BULLETIN №083Last updated · 08 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.6%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 15 Nov 2022 | GESTIÓN DE PATRIMONIOS ANFIPOLIS SL.The entity was fined for sending unsolicited commercial emails despite the recipient's explicit objection. The authority found a breach of Article 21 of the LSSI. | ES | AEPD | ePrivacy | €2,000 | ↗ |
| 15 Nov 2022 | Elektronikus direkt marketing hozzájárulás érvényességeThe entity did not provide data subjects with adequate information about the duration of electronic direct marketing (EDM) and did not have valid consent for EDM processing. NAIH found violations of GDPR Articles 6, 7, and 12 and imposed a fine of HUF 2,000,000. | HU | NAIH | GDPR | €4,940 | ↗ |
| 16 Nov 2022 | Raiffeisen Bank SARaiffeisen Bank SA was fined EUR 3,000 by ANSPDCP for GDPR violations related to data security incidents. The case concerned shortcomings in the protection of personal data and the handling of security events. | RO | ANSPDCP | GDPR | €3,000 | ↗ |
| 16 Nov 2022 | Raiffeisen Bank SARaiffeisen Bank SA was fined EUR 5,000 by ANSPDCP for GDPR violations related to data security incidents. The case concerned shortcomings in the protection of personal data and required remedial action by the bank. | RO | ANSPDCP | GDPR | €5,000 | ↗ |
| 16 Nov 2022 | Raiffeisen Bank SARaiffeisen Bank SA was fined by ANSPDCP EUR 20,000 for GDPR violations related to data security incidents. The case concerned shortcomings in the protection of personal data and security requirements. The decision highlights the need for effective technical and organizational controls. | RO | ANSPDCP | GDPR | €20,000 | ↗ |
| 17 Nov 2022 | NUEVAS TECNOLOGIAS MEDITERRANEO, S.L.NUEVAS TECNOLOGIAS MEDITERRANEO, S.L. was fined by the AEPD EUR 800 for sending unsolicited advertising emails without prior consent. The case concerned a breach of Article 21 of the LSSI and unlawful direct marketing. | ES | AEPD | ePrivacy | €800 | ↗ |
| 18 Nov 2022 | Asociația de Proprietari Bld. Pipera 1-2EThe association was fined for failing to provide requested information within the legal deadline. The case concerns a breach of the duty to cooperate with the supervisory authority. | RO | ANSPDCP | GDPR | €300 | ↗ |
| 21 Nov 2022 | ING Bank NV Amsterdam Sucursala BucureștiANSPDCP completed an investigation into ING Bank NV Amsterdam Bucharest Branch and found a breach of GDPR provisions. The case was opened following a data breach notification submitted by the controller. | RO | ANSPDCP | GDPR | €20,000 | ↗ |
| 23 Nov 2022 | Linee Stampalibera Società Cooperativa S.r.l.Linee Stampalibera Società Cooperativa S.r.l. was fined 1,000 EUR by the Garante for publishing personal data on its website without consent. The case also involved the full text of a property purchase contract, which breached data protection rules. | IT | Garante | GDPR | €1,000 | ↗ |
| 24 Nov 2022 | Azienda per la tutela della salute - ATS SardegnaATS Sardegna was fined by the Garante for breaching data protection principles in its handling of personal data relating to an employee's vaccination status. The authority found violations of lawfulness, fairness, transparency, and data minimization. | IT | Garante | GDPR | €4,000 | ↗ |
| 24 Nov 2022 | Dello Russo Giulio ditta individualeThe company was fined for using a biometric fingerprint system to record employee attendance without a valid legal basis. The authority found that the processing did not comply with data protection requirements. | IT | Garante | GDPR | €1,000 | ↗ |
| 24 Nov 2022 | Società Lombarda Sport s.r.l.Società Lombarda Sport s.r.l. was fined by the Garante 4,000 EUR for processing personal data without an adequate legal basis. The authority also found failures to ensure data integrity and confidentiality in connection with the issuance of medical certificates for non-competitive sports activities. | IT | Garante | GDPR | €4,000 | ↗ |
| 24 Nov 2022 | STS Di Prisinzano s.r.l.STS Di Prisinzano s.r.l. was fined EUR 1,000 by the Garante for failing to provide a data subject with an adequate privacy notice during roadside assistance. The authority found a breach of Article 13 GDPR. | IT | Garante | GDPR | €1,000 | ↗ |
| 24 Nov 2022 | SOCIETE FOURNISSANT DE l'ELECTRICITE, DU GAZ ET DES SERVICESCNIL imposed a fine of 600,000 EUR on SOCIETE FOURNISSANT DE l'ELECTRICITE, DU GAZ ET DES SERVICES. The available record indicates an administrative penalty issued by the French data protection authority. | FR | CNIL | GDPR | €600,000 | ↗ |
| 24 Nov 2022 | D. B.B.B.The entity was fined EUR 300 by the AEPD for installing surveillance cameras on a building facade facing public areas without prior administrative authorization. The authority found this to be a breach of Article 5(1)(c) GDPR. | ES | AEPD | GDPR | €300 | ↗ |
| 24 Nov 2022 | CARROZADOS TECAI, S.L.CARROZADOS TECAI, S.L. was fined by the AEPD EUR 300 for installing a surveillance camera that could capture public areas without proper authorization. The authority also found inadequate informational signage for affected individuals, in breach of Article 13 GDPR. | ES | AEPD | GDPR | €300 | ↗ |
| 24 Nov 2022 | Areti S.p.A.Areti S.p.A. was fined EUR 1,000,000 by the Garante for incorrectly labeling a customer as a “defaulting client” based on inaccurate and outdated data. The issue may have affected up to 16,743 other individuals, indicating a broader data processing failure. | IT | Garante | GDPR | €1,000,000 | ↗ |
| 24 Nov 2022 | dott.ssa Emilia ColosimoThe Garante imposed a EUR 1,000 fine on dott.ssa Emilia Colosimo for breaches of the principles of lawful, fair and transparent processing of personal data, data minimization, and data security. The authority also cited insufficient safeguards against unauthorized or unlawful processing. | IT | Garante | GDPR | €1,000 | ↗ |
| 24 Nov 2022 | Medicover S.R.L.Medicover S.R.L. was fined EUR 1,000 by ANSPDCP for a data security breach. An email sent to a customer included additional contract documents belonging to other clients, resulting in disclosure of third-party personal data. | RO | ANSPDCP | GDPR | €1,000 | ↗ |
| 24 Nov 2022 | Ordine dei Medici Chirurghi e degli Odontoiatri della Provincia di CagliariOrdine dei Medici Chirurghi e degli Odontoiatri della Provincia di Cagliari was fined €3,000 by the Garante. The authority found breaches of lawfulness, fairness, transparency, and data minimization in the handling of personal data related to an individual's employment. | IT | Garante | GDPR | €3,000 | ↗ |