BULLETIN №082Last updated · 01 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.1%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 01 Jan 2023 | B.B.B.The entity used a video from a training session containing the complainant’s personal statements without consent. The material was used for marketing purposes to attract new clients, which constituted a breach of data protection rules. | ES | AEPD | GDPR | €10,000 | ↗ |
| 01 Jan 2023 | VACACIONES EDREAMS, S.L.VACACIONES EDREAMS, S.L. was fined by the AEPD in the amount of 10,000 EUR for failing to provide access to personal data upon a customer request. The authority found a breach of Article 15 of the GDPR. | ES | AEPD | GDPR | €10,000 | ↗ |
| 09 Apr 2024 | ADNAYA GREEN SOLUTIONS, S.L.ADNAYA GREEN SOLUTIONS, S.L. was fined by the AEPD EUR 10,000 for unlawfully sharing personal data with a third party without consent. The authority found this conduct breached Article 6(1) of the GDPR. | ES | AEPD | GDPR | €10,000 | ↗ |
| 05 Mar 2015 | Comune di CapaccioComune di Capaccio was fined for unlawfully publishing sensitive personal data revealing health conditions on its institutional website. The authority found this to be a breach of privacy and data protection rules. | IT | Garante | GDPR | €10,000 | ↗ |
| 09 Jun 2022 | Cribis Credit Management s.r.l.Cribis Credit Management s.r.l. was fined 10,000 EUR by the Garante. The authority found that the company unjustifiably communicated debtor information to third parties, in breach of GDPR Article 5. | IT | Garante | GDPR | €10,000 | ↗ |
| 16 Jun 2023 | BORSA MEDIC, S.L.BORSA MEDIC, S.L. was fined 10,000 EUR by the AEPD for failing to comply with a data deletion request and for sending unsolicited advertising emails after the recipient objected. The case concerns breaches of data protection and electronic commerce rules. | ES | AEPD | ePrivacy | €10,000 | ↗ |
| 08 Jan 2015 | CHRYSOS ODIGOS ENTYPH & HLEKTRONIKI PLHROFORISI A.E.The company was fined by the HDPA EUR 10,000 for processing personal data without consent. The authority also found that it failed to respond to data subjects' requests for access and objection. | GR | HDPA | GDPR | €10,000 | ↗ |
| 11 Feb 2021 | Azienda Unità Sanitaria Locale di ParmaAzienda Unità Sanitaria Locale di Parma was fined by the Garante €10,000 for improper handling of sensitive personal data. The violation was linked to an occasional malfunction of its IT system, which led to improper data processing. | IT | Garante | GDPR | €10,000 | ↗ |
| 26 Nov 2024 | AD735 DATA MEDIA ADVERTISING, S.L.AD735 DATA MEDIA ADVERTISING, S.L. was fined by the AEPD EUR 10,000 for sending unsolicited advertising emails. The messages were sent despite the recipient's unsubscribe request and inclusion on the Robinson list, breaching the LSSI. | ES | AEPD | ePrivacy | €10,000 | ↗ |
| 06 Oct 2022 | Poste Italiane S.p.a.Poste Italiane S.p.a. was fined by the Garante in the amount of 10,000 EUR for failing to respond to a data access request. The authority found a breach of Article 15 of the GDPR. | IT | Garante | GDPR | €10,000 | ↗ |
| 19 Mar 2015 | Provincia di PisaProvincia di Pisa was fined €10,000 by the Garante. The authority found that employees at the employment center were not designated as data processing officers, resulting in insufficient security measures for handling personal data. | IT | Garante | GDPR | €10,000 | ↗ |
| 01 Jan 2024 | ESCOLA LES CAROLINES COOP. V.The school was fined by the AEPD 10,000 EUR for processing a minor’s image without a lawful basis. The child’s photograph was displayed on posters inside the school premises, which was found to breach GDPR Article 6(1). | ES | AEPD | GDPR | €10,000 | ↗ |
| 01 Jan 2020 | CENTRO DE DIAGNÓSTICO ***LOCALIDAD.1, S.A.The entity was fined for breaching data confidentiality by improperly sharing medical information between different entities without consent. The case involved sensitive data processing and a lack of a valid legal basis for the disclosure. | ES | AEPD | GDPR | €10,000 | ↗ |
| 03 Mar 2025 | BEKO ROMÂNIA SAIn February 2025, ANSPDCP completed an investigation at BEKO ROMÂNIA SA and found violations of GDPR provisions. As a result, the controller was fined EUR 10,000. | RO | ANSPDCP | GDPR | €10,000 | ↗ |
| 28 Mar 2023 | SOCIETE DE MARKETING (procédure simplifiée)CNIL imposed a fine of EUR 10,000 on SOCIETE DE MARKETING and issued an injunction. The case was handled under a simplified procedure. | FR | CNIL | GDPR | €10,000 | ↗ |
| 11 Jul 2019 | Thomas N****The individual secretly recorded video footage of two women in a changing room without their consent. The DSB found this to be a breach of GDPR rules on lawful processing and consent. | AT | DSB | GDPR | €10,000 | ↗ |
| 29 May 2019 | Regione PugliaRegione Puglia was fined by the Garante 10,000 EUR for unlawfully publishing personal data of participants in a selection process on its official website. The disclosure included tax codes and income data, breaching privacy rights. | IT | Garante | GDPR | €10,000 | ↗ |
| 01 Apr 2025 | BitdefenderBitdefender received a GDPR fine of EUR 10,000 from the Romanian data protection authority. The sanction followed an investigation completed in April 2025 after a data breach notification, with the authority citing inadequate technical and organizational security measures. | RO | Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal | — | €10,000 | ↗ |
| 19 Feb 2015 | Comune di CampotostoComune di Campotosto was fined by the Garante for unlawfully publishing personal data revealing health information on its website. The case concerned a breach of privacy and personal data protection rules. | IT | Garante | GDPR | €10,000 | ↗ |
| 05 Mar 2015 | Istituto Professionale di Stato per i Servizi Commerciali Turistici Alberghieri "Cesare Musatti"The Istituto Professionale di Stato per i Servizi Commerciali Turistici Alberghieri “Cesare Musatti” was fined by the Italian data protection authority, Garante, in the amount of €10,000. The violation involved unlawfully publishing personal data on its website that revealed students’ health status. | IT | Garante | GDPR | €10,000 | ↗ |