BULLETIN №083Last updated · 06 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -22.8%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 23 Jan 2023 | FRESHLY COSMETICS, S.L.FRESHLY COSMETICS, S.L. was fined EUR 5,000 by the AEPD for failing to provide a cookie notice on its website. The authority also found that non-essential cookies were used without prior user consent, in breach of Article 22.2 of the LSSI. | ES | AEPD | ePrivacy | €5,000 | ↗ |
| 24 Apr 2013 | Free Time s.r.l.Free Time s.r.l. was fined EUR 54,000 by the Italian Garante. The case concerned the registration of numerous phone cards to unaware third parties without providing the required information on data processing. | IT | Garante | GDPR | €54,000 | ↗ |
| 24 Jul 2024 | FREE TECHNOLOGIES EXCOM, S.L.FREE TECHNOLOGIES EXCOM, S.L. was fined by the AEPD 10,000 EUR for sending unencrypted emails containing user credentials without prior notice. The authority also noted the absence of two-factor authentication, which constituted a breach of Article 32 GDPR. | ES | AEPD | GDPR | €10,000 | ↗ |
| 13 Jan 2026 | Free Mobile and FreeFrance’s CNIL fined Free Mobile and Free a combined EUR 42 million for GDPR breaches linked to a 2024 data breach affecting more than 24 million users. The regulator found inadequate security measures and said Free Mobile unlawfully retained former subscribers’ data. | FR | Commission nationale de l’informatique et des libertés | GDPR | €42,000,000 | ↗ |
| 16 Dec 2021 | Frederiksberg KommuneFrederiksberg Kommune was fined by Datatilsynet for failing to implement adequate security measures in a self-service solution. This led to unauthorized access to protected personal data. | DK | Datatilsynet | GDPR | €6,724 | ↗ |
| 20 Mar 2008 | Frareg s.r.l.Frareg s.r.l. was fined by the Garante for sending advertising material by fax without providing prior and adequate information to recipients. The authority found this to be a breach of data protection rules. | IT | Garante | GDPR | €3,000 | ↗ |
| 23 Oct 2025 | Franco SpellecchiaFranco Spellecchia was fined by the Garante for installing a video surveillance system around his residence without the required legal basis. The authority found that the setup breached GDPR rules, including the absence of a legitimate interest or authorization. | IT | Garante | GDPR | €500 | ↗ |
| 20 Mar 2014 | Franco Oro più srlFranco Oro più srl was fined EUR 4,800 by the Italian Garante. The case concerned the failure to provide the required data protection information on both a paper form and the company website, in breach of the Italian Data Protection Code. | IT | Garante | GDPR | €4,800 | ↗ |
| 16 Oct 2013 | FRANCE TELECOM ESPAÑA, S.A.FRANCE TELECOM ESPAÑA, S.A. was fined by the AEPD for sending commercial emails to a complainant despite a request not to use personal data for advertising purposes. The authority found a breach of Article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €33,001 | ↗ |
| 22 Jan 2015 | Francesco Saverio ManesFrancesco Saverio Manes was fined by the Garante EUR 2,400 for failing to provide data subjects with the required information about the processing of personal data through a video surveillance system at the cultural club “K2”. The case concerned the absence of mandatory notices for individuals captured by the CCTV system. | IT | Garante | GDPR | €2,400 | ↗ |
| 17 Apr 2026 | Framos Italia s.r.l. in liquidazioneFramos Italia s.r.l. in liquidation was fined EUR 5,000 by the Garante. The authority found that former employees’ email accounts were not deactivated and that information on data processing was not clear and comprehensive. | IT | Garante | GDPR | €5,000 | ↗ |
| 04 Mar 2020 | Fotó készítése és közzététele Facebookon hozzájárulás nélkülThe authority found unlawful processing and publication of personal data without a valid legal basis. A fine was imposed and the image had to be deleted from Facebook. | HU | NAIH | GDPR | €299 | ↗ |
| 23 Nov 2017 | Foschini Mauro e Banca Nazionale del Lavoro S.p.A.Foschini Mauro and Banca Nazionale del Lavoro S.p.A. were fined by the Garante 4,000 EUR for breaches of data protection rules. The case concerned non-compliance with provisions of the Italian Privacy Code. | IT | Garante | GDPR | €4,000 | ↗ |
| 03 Oct 2013 | Forum Sport Center società sportiva dilettantistica S.r.l.Forum Sport Center società sportiva dilettantistica S.r.l. was fined by the Italian Garante in the amount of €8,400. The sanction concerned inadequate data protection notices for personal data collection and video surveillance systems. | IT | Garante | GDPR | €8,400 | ↗ |
| 21 Feb 2013 | Forum Media Edizioni s.r.l.Forum Media Edizioni s.r.l. was fined by the Italian Garante in the amount of €6,400. The case concerned the sending of unsolicited promotional faxes without the required information and without obtaining consent, in breach of Articles 13 and 130 of the Italian Data Protection Code. | IT | Garante | GDPR | €6,400 | ↗ |
| 28 Jun 2023 | Fortis Insolvency LimitedFortis Insolvency Limited sent 558,354 direct marketing SMS messages without valid consent, of which 527,481 were received by subscribers between 26 July 2020 and 26 July 2021. This breached regulation 22 of PECR. The company was fined £30,000 and issued with an enforcement notice. | GB | ICO | ePrivacy | €34,713 | ↗ |
| 28 Oct 2022 | FORMAESTUDIO, C.B.FORMAESTUDIO, C.B. was fined €6,000 by the AEPD for requiring students to disclose their COVID vaccination status and present a passport as a condition for participating in teaching practice. The authority found that this processing breached data protection rules. | ES | AEPD | GDPR | €6,000 | ↗ |
| 07 Aug 2023 | FORMACIÓN Y EMPLEO DE EXTREMADURA, S.L.The company sent emails to multiple recipients without using BCC, allowing each recipient to see the other recipients’ email addresses. AEPD treated this as a breach of data protection rules and imposed an 8,000 EUR fine. | ES | AEPD | GDPR | €8,000 | ↗ |
| 29 Jun 2023 | FORKMERGE S.L.FORKMERGE S.L. was fined by the AEPD EUR 2,000 for failing to comply with a data subject’s request to remove personal data from search engine results. The authority found this to be a breach of Article 17 GDPR. | ES | AEPD | GDPR | €2,000 | ↗ |
| 10 Jun 2021 | Foodinho s.r.l.Foodinho s.r.l. was fined by the Garante EUR 2,600,000 for violations in the processing of riders’ personal data. The authority cited insufficient data minimization, inadequate privacy by design measures, and automated decision-making without proper human intervention. | IT | Garante | GDPR | €2,600,000 | ↗ |