEPD for unlawfully processing personal data. The breach involved sending debt collection emails to an institutional email address without consent, in violation of data protection rules. | ES | AEPD | GDPR | €60,000 | ↗ |
| 01 Jan 2013 | GESTION CONFIDENCIAL DESTRUPACK S LGESTION CONFIDENCIAL DESTRUPACK S L was fined by the AEPD 1,800 EUR for sending unsolicited commercial emails despite a prior request to unsubscribe. The authority found a breach of Article 21 of Spain’s LSSI. | ES | AEPD | ePrivacy | €1,800 | ↗ |
| 20 Dec 2019 | GESTHOTEL ACTIVOS BALAGARES S.L.GESTHOTEL ACTIVOS BALAGARES S.L. was fined by the AEPD 15,000 EUR for disclosing special categories of personal data, including medical information. The authority found a breach of the integrity and confidentiality principle under GDPR Article 5(1)(f). | ES | AEPD | GDPR | €15,000 | ↗ |
| 27 Sept 2010 | GESTEVISION TELECINCO, S.A.GESTEVISION TELECINCO, S.A. was fined by the AEPD 50,000 EUR for sending mass promotional SMS messages. The authority found that recipients were not given a simple and free way to object to the processing of their data for marketing purposes, in breach of Article 21.2 of the LSSI. | ES | AEPD | ePrivacy | €50,000 | ↗ |
| 01 Jan 2022 | GESTERPOOL, S.L.U.The AEPD imposed a 15,000 EUR fine on GESTERPOOL, S.L.U. for unauthorized use of personal data in a commercial call and for contract processing without consent. The case concerns breaches of GDPR rules, including Articles 28 and 58(1). | ES | AEPD | GDPR | €15,000 | ↗ |
| 01 Jan 2024 | GESTERNOVA, S.A.GESTERNOVA, S.A. was fined by the AEPD in the amount of 220,000 EUR for processing personal data without a valid legal basis. The authority also found that the company failed to provide the required information to the data subject, in breach of GDPR Articles 6(1), 13, and 14. | ES | AEPD | GDPR | €220,000 | ↗ |
| 14 Jun 2024 | GESCONSULT, S.A. S.G.I.I.C.GESCONSULT, S.A. S.G.I.I.C. was fined by the AEPD 5,000 EUR for processing personal data without a legal basis. The case involved recording a meeting and sharing the recording without proper consent. | ES | AEPD | GDPR | €5,000 | ↗ |
| 17 Mar 2021 | GERCO FIT, S.L.GERCO FIT, S.L. was fined by the AEPD in the amount of 2,000 EUR for processing personal data without proper consent. The authority found a breach of Article 6 of the GDPR. | ES | AEPD | GDPR | €2,000 | ↗ |
| 16 Jul 2025 | Georgescu CălinThe operator Georgescu Călin was fined by ANSPDCP in the amount of EUR 4,000 for violations of GDPR provisions. The case concerned non-compliance with personal data protection requirements. | RO | ANSPDCP | GDPR | €4,000 | ↗ |
| 24 Feb 2017 | Geoanalysis S.A.Geoanalysis S.A. was fined EUR 10,000 by the HDPA for improper installation and operation of a video surveillance system. The authority found data protection breaches, including failure to notify the authority and inadequate employee information. | GR | HDPA | GDPR | €10,000 | ↗ |
| 19 Jan 2024 | GEO ALTERNATIVA, S.L.GEO ALTERNATIVA, S.L. was fined by the AEPD for unlawfully processing personal data. The company included a customer's information in a credit file even though an agreement had already been reached regarding the disputed gas bill. | ES | AEPD | GDPR | €20,000 | ↗ |
| 08 May 2024 | Genpact România SRLThe ANSPDCP imposed a fine of EUR 3,000 on Genpact România SRL. The sanction concerned sending a file containing recruitment data to an unauthorized employee email address. The incident indicates a failure to control access to personal data and maintain confidentiality. | RO | ANSPDCP | GDPR | €3,000 | ↗ |
| 04 Feb 2026 | GENPACT ROMANIA SRLThe National Supervisory Authority for Personal Data Processing completed an investigation into GENPACT ROMANIA SRL and found a GDPR violation. The company was fined EUR 10,000 due to the severity of the circumstances. | RO | ANSPDCP | GDPR | €10,000 | ↗ |