BULLETIN №083Last updated · 09 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.1%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 16 Mar 2023 | B.B.B.B.B.B. was fined by the AEPD in the amount of EUR 300 for failing to provide adequate information about video surveillance. The authority found a breach of Article 13 GDPR because the affected individuals did not receive the required information. | ES | AEPD | GDPR | €300 | ↗ |
| 16 Mar 2023 | SOCIETE DE LOCATION DE SCOOTERS ELECTRIQUES EN LIBRE-SERVICEThe CNIL imposed a fine of EUR 125,000 on SOCIETE DE LOCATION DE SCOOTERS ELECTRIQUES EN LIBRE-SERVICE. The case concerns a confirmed breach of rules supervised by the data protection authority. | FR | CNIL | GDPR | €125,000 | ↗ |
| 16 Mar 2023 | Sancțiuni pentru încălcarea RGPDA healthcare operator was fined for failing to implement adequate security measures, which led to unauthorized access to personal data. The case indicates a breach of data protection obligations under the GDPR. | RO | ANSPDCP | GDPR | €3,000 | ↗ |
| 17 Mar 2023 | ORANGE ESPAGNE, S.A.U.ORANGE ESPAGNE, S.A.U. was fined EUR 70,000 by the AEPD for activating a call forwarding service without the user's consent. This led to unauthorized access to the user's bank accounts and transactions. | ES | AEPD | GDPR | €70,000 | ↗ |
| 17 Mar 2023 | TELEFÓNICA MÓVILES ESPAÑA, S.A.The AEPD fined TELEFÓNICA MÓVILES ESPAÑA, S.A. 70,000 EUR for changing a customer's mobile tariff without consent. The authority found that the action breached Article 6(1) GDPR because there was no valid legal basis for the change. | ES | AEPD | GDPR | €70,000 | ↗ |
| 17 Mar 2023 | PLAY FUL KIDS, S.L.PLAY FUL KIDS, S.L. was fined by the AEPD EUR 3,000 for breaching Article 6(1) of the GDPR, which requires a lawful basis for processing personal data. The infringement was classified as very serious. | ES | AEPD | GDPR | €3,000 | ↗ |
| 18 Mar 2023 | TOTALENERGIES CLIENTES, S.A.TOTALENERGIES CLIENTES, S.A. was fined EUR 200,000 by the AEPD for linking a customer’s personal data to a third party during gas supply service registration. The authority found this breached data protection principles. | ES | AEPD | GDPR | €200,000 | ↗ |
| 22 Mar 2023 | GRUPO MASSIMO DUTTI, S.A.The AEPD fined GRUPO MASSIMO DUTTI, S.A. EUR 5,000 for failing to provide sufficient information and adequate options regarding cookie consent on its website. The authority found a breach of Article 22.2 of the LSSI. | ES | AEPD | ePrivacy | €5,000 | ↗ |
| 23 Mar 2023 | B.B.B.B.B.B. was fined 300 EUR by the AEPD for installing surveillance cameras that could capture images of a neighboring property without prior authorization. The authority found this to be a breach of the data minimization principle under Article 5(1)(c) GDPR. | ES | AEPD | GDPR | €300 | ↗ |
| 23 Mar 2023 | Dedalus Italia S.p.a.Dedalus Italia S.p.a. was fined EUR 15,000 by the Garante for failing to implement adequate measures to protect personal data. The authority found a breach of Article 32 GDPR on security of processing. | IT | Garante | GDPR | €15,000 | ↗ |
| 23 Mar 2023 | Consiglio Nazionale dell'Ordine degli Assistenti SocialiConsiglio Nazionale dell'Ordine degli Assistenti Sociali was fined EUR 3,000 by the Garante for breaching data protection principles. The case involved improper handling of personal data during a recruitment process, including disclosure of information about a candidate's exclusion. | IT | Garante | GDPR | €3,000 | ↗ |
| 23 Mar 2023 | Tehnoplus Industry SRLTehnoplus Industry SRL was fined EUR 2,000 by ANSPDCP for violating GDPR provisions. The case concerns non-compliance with personal data protection requirements. | RO | ANSPDCP | GDPR | €2,000 | ↗ |
| 23 Mar 2023 | Comune di PulsanoComune di Pulsano was fined by the Garante for unlawfully publishing personal data related to an employee’s disciplinary proceedings on its institutional website. The authority found breaches of data minimization and transparency principles. | IT | Garante | GDPR | €3,000 | ↗ |
| 23 Mar 2023 | Tehnoplus Industry SRLANSPDCP imposed a fine of EUR 3,000 on Tehnoplus Industry SRL for violating GDPR provisions. The case concerned non-compliance with personal data protection requirements. | RO | ANSPDCP | GDPR | €3,000 | ↗ |
| 23 Mar 2023 | Paolo MeloniThe condominium administrator, Paolo Meloni, was fined for disclosing to all residents that a family had tested positive for COVID-19. The authority found this to be a breach of data protection rules. | IT | Garante | GDPR | €2,000 | ↗ |
| 23 Mar 2023 | Azienda 1 di SassariThe Garante imposed a fine of 4,000 EUR on Azienda 1 di Sassari for violations related to the processing of personal data, including health data. The authority found that adequate security measures were not in place for this processing. | IT | Garante | GDPR | €4,000 | ↗ |
| 23 Mar 2023 | B.B.B.B.B.B. was fined by the AEPD in the amount of 2,000 EUR for sending unsolicited commercial emails after a request for data deletion. The conduct breached Article 21 of the LSSI on marketing communications without consent. | ES | AEPD | ePrivacy | €2,000 | ↗ |
| 23 Mar 2023 | La Risorsa Umana.it s.r.l.La Risorsa Umana.it s.r.l. was fined EUR 40,000 by the Garante for monitoring employee email communications without providing proper information to employees. The authority found that this conduct breached GDPR requirements on transparency of processing and data security. | IT | Garante | GDPR | €40,000 | ↗ |
| 23 Mar 2023 | CAAF CGIL Lombardia s.r.l.CAAF CGIL Lombardia s.r.l. was fined EUR 30,000 by the Garante for unlawful processing of personal data. The company sent promotional emails despite a prior request to delete the data. | IT | Garante | GDPR | €30,000 | ↗ |
| 23 Mar 2023 | Gruppo SAE S.p.A.The Garante fined Gruppo SAE S.p.A. 10,000 EUR for publishing sensitive personal data, including medical information, in an article without proper consent. The case concerns unlawful processing of special-category personal data. | IT | Garante | GDPR | €10,000 | ↗ |