BULLETIN №081Last updated · 26 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -20.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 18 Dec 2013 | Anonymised (HDPA 154/2013)The HDPA imposed a fine of EUR 3,000 on the company for unlawfully collecting an individual's creditworthiness data. The case concerned processing without a valid legal basis, which breaches data protection rules. | GR | HDPA | GDPR | €3,000 | ↗ |
| 24 Mar 2022 | Anonymised (HDPA 17/2022)A fine of EUR 3,000 was imposed for sending unsolicited political communication by SMS without prior consent. The conduct was found to breach Article 11 of Law 3471/2006. | GR | HDPA | ePrivacy | €3,000 | ↗ |
| 27 Sept 2022 | Anonymised (HDPA 18/2022)A fine was imposed for sending unsolicited political communication via SMS without prior consent. The case concerns a breach of consent requirements for political and marketing communications. | GR | HDPA | ePrivacy | €2,000 | ↗ |
| 13 Jun 2025 | Anonymised (HDPA 21/2025)A fine of EUR 1,000 was imposed for violating the data subject’s right of access. The entity did not provide the requested video footage. | GR | HDPA | GDPR | €1,000 | ↗ |
| 13 Jun 2025 | Anonymised (HDPA 21/2025)A fine was imposed for breaching the principles of lawfulness, fairness, and transparency in data processing in connection with a video surveillance system. The case concerned improper processing of personal data through video monitoring. | GR | HDPA | GDPR | €2,000 | ↗ |
| 20 Jun 2022 | Anonymised (HDPA 23/2022)A fine was imposed for failing to respond to a data access request within the required timeframe. The case concerns a breach of the controller’s obligations to facilitate data subject rights. | GR | HDPA | GDPR | €2,000 | ↗ |
| 26 Feb 2015 | Anonymised (HDPA 26/2015)The company was fined for unlawful collection and processing of personal data, and for sending unsolicited marketing emails without recipients’ consent. The case concerns breaches of core data protection principles and the requirement to obtain prior consent for marketing communications. | GR | HDPA | ePrivacy | €1,000 | ↗ |
| 24 May 2022 | Anonymised (HDPA 26/2022)A fine of EUR 2,000 was imposed for sending unsolicited political communication by SMS without the recipient's prior consent. The authority treated this as a breach of data protection and electronic communications rules. | GR | HDPA | ePrivacy | €2,000 | ↗ |
| 16 Jun 2010 | Anonymised (HDPA 29/2010)The company was fined EUR 3,000 by the HDPA for sending unsolicited marketing emails and faxes without subscriber consent. This conduct breached ePrivacy rules on electronic marketing communications. | GR | HDPA | ePrivacy | €3,000 | ↗ |
| 16 Jun 2010 | Anonymised (HDPA 29/2010)The company was fined 3,000 EUR by the HDPA for unlawfully processing email addresses without prior consent. This conduct breached Greek data protection law. | GR | HDPA | GDPR | €3,000 | ↗ |
| 14 Jul 2021 | Anonymised (HDPA 31/2021)The fined individual unlawfully obtained and processed personal data from the complainant's personnel file. The data came from an unauthorized source and were used in a complaint against the complainant, in breach of data protection rules. | GR | HDPA | GDPR | €2,000 | ↗ |
| 09 Sept 2022 | Anonymised (HDPA 48/2022)The mayor of a municipality was fined for sending unsolicited emails without the recipients’ consent. The authority found breaches of GDPR transparency and purpose limitation principles. | GR | HDPA | GDPR | €2,000 | ↗ |
| 22 Sept 2022 | Anonymised (HDPA 51/2022)The fined entity did not comply with a data subject access request and did not provide any justification for failing to act on it. It also failed to inform the data subject about further processing and the transfer of their data to the police. | GR | HDPA | GDPR | €3,000 | ↗ |
| 19 May 2011 | Anonymised (HDPA 59/2011)The company was fined for sending unsolicited electronic messages and faxes without subscriber consent. This conduct breached e-privacy rules governing direct electronic communications. | GR | HDPA | ePrivacy | €2,000 | ↗ |
| 19 May 2011 | Anonymised (HDPA 59/2011)The company was fined for unlawfully processing email addresses without prior consent. The authority found this to be a breach of data protection law. | GR | HDPA | GDPR | €2,000 | ↗ |
| 20 Nov 2006 | Anonymised (HDPA 61/2006)A hospital was fined for failing to properly inform the complainant about the transmission of sensitive health data. The case concerns a breach of the duty to provide clear information to the data subject. | GR | HDPA | GDPR | €3,000 | ↗ |
| 20 Nov 2006 | Anonymised (HDPA 61/2006)An insurance company was fined for unlawfully transmitting the complainant’s sensitive health data. The case concerned a breach of the rules governing the lawful processing of special-category personal data. | GR | HDPA | GDPR | €15,000 | ↗ |
| 16 Feb 2024 | Anonymised (HDPA 6/2024)The company was fined 2,000 EUR by the HDPA for unlawful processing of personal data. It used vehicle tracking data outside working hours to locate an employee. | GR | HDPA | GDPR | €2,000 | ↗ |
| 25 Jul 2013 | Anonymised (HDPA 90/2013)The HDPA imposed a EUR 500 fine on the anonymised entity for sending unsolicited marketing emails. The conduct breached the requirement to obtain subscriber consent before sending such communications. | GR | HDPA | ePrivacy | €500 | ↗ |
| 25 Jul 2013 | Anonymised (HDPA 90/2013)HDPA imposed a fine of EUR 1,000 on Anonymised (HDPA 90/2013) for the illegal collection and further processing of personal data. The case concerns a breach of the lawful processing requirements. | GR | HDPA | GDPR | €1,000 | ↗ |