BULLETIN №083Last updated · 09 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.1%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 03 Apr 2023 | CAIXABANK PAYMENTS & CONSUMER EFC, EP, S.A.U.CAIXABANK PAYMENTS & CONSUMER EFC, EP, S.A.U. was fined by the AEPD 200,000 EUR for unlawfully including an individual's data in a creditworthiness file without a lawful basis. The authority found this conduct violated Article 6 of the GDPR. | ES | AEPD | GDPR | €200,000 | ↗ |
| 04 Apr 2023 | Tensa Art Design SRLThe company was fined for sending commercial messages to individuals by phone and email despite their requests to stop contact. The case concerned failure to respect opt-out requests against further marketing communication. | RO | ANSPDCP | GDPR | €3,000 | ↗ |
| 04 Apr 2023 | B.B.B.A neighbor installed a digital peephole with video recording capabilities without the consent of the homeowners' association. AEPD found that personal data were processed without a lawful basis, in breach of Article 6(1) GDPR. | ES | AEPD | GDPR | €300 | ↗ |
| 06 Apr 2023 | К. Л. НK. L. N was fined for unlawfully processing voters' personal data. The case involved forwarding an email containing scanned voting lists to a personal email address, in breach of GDPR Article 6. | BG | CPDP | GDPR | €767 | ↗ |
| 10 Apr 2023 | BIROU GAS, S.L.BIROU GAS, S.L. was fined EUR 60,000 by the AEPD for breaching Article 58(1) of the GDPR. The company did not respond to information requests from the supervisory authority. | ES | AEPD | GDPR | €60,000 | ↗ |
| 10 Apr 2023 | COLEGIO OFICIAL DE ARQUITECTOS DE GRANADACOLEGIO OFICIAL DE ARQUITECTOS DE GRANADA was fined €14,000 by the AEPD for data protection breaches. The authority found a conflict of interest in the appointment of the Data Protection Officer, missing required information on data processing in complaint forms, and the use of third-party cookies without user consent. | ES | AEPD | ePrivacy | €14,000 | ↗ |
| 11 Apr 2023 | CORPORACION DE MEDIOS DE EXTREMADURA, S.A.The entity published a video containing personal data of 56 women registered as victims of gender-based violence. The authority found a breach of the data minimization principle and imposed a 150,000 EUR fine. | ES | AEPD | GDPR | €150,000 | ↗ |
| 11 Apr 2023 | CAIXABANK, S.A.CAIXABANK, S.A. was fined by the AEPD EUR 200,000 for failing to remove personal data from a credit information system after the debt was sold. The authority found that the continued processing of the data was not compliant with data protection rules. | ES | AEPD | GDPR | €200,000 | ↗ |
| 11 Apr 2023 | SOCIEDAD VASCONGADA DE PUBLICACIONES, S.A.The entity published a video containing personal data of 56 women registered as victims of gender-based violence. AEPD found that this breached the data minimization principle. | ES | AEPD | GDPR | €150,000 | ↗ |
| 12 Apr 2023 | Česká republika – Ministerstvo vnitraThe Czech Ministry of Interior was fined CZK 975,000 by the UOOU for violations of personal data processing rules during COVID-19 measures. The authority found, among other issues, a failure to conduct data protection impact assessments and improper disclosure of processing purposes. | CZ | UOOU | GDPR | €41,633 | ↗ |
| 13 Apr 2023 | Citynews S.p.A.Citynews S.p.A. was fined EUR 15,000 by the Italian data protection authority, Garante. The case concerned the publication of detailed health information about an individual without consent, in breach of GDPR Article 9 on special categories of personal data. | IT | Garante | GDPR | €15,000 | ↗ |
| 13 Apr 2023 | Unione PilotiUnione Piloti was fined by the Garante in the amount of 4,000 EUR for violations related to the processing of personal data. The authority found that the company failed to ensure lawful, fair, and transparent data handling. | IT | Garante | GDPR | €4,000 | ↗ |
| 13 Apr 2023 | Arnia società cooperativaThe Garante imposed a fine of 800,000 EUR on Arnia società cooperativa for unauthorized data processing and telemarketing activities. The case concerned a breach of GDPR Article 5. | IT | Garante | GDPR | €800,000 | ↗ |
| 13 Apr 2023 | Sociale verzekeringsbankThe Dutch AP fined Sociale verzekeringsbank EUR 150,000. The authority found that the organization failed to implement adequate technical and organizational measures to ensure a risk-appropriate level of security when processing personal data during telephone contact with AOW beneficiaries, in breach of GDPR Article 32. | NL | AP | GDPR | €150,000 | ↗ |
| 13 Apr 2023 | SWG S.p.A.SWG S.p.A. was fined EUR 15,000 by the Garante for blocking an employee’s access to email and phone before the agreed termination date. This prevented access to personal data, including sensitive data. | IT | Garante | GDPR | €15,000 | ↗ |
| 13 Apr 2023 | Suditaly Imprese Meridionali Soc. coop.The Garante imposed a 2,500 EUR fine on Suditaly Imprese Meridionali Soc. coop. for publishing detailed health data without the data subjects' consent. The case concerned Article 9 of the GDPR, which restricts processing of special categories of personal data. | IT | Garante | GDPR | €2,500 | ↗ |
| 13 Apr 2023 | GMC s.a.p.a.GMC s.a.p.a. was fined EUR 15,000 by the Italian supervisory authority, Garante. The case concerned the publication of detailed health data of an individual without consent, in breach of GDPR Article 9 on special categories of personal data. | IT | Garante | GDPR | €15,000 | ↗ |
| 13 Apr 2023 | Ordine degli Avvocati di AnconaThe Garante fined the Ordine degli Avvocati di Ancona 20,000 EUR for violations related to data processing transparency and security. The authority found incorrect privacy notices and non-compliance with GDPR principles. | IT | Garante | GDPR | €20,000 | ↗ |
| 13 Apr 2023 | Azienda Ospedaliero Universitaria SeneseThe Garante fined Azienda Ospedaliero Universitaria Senese EUR 13,000 for violations related to the processing of personal data in the health sector. The case concerned data minimization and security measures. | IT | Garante | GDPR | €13,000 | ↗ |
| 13 Apr 2023 | Azienda Ospedaliera Universitaria di CagliariAzienda Ospedaliera Universitaria di Cagliari was fined EUR 8,000 by the Garante for unlawfully publishing personal data related to a disciplinary procedure online. The authority found breaches of data minimization and transparency principles. | IT | Garante | GDPR | €8,000 | ↗ |