BULLETIN №083Last updated · 06 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -22.8%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 15 Feb 2018 | Genova Car Sharing SrlGenova Car Sharing Srl was fined EUR 46,000 by the Garante. The authority found that customers were not fully informed about vehicle geolocation and that separate consent was not obtained for newsletter communications. | IT | Garante | GDPR | €46,000 | ↗ |
| 14 Nov 2014 | Geniki TrapezaThe bank failed to ensure the accuracy of personal data and did not respond adequately to a data access request. The case concerns breaches of data quality obligations and the handling of data subject rights. | GR | HDPA | GDPR | €30,000 | ↗ |
| 06 Feb 2014 | Genesis Consulting s.r.l.Genesis Consulting s.r.l. was fined EUR 4,000 by the Garante. The authority found that personal data collected through a website form were used for marketing purposes without adequate notice and without specific consent. | IT | Garante | GDPR | €4,000 | ↗ |
| 09 Aug 2013 | General Secretariat for Information SystemsThe General Secretariat for Information Systems was fined EUR 150,000 by the HDPA for failing to implement appropriate security measures. The breach led to unauthorized processing of Greek taxpayers’ personal tax data from 2000 to 2012. | GR | HDPA | GDPR | €150,000 | ↗ |
| 11 Jul 2018 | General Market di E. Barcio & Fratelli s.n.c.General Market di E. Barcio & Fratelli s.n.c. was fined by the Garante 7,200 EUR for failing to provide adequate information to people entering its stores about data processing through video surveillance systems. The authority found that the required notice obligations for monitored individuals were not met. | IT | Garante | GDPR | €7,200 | ↗ |
| 01 Jan 2023 | GENERAL LOGISTICS SYSTEMS SPAIN, S.A.GENERAL LOGISTICS SYSTEMS SPAIN, S.A. was fined by the AEPD 140,000 EUR for processing the personal data of two complainants without proper authorization. The breach resulted in identity theft and misuse of personal data. | ES | AEPD | GDPR | €140,000 | ↗ |
| 26 May 2014 | General Hospital PapageorgiouGeneral Hospital Papageorgiou was fined EUR 1,000 by the HDPA for transferring sensitive health data without prior authorization. The hospital also failed to inform the data subject, breaching Greek data protection law. | GR | HDPA | GDPR | €1,000 | ↗ |
| 17 Nov 2023 | Gemeente VoorschotenThe municipality of Voorschoten unlawfully processed personal data about residents’ waste disposal history without a sufficient legal basis. It also failed to properly inform the affected residents, breaching GDPR Articles 5, 6 and 14. | NL | AP | GDPR | €30,000 | ↗ |
| 05 Feb 2026 | Gemeente HilversumThe Autoriteit Persoonsgegevens found that Gemeente Hilversum processed personal data without a valid legal basis during an investigation into Muslim residents and organizations. The municipality accepted an administrative fine of 25,000 EUR and acknowledged responsibility. | NL | Autoriteit Persoonsgegevens | GDPR | €25,000 | ↗ |
| 29 Apr 2021 | Gemeente EnschedeThe municipality of Enschede was fined by AP for processing personal data of mobile device owners and users without a legal basis. The authority found violations of GDPR Articles 5 and 6. | NL | AP | GDPR | €600,000 | ↗ |
| 05 Feb 2026 | Gemeente DelftGemeente Delft processed personal data without a sufficient legal basis. It also processed special categories of personal data without a valid exception, breaching GDPR principles. | NL | AP | GDPR | €25,000 | ↗ |
| 24 Nov 2011 | Gema s.p.a.Gema s.p.a. was fined by the Italian data protection authority, Garante, for failing to provide the required data protection information to users and entities through its website. The authority also found that the company used a video surveillance system without proper notification, in breach of the Italian Data Protection Code. | IT | Garante | GDPR | €22,000 | ↗ |
| 13 May 2015 | Gelpi Elettrodomestici S.r.l.Gelpi Elettrodomestici S.r.l. was fined 30,000 EUR by the Garante. The case concerned the activation of SIM cards in individuals' names without their knowledge, which breached data protection rules. | IT | Garante | GDPR | €30,000 | ↗ |
| 27 Apr 2023 | Geico S.p.A.Geico S.p.A. was fined 40,000 EUR by the Garante for keeping former employees' email accounts active after the employment relationship ended. The authority found that the company accessed the contents of those accounts in breach of GDPR requirements. | IT | Garante | GDPR | €40,000 | ↗ |
| 29 Sept 2021 | GEDI News Network S.p.A.GEDI News Network S.p.A. was fined 30,000 EUR by the Garante for publishing personal data and detailed information about an individual involved in a workplace accident. The authority found a breach of data protection rules. | IT | Garante | GDPR | €30,000 | ↗ |
| 31 Aug 2023 | GEDI News Network S.p.a.The Garante imposed a EUR 30,000 fine on GEDI News Network S.p.a. for publishing a photo of minors with insufficient pixelation, making them identifiable. The authority found this to be a breach of data protection rules concerning children. | IT | Garante | GDPR | €30,000 | ↗ |
| 25 Mar 2021 | GEDI News Network S.p.a.GEDI News Network S.p.a. was fined by the Italian data protection authority, Garante, in the amount of EUR 20,000. The case concerned failure to comply with a request to delete personal data from an article about a 1998 legal case, which remained prejudicial because the outcome was not updated. | IT | Garante | GDPR | €20,000 | ↗ |
| 01 Jan 2015 | GEDESCO SERVICES SPAIN, S.A.GEDESCO SERVICES SPAIN, S.A. was fined EUR 7,000 by the AEPD for sending unsolicited commercial communications by email and SMS. This conduct breached Article 21 of the LSSI. | ES | AEPD | ePrivacy | €7,000 | ↗ |
| 24 May 2022 | Geanonimiseerd (APD 84/2022)The case concerns a complaint by the Ordre des Barreaux Francophones de Belgique against sos-services.be and sos-avocats.be. The authority found that lawyers were listed without a legal basis and with incorrect information, in breach of GDPR and ePrivacy rules. | BE | APD | ePrivacy | €10,000 | ↗ |
| 29 Sept 2020 | Geanonimiseerd (APD 64/2020)The Litigation Chamber fined the data controller for failing to close email accounts after employees left the company. The authority found breaches of GDPR principles of purpose limitation, data minimization, and storage limitation. | BE | APD | GDPR | €5,000 | ↗ |