BULLETIN №083Last updated · 08 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.6%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 13 Jul 2022 | GRUPO TRANSAHER, S.L.GRUPO TRANSAHER, S.L. was fined by the AEPD 50,000 EUR for installing surveillance cameras in employee rest areas. The authority found that the company did not properly inform employees and may have infringed their privacy under the GDPR. | ES | AEPD | GDPR | €50,000 | ↗ |
| 14 Jul 2022 | SIRIUS advokaterSIRIUS advokater was recommended a fine of DKK 500,000 by Datatilsynet for failing to implement basic security measures. The deficiencies led to a data breach in which sensitive personal data was compromised during a hacking incident. | DK | Datatilsynet | GDPR | €67,180 | ↗ |
| 15 Jul 2022 | URBANO DIVERTIA, S.L.URBANO DIVERTIA, S.L. was fined by the AEPD 2,000 EUR for sending clients documents that contained personal data of third parties. The company also failed to include a reference to its privacy policy in corporate emails, which breached data protection requirements. | ES | AEPD | GDPR | €2,000 | ↗ |
| 15 Jul 2022 | FEDERACIÓN DE ATENCIÓN A LA CIUDADANÍA DE LA UNIÓN SINDICAL OBRERA (FAC-USO)The organization continued sending emails to an individual after they requested deletion of their personal data. The AEPD found a breach of Article 6 of the GDPR and imposed a EUR 3,000 fine. | ES | AEPD | GDPR | €3,000 | ↗ |
| 15 Jul 2022 | BANCO BILBAO VIZCAYA ARGENTARIA, S.A.The bank was fined for requesting a disproportionate amount of personal data, including a copy of the DNI, to process a request for information about account movements. The authority found this to be a breach of the data minimization principle. | ES | AEPD | GDPR | €70,000 | ↗ |
| 21 Jul 2022 | Comune di GinosaComune di Ginosa was fined EUR 5,000 by the Garante for violations related to the processing of personal data in the whistleblowing context. The authority found that an adequately high level of confidentiality and protection for the data subjects was not ensured. | IT | Garante | GDPR | €5,000 | ↗ |
| 21 Jul 2022 | Global Service s.r.l.Global Service s.r.l. was fined by the Garante EUR 2,000 for installing a video surveillance system without the required informational signage. The case concerned a breach of data protection rules and the duty to properly inform individuals under surveillance. | IT | Garante | GDPR | €2,000 | ↗ |
| 21 Jul 2022 | WUNSCHURLAUB S.L.WUNSCHURLAUB S.L. was fined by the AEPD 3,000 EUR for storing user passwords in plain text and sending them by email without encryption. The authority found this breached GDPR Article 32 on appropriate security measures. | ES | AEPD | GDPR | €3,000 | ↗ |
| 21 Jul 2022 | Stay Over s.r.l.Stay Over s.r.l. was fined by the Garante EUR 10,000 for a delayed and inadequate response to a data access request. The authority also found unlawful processing of a former employee's email account after employment ended. | IT | Garante | GDPR | €10,000 | ↗ |
| 21 Jul 2022 | Clio s.r.l.Clio s.r.l. was fined by the Italian Garante in the amount of 10,000 EUR for violations related to personal data processing. The case involved inadequate protection of whistleblower identities, in breach of the GDPR and national privacy code provisions. | IT | Garante | GDPR | €10,000 | ↗ |
| 21 Jul 2022 | Azienda Socio Sanitaria Territoriale RhodenseAzienda Socio Sanitaria Territoriale Rhodense was fined by the Garante EUR 3,000 for violations of data protection rules. The case concerned data breaches and inadequate security measures. | IT | Garante | GDPR | €3,000 | ↗ |
| 21 Jul 2022 | Acqua Novara.VCO S.p.a.Acqua Novara.VCO S.p.a. was fined EUR 20,000 by the Garante for breaches related to the processing of personal data. The case concerned confidentiality and the risks arising from handling sensitive data in a workplace context. | IT | Garante | GDPR | €20,000 | ↗ |
| 22 Jul 2022 | MAX2PROTECT, S.L.MAX2PROTECT, S.L. was fined EUR 4,000 by the AEPD for sending commercial emails without the required authorization. The case concerned a breach of Article 21 of the LSSI and involved unauthorized marketing communications. | ES | AEPD | ePrivacy | €4,000 | ↗ |
| 23 Jul 2022 | GESTIONES AUTO LOW COST S. LThe entity was fined for not having a privacy policy on its website. The breach concerned Article 13 of the GDPR, which requires specific information to be provided to data subjects. | ES | AEPD | GDPR | €1,000 | ↗ |
| 25 Jul 2022 | MZN HELLAS A.E.The company was fined for sending unsolicited SMS messages for marketing purposes despite the recipient's objection. This conduct breached GDPR rules on personal data processing and direct marketing. | GR | HDPA | GDPR | €5,000 | ↗ |
| 28 Jul 2022 | Ordinanza ingiunzione - 28 luglio 2022 [9813385]The Garante imposed a fine of EUR 1,000 on the website administrator for failing to remove or de-index a page containing a Corriere della Sera article about a judicial case involving the complainant's father. The authority found a violation of the right to be forgotten. | IT | Garante | GDPR | €1,000 | ↗ |
| 28 Jul 2022 | Auto Hi-Fi System S.n.cAuto Hi-Fi System S.n.c was fined EUR 2,000 by the Garante. The surveillance camera captured public areas and private property without proper notice, breaching data protection principles. | IT | Garante | GDPR | €2,000 | ↗ |
| 28 Jul 2022 | Intesa Sanpaolo S.p.a.Intesa Sanpaolo S.p.a. was fined EUR 100,000 by Garante after an employee accessed a customer's financial data without authorization. The data was then used in judicial proceedings. The authority found that the bank had not implemented adequate data protection measures. | IT | Garante | GDPR | €100,000 | ↗ |
| 29 Jul 2022 | LA CASA DEL BAMBÚLA CASA DEL BAMBÚ was fined €200 by the AEPD for continuing to send marketing emails to a customer after an unsubscribe request. The authority found this to be a breach of Article 21 of the LSSI on unsolicited commercial communications. | ES | AEPD | ePrivacy | €200 | ↗ |
| 29 Jul 2022 | COMUNIDAD DE PROPIETARIOSA community of property owners was fined by the AEPD €300 for installing a surveillance camera without proper signage. The notice did not identify the data controller or provide contact details for exercising data subject rights. | ES | AEPD | GDPR | €300 | ↗ |