BULLETIN №083Last updated · 08 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.6%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 31 Oct 2022 | B OEThe company was fined for violations related to the operation of a video surveillance system. The authority found non-compliance with data processing principles and insufficient data minimization. | GR | HDPA | GDPR | €10,000 | ↗ |
| 31 Oct 2022 | TECNO MOTOR LA MUELA, S.L.L.TECNO MOTOR LA MUELA, S.L.L. was fined by the AEPD €600 for installing surveillance cameras oriented toward public areas without prior administrative authorization. The authority treated this as a breach of data protection rules. | ES | AEPD | GDPR | €600 | ↗ |
| 31 Oct 2022 | FACTOR ENERGÍA, S.A.FACTOR ENERGÍA, S.A. was fined by the AEPD EUR 40,000 for sending personalized marketing messages using personal data without a legal basis. The authority found a breach of Article 6(1) of the GDPR. | ES | AEPD | GDPR | €40,000 | ↗ |
| 02 Nov 2022 | Dane anonimowe (Wójta Gminy U. za naruszenie przepisów art. 5 ust. 1 lit. f), art. 5 ust. 2, art. 25 ust. 1 oraz art. 32 ust. 1 i 2 rozporządzenia 2016/679)The Polish DPA (UODO) imposed an administrative fine of PLN 8,000 on the Mayor of U. Commune. The authority found that personal data were processed without adequate security, in breach of Articles 5, 25 and 32 of the GDPR. | PL | UODO | GDPR | €1,701 | ↗ |
| 02 Nov 2022 | QUALITY-PROVIDER S.A.QUALITY-PROVIDER S.A. was fined EUR 20,000 by the AEPD for processing personal data without a valid legal basis and for failing to comply with data deletion requests. The violations concerned Articles 6 and 17 of the GDPR. | ES | AEPD | GDPR | €20,000 | ↗ |
| 03 Nov 2022 | DKN.5131.18.2022StatusnieprawomocnaTytuUODO imposed an administrative fine of PLN 250,000 on the company. The authority found that the company failed to notify the supervisory authority within 24 hours of detecting the personal data breach and did not promptly inform the affected data subject. | PL | UODO | GDPR | €53,090 | ↗ |
| 03 Nov 2022 | FINCAS MARTIN 2, S.L.FINCAS MARTIN 2, S.L. was fined by the AEPD 5,000 EUR for failing to provide the information required under Article 13 GDPR when collecting personal data through a website contact form. The authority found that users were not properly informed about the processing of their data at the time of collection. | ES | AEPD | GDPR | €5,000 | ↗ |
| 07 Nov 2022 | Compania Națională Poșta Română SAIn October 2022, ANSPDCP completed an investigation into Compania Națională Poșta Română SA and found a breach of GDPR provisions. The company was fined EUR 2,000 following a data security incident reported by a data operator. | RO | ANSPDCP | GDPR | €2,000 | ↗ |
| 08 Nov 2022 | B.B.B.The entity installed a surveillance camera on the facade of a residence without the required administrative authorization. The camera captured public areas and the complainant’s home entrance, breaching data protection principles. | ES | AEPD | GDPR | €300 | ↗ |
| 08 Nov 2022 | SC Prestige Media PHG SRLSC Prestige Media PHG SRL was fined by ANSPDCP in the amount of 5,000 EUR for breaching the data processing principles under Article 5 of the GDPR. The case concerned unlawful processing of personal data. | RO | ANSPDCP | GDPR | €5,000 | ↗ |
| 09 Nov 2022 | SC Das Sense Society SRLSC Das Sense Society SRL was fined EUR 1,000 by ANSPDCP. The authority found a GDPR breach for failing to provide the requested information. | RO | ANSPDCP | GDPR | €1,000 | ↗ |
| 10 Nov 2022 | Sportitalia, società sportiva dilettantistica a responsabilità limitataSportitalia was fined €20,000 by the Italian supervisory authority, Garante. The case concerned the use of a biometric system to record employee attendance without a proper legal basis, in breach of GDPR rules on data processing and special categories of data. | IT | Garante | GDPR | €20,000 | ↗ |
| 10 Nov 2022 | Azienda Usl Valle d’AostaAzienda Usl Valle d’Aosta was fined EUR 40,000 by the Garante for unlawful access to a patient's health dossier. The access was made by a healthcare professional not involved in the patient's care, breaching GDPR data processing principles. | IT | Garante | GDPR | €40,000 | ↗ |
| 10 Nov 2022 | Conservatorio di Musica S. Cecilia di RomaThe Conservatorio di Musica S. Cecilia di Roma was fined €6,000 by the Garante. The authority found unlawful processing of personal data contained in an audio/video recording used in disciplinary proceedings against a student without a lawful basis. | IT | Garante | GDPR | €6,000 | ↗ |
| 10 Nov 2022 | SOCIETE DEVELOPPANT UN LOGICIEL DE VOIX SUR IP ET UNE MESSAGERIE INSTANTANEECNIL imposed a fine of 800,000 EUR on SOCIETE DEVELOPPANT UN LOGICIEL DE VOIX SUR IP ET UNE MESSAGERIE INSTANTANEE. The decision concerns a breach of rules covered by the authority’s enforcement action. | FR | CNIL | GDPR | €800,000 | ↗ |
| 10 Nov 2022 | Doctolib SrlDoctolib Srl was fined EUR 40,000 by the Italian Garante for violations linked to insufficient transparency in the online information provided to patients. The case concerned, in particular, how consent for processing health data was obtained. | IT | Garante | GDPR | €40,000 | ↗ |
| 10 Nov 2022 | Comune di Villafranca di VeronaThe Comune di Villafranca di Verona was fined 4,000 EUR by the Garante for breaching data protection principles. The authority found that personal data linked to a sensitive private matter was improperly disclosed online. | IT | Garante | GDPR | €4,000 | ↗ |
| 10 Nov 2022 | Vodafone Italia S.p.A.Vodafone Italia S.p.A. was fined EUR 500,000 by the Garante. The authority found that promotional contacts were made without the required information and without obtaining the data subject’s consent, in breach of GDPR requirements. | IT | Garante | GDPR | €500,000 | ↗ |
| 10 Nov 2022 | Comune di Cisterna di LatinaComune di Cisterna di Latina was fined 5,000 EUR by the Garante for violating data protection principles, including data minimization. Improper handling of personal data led to unauthorized access by third parties. | IT | Garante | GDPR | €5,000 | ↗ |
| 14 Nov 2022 | Megismételt eljárásban bírság kiszabásaThe authority imposed a fine for violations related to the processing of personal data and special categories of data, including health data, without proper notification and consent. The case also concerned actions linked to the termination of an employment relationship. | HU | NAIH | GDPR | €1,230 | ↗ |