BULLETIN №083Last updated · 09 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.1%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 23 Mar 2023 | Ministero dell’InternoMinistero dell’Interno was fined EUR 4,000 by the Garante for unlawfully communicating personal data, including health information, to the police without proper justification. The case concerned a breach of lawfulness and purpose limitation requirements. | IT | Garante | GDPR | €4,000 | ↗ |
| 24 Mar 2023 | NATURGESTYGAS, S.L.NATURGESTYGAS, S.L. was fined EUR 10,000 by the AEPD for processing personal data without a legal basis. The company charged a customer despite having no contract or consent, which breached the legality requirement for processing. | ES | AEPD | GDPR | €10,000 | ↗ |
| 24 Mar 2023 | A.A.A.A.A.A. was fined EUR 300 by the AEPD for failing to provide adequate information about data processing in a video surveillance system. The authority found a breach of Article 13 GDPR because data subjects did not receive the required information. | ES | AEPD | GDPR | €300 | ↗ |
| 24 Mar 2023 | B.B.B.The entity installed surveillance cameras without the required informational signage. AEPD treated this as a breach of data protection rules. | ES | AEPD | GDPR | €300 | ↗ |
| 24 Mar 2023 | COMUNIDAD DE PROPIETARIOS ***DIRECCIÓN.1The homeowners’ association was fined 500 EUR by the AEPD for installing surveillance cameras aimed at public areas without prior administrative authorization. The authority treated this as a breach of data protection rules. | ES | AEPD | GDPR | €500 | ↗ |
| 27 Mar 2023 | QUALITY-PROVIDER S.A.QUALITY-PROVIDER S.A. was fined EUR 20,000 by the Spanish data protection authority, AEPD. The company failed to provide requested information, obstructing the authority’s investigative powers under Article 58(1) GDPR. | ES | AEPD | GDPR | €20,000 | ↗ |
| 27 Mar 2023 | persoană fizicăAn individual was fined EUR 450 by ANSPDCP for violating GDPR provisions. The case concerned non-compliance with obligations under personal data protection rules. | RO | ANSPDCP | GDPR | €450 | ↗ |
| 28 Mar 2023 | SOCIETE DE PROGRAMMATION INFORMATIQUE (procédure simplifiée)The CNIL imposed a EUR 20,000 fine on SOCIETE DE PROGRAMMATION INFORMATIQUE under a simplified procedure. The record only indicates the financial sanction and does not provide further details on the underlying breach. | FR | CNIL | GDPR | €20,000 | ↗ |
| 28 Mar 2023 | DENTAL REY-GAR, S.L.DENTAL REY-GAR, S.L. was fined by the AEPD EUR 1,000 for failing to comply with a resolution concerning the right of access to personal data. The authority found a breach of Article 58(2) of the GDPR. | ES | AEPD | GDPR | €1,000 | ↗ |
| 28 Mar 2023 | SOCIETE DE MARKETING (procédure simplifiée)CNIL imposed a fine of EUR 10,000 on SOCIETE DE MARKETING and issued an injunction. The case was handled under a simplified procedure. | FR | CNIL | GDPR | €10,000 | ↗ |
| 28 Mar 2023 | Sky Italia S.r.l.The Italian Data Protection Authority fined Sky Italia S.r.l. EUR 842,062 for violations related to telemarketing and commercial communications. The company failed to properly verify consent, relied on outdated consents, and did not check the Public Register of Oppositions before campaigns. | IT | Garante per la protezione dei dati personali | GDPR | €842,000 | ↗ |
| 29 Mar 2023 | SOLAR PROGRESS, S.L.SOLAR PROGRESS, S.L. was fined 5,000 EUR by the AEPD for displaying an employee’s personal data on a company WhatsApp profile. The authority found a breach of data protection rules. | ES | AEPD | GDPR | €5,000 | ↗ |
| 30 Mar 2023 | Vodafone-PanafonVodafone-Panafon was fined by the HDPA for processing personal data for direct marketing without proper consent and transparency. The authority found breaches of lawfulness, fairness, and purpose limitation. | GR | HDPA | GDPR | €10,000 | ↗ |
| 30 Mar 2023 | XCOM DIGITAL LAB, S.L.XCOM DIGITAL LAB, S.L. was fined by the AEPD EUR 800 for sending unsolicited commercial emails. The company failed to comply with Article 21 of the LSSI despite repeated requests from the recipient to unsubscribe. | ES | AEPD | ePrivacy | €800 | ↗ |
| 30 Mar 2023 | Vodafone-PanafonVodafone-Panafon was fined by the HDPA for failing to respond to a data subject access request concerning recorded calls. The authority also found that the company did not notify a personal data breach to the regulator. | GR | HDPA | GDPR | €40,000 | ↗ |
| 31 Mar 2023 | LODEJU, S.L.LODEJU, S.L. was fined by the AEPD EUR 3,000 for improperly directing surveillance cameras toward public spaces without authorization. The authority also found inadequate informational signage, in breach of GDPR Articles 5(1)(c) and 13. | ES | AEPD | GDPR | €3,000 | ↗ |
| 31 Mar 2023 | APOLLONIA TOPCO, S.L.APOLLONIA TOPCO, S.L. was fined by the AEPD EUR 30,000 for improperly requesting copies of clients’ ID documents. The authority also noted a failure to respond to a data protection complaint, in breach of data minimization and purpose limitation principles. | ES | AEPD | GDPR | €30,000 | ↗ |
| 01 Apr 2023 | TikTokTikTok is appealing a UK data-protection fine of GBP 12.7 million imposed by the Information Commissioner's Office. The record states that in April 2023 the platform was found to have breached the UK GDPR by failing to process children's personal data lawfully. | GB | Information Commissioner's Office | GDPR | €14,444,000 | ↗ |
| 03 Apr 2023 | HM HOSPITALES 1989, S.A.HM HOSPITALES 1989, S.A. was fined EUR 200,000 by the AEPD for insufficient security measures in its hospital information system. The authority found a breach of Article 32 GDPR, which requires appropriate technical and organizational safeguards. | ES | AEPD | GDPR | €200,000 | ↗ |
| 03 Apr 2023 | Banca Transilvania SABanca Transilvania SA was fined EUR 2,000 by ANSPDCP for a GDPR breach. The case concerned improperly restricting access to an account in the mobile banking application despite the client's explicit request. | RO | ANSPDCP | GDPR | €2,000 | ↗ |