BULLETIN №083Last updated · 09 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.1%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 04 May 2023 | RENEDO JOHNSEY, S.L.RENEDO JOHNSEY, S.L. was fined by the AEPD €2,000 for not having a privacy policy on its website. The authority treated this as a breach of Article 13 of the GDPR. | ES | AEPD | GDPR | €2,000 | ↗ |
| 09 May 2023 | Dane anonimowe (Burmistrza Miasta i Gminy W.)UODO imposed an administrative fine of PLN 10,000 on the Mayor of the City and Commune of W. for failing to implement organisational measures appropriate to the risk of data processing. The deficiency resulted in an employee unlawfully copying personal data from a work computer to a portable storage device. | PL | UODO | GDPR | €2,187 | ↗ |
| 09 May 2023 | TELEFÓNICA SERVICIOS INTEGRALES DE DISTRIBUCIÓN, S.A.ZELERIS, a Telefónica subsidiary, was fined by the AEPD for delivering a package containing personal data to the wrong address without consent. The case indicates a breach of data protection rules in the handling and delivery of shipments. | ES | AEPD | GDPR | €70,000 | ↗ |
| 11 May 2023 | SOCIETE EDITANT UN SITE INTERNET PROPOSANT DES ARTICLES, TESTS, QUIZ ET FORUMS DE DISCUSSION EN LIEN AVEC LA SANTE ET LE BIEN-ETRECNIL imposed a fine of 380,000 EUR on SOCIETE EDITANT UN SITE INTERNET PROPOSANT DES ARTICLES, TESTS, QUIZ ET FORUMS DE DISCUSSION EN LIEN AVEC LA SANTE ET LE BIEN-ETRE. The case concerns data processing breaches in connection with a health and wellness website. | FR | CNIL | GDPR | €380,000 | ↗ |
| 11 May 2023 | Libra Internet Bank SALibra Internet Bank SA was fined EUR 1,000 by ANSPDCP. The sanction relates to a breach of GDPR provisions. | RO | ANSPDCP | GDPR | €1,000 | ↗ |
| 11 May 2023 | Libra Internet Bank SALibra Internet Bank SA was fined EUR 10,000 by ANSPDCP for another breach of GDPR provisions. The case concerns non-compliance with personal data protection requirements. | RO | ANSPDCP | GDPR | €10,000 | ↗ |
| 12 May 2023 | Noi sancțiuniA company in the insurance sector was fined by ANSPDCP in the amount of 1,500 EUR for violating GDPR Article 5. The case concerned non-compliance with the basic principles for processing personal data. | RO | ANSPDCP | GDPR | €1,500 | ↗ |
| 12 May 2023 | CHIRURGIEN DENTISTE (procédure simplifiée)The CNIL imposed a fine of EUR 4,500 on CHIRURGIEN DENTISTE and issued an injunction. The case was handled under a simplified procedure. | FR | CNIL | GDPR | €4,500 | ↗ |
| 12 May 2023 | Noi sancțiuniAn insurance-sector company was fined EUR 1,000 by ANSPDCP for breaching GDPR Article 5. The case concerned non-compliance with the core principles governing personal data processing under data protection law. | RO | ANSPDCP | GDPR | €1,000 | ↗ |
| 12 May 2023 | Meta Platforms Ireland Limited (previously known as Facebook Ireland Limited)The Irish DPC imposed a fine of EUR 1,200,000,000 on Meta Platforms Ireland Limited (formerly Facebook Ireland Limited) in case IN-20-8-1. The decision is currently under appeal. | IE | DPC | GDPR | €1,200,000,000 | ↗ |
| 12 May 2023 | CENTRAL SINDICAL INDEPENDIENTE Y DE FUNCIONARIOS CSI-CSIFThe union sent an email containing personal data of election officials and representatives without their consent. AEPD found this to be a breach of data protection rules and imposed a 4,000 EUR fine. | ES | AEPD | GDPR | €4,000 | ↗ |
| 15 May 2023 | TikTok Information Technologies UK Limited and TikTok Inc (TikTok)The UK ICO imposed a fine of 12,700,000 GBP on TikTok Information Technologies UK Limited and TikTok Inc for multiple breaches of data protection law. The regulator specifically cited unlawful use of children’s personal data. | GB | ICO | GDPR | €14,607,000 | ↗ |
| 16 May 2023 | Dane anonimowe (Burmistrza Miasta Z.)UODO imposed an administrative fine of PLN 30,000 on the Mayor of City Z. and ordered the processing operations to be brought into compliance with the GDPR. The authority required appropriate technical and organizational measures, including regular testing, measuring, and evaluating their effectiveness to ensure processing security. | PL | UODO | GDPR | €6,687 | ↗ |
| 16 May 2023 | UK Direct Business Solutions LimitedUK Direct Business Solutions Limited was fined by the ICO for making 410,369 unsolicited marketing calls to businesses registered with the CTPS or TPS. The calls were made between 1 March 2020 and 31 October 2021 and breached rules on telephone marketing. | GB | ICO | GDPR | €115,000 | ↗ |
| 16 May 2023 | Ice Telecommunications LtdIce Telecommunications Ltd made 72,682 unsolicited marketing calls to businesses registered with the CTPS or TPS between 13 September 2021 and 31 January 2022. The ICO imposed a fine of £80,000 for breaching direct marketing rules. | GB | ICO | GDPR | €92,016 | ↗ |
| 16 May 2023 | Compania Națională Poșta Română S.A.Compania Națională Poșta Română S.A. was fined EUR 5,000 by ANSPDCP for GDPR violations related to the completion of Form 230. The case arose from complaints, and the authority instructed the company to ensure personal data processing complies with processing principles. | RO | ANSPDCP | GDPR | €5,000 | ↗ |
| 16 May 2023 | COLEGIO NUESTRA SEÑORA DE LA CARIDAD DEL COBRECOLEGIO NUESTRA SEÑORA DE LA CARIDAD DEL COBRE was fined by the AEPD for failing to implement appropriate technical and organizational measures to ensure data security. The deficiency resulted in a breach involving minors’ data stored in cloud services. | ES | AEPD | GDPR | €5,000 | ↗ |
| 17 May 2023 | Ministero delle infrastrutture e dei trasportiThe Ministry of Infrastructure and Transport was fined by the Garante for improper online disclosure of personal data. The authority found a breach of GDPR transparency obligations. | IT | Garante | GDPR | €24,000 | ↗ |
| 17 May 2023 | Santander Consumer Bank S.p.A.Santander Consumer Bank S.p.A. was fined by the Garante EUR 10,000 for failing to provide timely and adequate access to personal data. The authority also found that prejudicial information related to a loan was not deleted, constituting a breach of GDPR Article 15. | IT | Garante | GDPR | €10,000 | ↗ |
| 17 May 2023 | Fabio Giovanni PettaFabio Giovanni Petta was fined by the Garante 60,000 EUR for the unauthorized publication of personal data, including names, addresses, and phone numbers, on www.trovanumeri.com. The authority also noted continued processing of the data despite a prior prohibition. The case constitutes a GDPR violation. | IT | Garante | GDPR | €60,000 | ↗ |