BULLETIN №083Last updated · 06 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -22.8%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 27 Dec 2012 | Euro-Catering O.E.The company installed a CCTV system without notifying the supervisory authority, failed to display required informational signs, and collected excessive data. These actions breached privacy protection rules. | GR | HDPA | GDPR | €20,000 | ↗ |
| 27 Dec 2012 | Euro-Catering O.E.The company was fined for failing to comply with a prior decision by the authority. It was noted that it no longer operated the stores concerned and that its financial situation was difficult. | GR | HDPA | GDPR | €10,000 | ↗ |
| 21 Aug 2018 | Eurobank Ergasias A.E.Eurobank Ergasias A.E. was fined by the HDPA in the amount of 5,000 EUR for failing to maintain and process accurate data of its debtors. The authority found that the company’s handling of debtor information breached data protection requirements. | GR | HDPA | GDPR | €5,000 | ↗ |
| 20 Mar 2017 | Eurobank Ergasias A.E.Eurobank Ergasias A.E. was fined EUR 10,000 by the HDPA. The authority found that the bank did not adequately satisfy the complainant’s right of access to recorded telephone conversations. The case concerned the legal obligation to provide access to such recordings. | GR | HDPA | GDPR | €10,000 | ↗ |
| 16 Jun 2015 | Eurobank Ergasias AEA fine was imposed for failing to maintain appropriate organizational and technical security measures. This led to unauthorized employee access to the complainant's personal data. | GR | HDPA | GDPR | €5,000 | ↗ |
| 16 Jun 2015 | Eurobank Ergasias AEA fine was imposed on Eurobank Ergasias AE for unlawful processing of the complainant’s personal data. The case concerned a breach of data protection rules by the bank. | GR | HDPA | GDPR | €5,000 | ↗ |
| 26 Mar 2026 | Euro Bangla MinimarketThe Garante fined Euro Bangla Minimarket EUR 1,000 for improper use of a video surveillance system. Images from six cameras were visible to everyone on a monitor in the store, which breached GDPR requirements. | IT | Garante | GDPR | €1,000 | ↗ |
| 18 Aug 2021 | EULEN SEGURIDAD, S.A.EULEN SEGURIDAD, S.A. was fined by the AEPD 3,000 EUR for disclosing employees' DNI numbers in a workplace notice. The authority found a breach of confidentiality and data security principles. | ES | AEPD | GDPR | €3,000 | ↗ |
| 11 Feb 2022 | Etterforsker1 Gruppen ASEtterforsker1 Gruppen AS was fined NOK 50,000 by Datatilsynet for conducting a credit assessment of an individual without a legal basis. The assessment was carried out on behalf of a client who claimed to have a compensation claim against the complainant. | NO | Datatilsynet | GDPR | €4,964 | ↗ |
| 23 May 2024 | ETABLISSEMENT PUBLIC NATIONAL (ENSEIGNEMENT) (procédure simplifiée)CNIL imposed an administrative fine of EUR 6,000 on ETABLISSEMENT PUBLIC NATIONAL (ENSEIGNEMENT) under a simplified procedure. The case concerned a breach identified by the supervisory authority. | FR | CNIL | GDPR | €6,000 | ↗ |
| 29 Jan 2026 | ÉTABLISSEMENT PUBLIC EXERÇANT UNE ACTIVITÉ DE TRANSPORT URBAIN (procédure simplifiée)The CNIL imposed an administrative fine of EUR 20,000 on ÉTABLISSEMENT PUBLIC EXERÇANT UNE ACTIVITÉ DE TRANSPORT URBAIN. The case was handled under a simplified procedure. | FR | CNIL | GDPR | €20,000 | ↗ |
| 11 Dec 2025 | ETABLISSEMENT PUBLIC EXERCANT UNE ACTIVITE DE GESTION LOCATIVE DE LOGEMENTS (procédure simplifiée)The CNIL imposed an administrative fine of EUR 20,000 on ETABLISSEMENT PUBLIC EXERCANT UNE ACTIVITE DE GESTION LOCATIVE DE LOGEMENTS and issued an injunction. The case concerns a regulatory breach in the area of data protection. | FR | CNIL | GDPR | €20,000 | ↗ |
| 22 Jan 2026 | ÉTABLISSEMENT PUBLIC ADMINISTRATIFCNIL imposed an administrative fine of EUR 5,000,000 on ÉTABLISSEMENT PUBLIC ADMINISTRATIF and issued an injunction. The case concerns a confirmed breach of rules supervised by CNIL. | FR | CNIL | GDPR | €5,000,000 | ↗ |
| 25 Jul 2024 | ETABLISSEMENT D'ENSEIGNEMENT SUPERIEUR PRIVE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 20,000 on ETABLISSEMENT D'ENSEIGNEMENT SUPERIEUR PRIVE under a simplified procedure. The case concerned a confirmed breach of rules supervised by the CNIL. | FR | CNIL | GDPR | €20,000 | ↗ |
| 14 Apr 2023 | ESTUDIO VILLALBA ANTIQUE, S.L.ESTUDIO VILLALBA ANTIQUE, S.L. was fined by the AEPD for processing personal data without consent. The authority found a breach of the lawfulness principle under Article 6(1) GDPR. | ES | AEPD | GDPR | €5,000 | ↗ |
| 26 Jan 2022 | ESTUDIO INMOBILIARIO SAN ISIDRO, S.L.UESTUDIO INMOBILIARIO SAN ISIDRO, S.L.U was fined by the AEPD EUR 5,000 for unlawfully obtaining personal data and visiting the complainant's home to promote real estate services without proper consent. The case concerns unlawful processing and improper direct marketing contact. | ES | AEPD | GDPR | €5,000 | ↗ |
| 07 Feb 2025 | ESTUDIO ALCAZAR DEL GENIL 2022, S.L.ESTUDIO ALCAZAR DEL GENIL 2022, S.L. was fined EUR 10,000 by the AEPD for collecting and storing personal data taken from mailboxes without consent or notice to the data subjects. The authority found breaches of the lawful basis and transparency requirements under GDPR Articles 6(1) and 14. | ES | AEPD | GDPR | €10,000 | ↗ |
| 21 Apr 2016 | Estracom s.p.a.Estracom s.p.a. was fined EUR 20,000 by the Garante for retaining customers’ call data for more than thirty days. The authority found this to be a breach of data protection rules. | IT | Garante | GDPR | €20,000 | ↗ |
| 21 Mar 2024 | Estlevante s.r.l.s.The Garante imposed a EUR 2,000 fine on Estlevante s.r.l.s. for failing to provide the required privacy notice for its video surveillance system. The breach concerned Article 13 of the GDPR. | IT | Garante | GDPR | €2,000 | ↗ |
| 26 Oct 2020 | ESTILO 1221, S.C.ESTILO 1221, S.C. was fined by the AEPD EUR 1,500 for sending unsolicited commercial emails without recipient consent. The conduct breached Article 21.1 of the LSSI, which prohibits this type of marketing communication without prior consent. | ES | AEPD | ePrivacy | €1,500 | ↗ |