BULLETIN №082Last updated · 03 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 25 Jul 2013 | Fast-typeFast-type was fined EUR 500 by the HDPA for sending unsolicited marketing emails without subscriber consent. The case concerns a failure to obtain prior consent for marketing communications. | GR | HDPA | ePrivacy | €500 | ↗ |
| 23 Jun 2025 | Piraeus Bank S.A.Piraeus Bank S.A. was fined by the HDPA 50,000 EUR for unlawfully transferring personal data to third parties without the data subject's consent. The authority found breaches of GDPR principles of lawfulness and accuracy. | GR | HDPA | GDPR | €50,000 | ↗ |
| 16 Jun 2010 | Anonymised (HDPA 29/2010)The company was fined 3,000 EUR by the HDPA for unlawfully processing email addresses without prior consent. This conduct breached Greek data protection law. | GR | HDPA | GDPR | €3,000 | ↗ |
| 08 Aug 2014 | Anonymised (HDPA 112/2014)The controller sent unsolicited marketing SMS messages without recipients' consent, breaching data protection rules. The case concerned the use of contact data for marketing without a valid legal basis. | GR | HDPA | ePrivacy | €1,000 | ↗ |
| 09 Jan 2025 | National Bank of GreeceNational Bank of Greece was fined €20,000 by the HDPA. The authority found that the bank failed to provide data subjects with timely access to their personal data, breaching GDPR Articles 15 and 12. | GR | HDPA | GDPR | €20,000 | ↗ |
| 09 Oct 2018 | CosmoteCosmote was fined EUR 150,000 by the HDPA for making unsolicited promotional calls to subscribers who had opted out of such contact. The authority found that this conduct breached privacy and personal data protection rules. | GR | HDPA | ePrivacy | €150,000 | ↗ |
| 21 Feb 2017 | MILI CAFEMILI CAFE was fined EUR 1,000 for unlawful video surveillance practices. The violations included recording audio without proper security measures and retaining footage for more than 15 days. | GR | HDPA | GDPR | €1,000 | ↗ |
| 15 Feb 2022 | Organismos Limenos Irakleiou A.E.Organismos Limenos Irakleiou A.E. was fined 30,000 EUR by the HDPA for breaching the data subject’s right of access. The company failed to provide requested video footage and incorrectly claimed that the data had been deleted. | GR | HDPA | GDPR | €30,000 | ↗ |
| 22 Sept 2022 | Anonymised (HDPA 51/2022)The fined entity did not comply with a data subject access request and did not provide any justification for failing to act on it. It also failed to inform the data subject about further processing and the transfer of their data to the police. | GR | HDPA | GDPR | €3,000 | ↗ |
| 12 Jun 2015 | ALPHA BANKALPHA BANK was fined 30,000 EUR by the HDPA. The authority found that the bank failed to notify the location and facilities used for ICAP data processing. | GR | HDPA | GDPR | €30,000 | ↗ |
| 12 Jun 2015 | Tiresias AETiresias AE was fined for failing to implement measures to control access to personal data files. This failure led to unauthorized access by ICAP. | GR | HDPA | GDPR | €30,000 | ↗ |
| 30 Mar 2023 | Vodafone-PanafonVodafone-Panafon was fined by the HDPA for failing to respond to a data subject access request concerning recorded calls. The authority also found that the company did not notify a personal data breach to the regulator. | GR | HDPA | GDPR | €40,000 | ↗ |
| 25 Sept 2025 | JacksonsThe ODPA fined Jacksons £65,000 after finding that the company unlawfully changed customer marketing preferences. The investigation identified anomalies in customer records and direct marketing communications made against customers’ wishes. | GG | ODPA | GDPR | €74,302 | ↗ |
| 20 Oct 2025 | The Medical Specialist GroupThe Medical Specialist Group LLP reported a personal data breach after suspicious emails indicated that cyber criminals had accessed its mail server. An internal investigation found the server had been compromised in August 2021 through multiple vulnerabilities, allowing access to and theft of stored emails containing personal data. | GG | ODPA | GDPR | €115,000 | ↗ |
| 21 Sept 2023 | F12 Management LtdF12 Management Ltd made 1,346,019 marketing calls to individuals in breach of regulation 21 of PECR. The ICO imposed a £200,000 fine and issued an enforcement notice. | GB | ICO | ePrivacy | €230,000 | ↗ |
| 24 Apr 2025 | Darian Bishop trading as ECO4UBetween 9 January 2023 and 9 October 2023, 194,110 unsolicited direct marketing calls were made to subscribers registered with the TPS who had not indicated consent to receive such calls. The conduct generated 21 complaints to the Commissioner and the TPS, leading to an ICO fine. | GB | ICO | GDPR | €58,480 | ↗ |
| 15 Aug 2024 | Coastal Windows & Conservatories (UK) LimitedCoastal Windows & Conservatories (UK) Limited made more than 18,000 unsolicited marketing calls between 1 January and 1 June 2023 to numbers registered with the TPS. The ICO and TPS received numerous complaints from people who said they had not consented to the calls or continued to receive them after asking for the calls to stop. | GB | ICO | GDPR | €46,720 | ↗ |
| 15 Feb 2023 | It's OK LimitedBetween 1 July 2019 and 1 June 2020, It's OK Limited made 1,752,149 unsolicited direct marketing calls to subscribers who had been registered with the TPS for at least 28 days. The company had no evidence that the recipients had not objected to receiving such calls, breaching regulation 21 of PECR. | GB | ICO | ePrivacy | €225,000 | ↗ |
| 10 Oct 2024 | Service Box Group LimitedService Box Group Limited made 5,361 marketing calls to individuals in breach of regulation 21 of PECR. The ICO imposed a fine of GBP 40,000 and issued an enforcement notice. | GB | ICO | ePrivacy | €47,796 | ↗ |
| 01 Oct 2023 | Capita plc and CPSLThe Information Commissioner's Office imposed a GBP 2,000,000 fine on Capita plc and CPSL. The case concerned data protection breaches linked to unsolicited marketing calls, indicating improper use of contact data. | GB | Information Commissioner's Office | GDPR | €2,313,000 | ↗ |