BULLETIN №083Last updated · 06 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -22.8%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 31 Oct 2022 | FACTOR ENERGÍA, S.A.FACTOR ENERGÍA, S.A. was fined by the AEPD EUR 40,000 for sending personalized marketing messages using personal data without a legal basis. The authority found a breach of Article 6(1) of the GDPR. | ES | AEPD | GDPR | €40,000 | ↗ |
| 13 Feb 2024 | FACTOR ENERGÍA, S.A.FACTOR ENERGÍA, S.A. was fined by the AEPD 6,000 EUR for processing personal data without a legal basis, in breach of Article 6(1) GDPR. The company failed to communicate the termination of a gas contract and improperly shared personal data with other companies. | ES | AEPD | GDPR | €6,000 | ↗ |
| 11 Apr 2024 | Facile.Energy S.r.l.Facile.Energy S.r.l. was fined EUR 100,000 by the Garante for making unsolicited promotional calls without prior consent and activating energy supplies without a request from the customer. The authority found that these practices breached GDPR rules on data protection and security measures. | IT | Garante | GDPR | €100,000 | ↗ |
| 05 Feb 2025 | FacharztThis case concerns a confirmed fine by the Austrian Federal Administrative Court (BVwG) against Facharzt for disclosing health data in an online review. The conduct indicates a breach of personal data protection rules involving medical information. | AT | Bundesverwaltungsgericht (BVwG) | GDPR | €4,500,000 | ↗ |
| 14 Jun 2019 | Facebook Ireland Ltd e Facebook Italy s.r.l.Facebook Ireland Ltd and Facebook Italy s.r.l. were fined EUR 1,000,000 by the Garante for violations involving the unauthorized sharing of user data with the application “Thisisyourdigitallife”. The case affected approximately 214,020 users. | IT | Garante | GDPR | €1,000,000 | ↗ |
| 14 Feb 2013 | Face2Face s.r.l.Face2Face s.r.l. was fined EUR 40,000 by the Italian data protection authority, Garante. The authority found that the company failed to provide the required privacy notice and did not obtain specific consent from data subjects before processing their data. | IT | Garante | GDPR | €40,000 | ↗ |
| 17 May 2023 | Fabio Giovanni PettaFabio Giovanni Petta was fined by the Garante 60,000 EUR for the unauthorized publication of personal data, including names, addresses, and phone numbers, on www.trovanumeri.com. The authority also noted continued processing of the data despite a prior prohibition. The case constitutes a GDPR violation. | IT | Garante | GDPR | €60,000 | ↗ |
| 15 Jun 2017 | F2F Communications s.r.l.F2F Communications s.r.l. was fined by the Garante 16,000 EUR for making unsolicited promotional calls. The authority found that the required privacy notice was not provided and consent was not obtained, in breach of data protection rules. | IT | Garante | GDPR | €16,000 | ↗ |
| 15 Jun 2017 | F2F Communications s.r.l.F2F Communications s.r.l. was fined by the Garante in the amount of 10,000 EUR for making unsolicited promotional calls to a number listed in the public opposition registry. The conduct breached data protection rules and the right to object to direct marketing. | IT | Garante | GDPR | €10,000 | ↗ |
| 21 Sept 2023 | F12 Management LtdF12 Management Ltd made 1,346,019 marketing calls to individuals in breach of regulation 21 of PECR. The ICO imposed a £200,000 fine and issued an enforcement notice. | GB | ICO | ePrivacy | €230,000 | ↗ |
| 29 Aug 2025 | EXTRA MADRID, S.L.EXTRA MADRID, S.L. sent personalized postal advertising without the recipient’s consent. The AEPD found this to be a breach of Article 6 GDPR and imposed a fine of 1,000 EUR. | ES | AEPD | GDPR | €1,000 | ↗ |
| 24 Dec 2022 | EXPLOTACIONES HOSTELERAS Y DE OCIO ALBACETEÑAS, S.L.The entity was fined by the AEPD for breaching data protection rules. Its surveillance cameras were positioned to capture public areas without proper legal authorization. | ES | AEPD | GDPR | €500 | ↗ |
| 17 Oct 2025 | Experian Nederland B.V.Experian Nederland B.V. was fined by the AP €2,700,000 for failing to adequately inform data subjects and for processing personal data without a valid legal basis. The case concerns breaches of the GDPR principles of transparency and lawful processing. | NL | AP | GDPR | €2,700,000 | ↗ |
| 01 Oct 2023 | ExperianThe Dutch data protection authority, Autoriteit Persoonsgegevens, imposed a fine of €2.7 million on Experian. The case concerns a GDPR violation by the credit company. | NL | Autoriteit Persoonsgegevens | GDPR | €2,700,000 | ↗ |
| 07 Aug 2024 | EXPANSION CONSULTING 2020, S.L.EXPANSION CONSULTING 2020, S.L. was fined by the AEPD in the amount of €4,000 for failing to provide access to personal data and the information requested by the data protection authority. The case concerned non-compliance with Article 58(1) GDPR. | ES | AEPD | GDPR | €4,000 | ↗ |
| 04 Mar 2024 | EXESRIVAS GESTIÓN PATRIMONIALThe entity sent unsolicited commercial messages via WhatsApp despite the complainant's explicit refusal to receive such communications. AEPD found a breach of Article 21 of the LSSI and imposed a 300 EUR fine. | ES | AEPD | ePrivacy | €300 | ↗ |
| 01 Jan 2024 | EXCEL HOTELS & RESORTS, S.A.EXCEL HOTELS & RESORTS, S.A. was fined by the AEPD 40,000 EUR for leaving property owners’ personal data unattended, including ID and passport numbers. The authority found that this created unauthorized access to sensitive personal information and breached data protection principles. | ES | AEPD | GDPR | €40,000 | ↗ |
| 01 Jun 2023 | Ew Business Machines S.p.A.Ew Business Machines S.p.A. was fined 20,000 EUR by the Garante. The authority found that the company used a surveillance system without proper notice, collected employee fingerprints, and tracked employee locations through mobile apps without adequate transparency. | IT | Garante | GDPR | €20,000 | ↗ |
| 24 Jan 2013 | Evolution chirurgia estetica s.r.l.Evolution chirurgia estetica s.r.l. was fined 10,000 EUR by the Garante. The authority found that the website contact form required mandatory acceptance of the privacy notice, which breached consent requirements under the Italian privacy code. | IT | Garante | GDPR | €10,000 | ↗ |
| 11 Feb 2016 | E-Via s.p.a.E-Via s.p.a. was fined 10,000 EUR by the Garante for failing to implement minimum security measures in the processing of telematic traffic data. The authority found a breach of Article 33 of the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |