BULLETIN №083Last updated · 09 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.1%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 31 May 2023 | D.D.D.The entity installed surveillance cameras without authorization, breaching Article 5(1)(c) of the GDPR. The AEPD imposed a fine of EUR 500. | ES | AEPD | GDPR | €500 | ↗ |
| 31 May 2023 | Dane anonimowe (G. Sp. z o.o. z siedzibą w K. przy ul.)The President of UODO imposed an administrative fine of PLN 14,148 on G. Sp. z o.o. The sanction was issued for failing to cooperate with the authority in the performance of its duties and for not providing access to information necessary for those duties. | PL | UODO | GDPR | €3,119 | ↗ |
| 31 May 2023 | VODAFONE ESPAÑA, S.A.U.The AEPD fined VODAFONE ESPAÑA, S.A.U. 70,000 EUR for failing to implement adequate security measures. This allowed a third party to impersonate a customer, change contact details, and gain unauthorized access to personal and banking data. | ES | AEPD | GDPR | €70,000 | ↗ |
| 31 May 2023 | Dane anonimowe (P. Sp. z o.o. z siedzibą w W. przy ul.)UODO imposed a PLN 47,160 fine on the anonymous company for failing to implement appropriate technical and organizational measures to secure personal data processing in IT systems. The authority also found a lack of regular testing, measuring, and evaluation of the effectiveness of those measures, as well as failure to report the personal data breach without undue delay. In addition, the company did not notify affected individuals without undue delay despite a high risk to their rights and freedoms. | PL | UODO | GDPR | €10,395 | ↗ |
| 01 Jun 2023 | Comune di GuardiagreleComune di Guardiagrele was fined EUR 5,000 by the Garante for failing to provide an adequate response to a data access request. The authority found a breach of the principles of lawfulness, fairness, and transparency in data processing. | IT | Garante | GDPR | €5,000 | ↗ |
| 01 Jun 2023 | Cooperjob S.p.A.Cooperjob S.p.A. was fined EUR 20,000 by the Garante for failing to respond within the required timeframe to a job applicant’s request to delete personal data. The authority found a breach of GDPR Article 12 on timely handling of data subject requests. | IT | Garante | GDPR | €20,000 | ↗ |
| 01 Jun 2023 | Comune di NapoliComune di Napoli was fined for improperly communicating performance evaluation results of former employees. The authority found breaches of lawfulness, fairness, transparency, and data minimization principles. | IT | Garante | GDPR | €3,000 | ↗ |
| 01 Jun 2023 | Ew Business Machines S.p.A.Ew Business Machines S.p.A. was fined 20,000 EUR by the Garante. The authority found that the company used a surveillance system without proper notice, collected employee fingerprints, and tracked employee locations through mobile apps without adequate transparency. | IT | Garante | GDPR | €20,000 | ↗ |
| 01 Jun 2023 | Provvedimento del 1° giugno 2023 [9909889]The Garante imposed a 10,000 EUR fine on a healthcare center for incorrectly sending automatic SMS reminders to a patient due to a data misattribution error. The case concerned GDPR provisions on data processing and security. | IT | Garante | GDPR | €10,000 | ↗ |
| 01 Jun 2023 | Thin SrlThin Srl was fined EUR 15,000 by the Garante for breaching the GDPR principles of lawfulness, fairness, and transparency in data processing. The case concerned processing activities linked to a medical project. | IT | Garante | GDPR | €15,000 | ↗ |
| 01 Jun 2023 | AUSL Toscana Sud EstThe Garante fined AUSL Toscana Sud Est 20,000 EUR for the unlawful dissemination of a patient's health data. The authority found a breach of data protection principles. | IT | Garante | GDPR | €20,000 | ↗ |
| 01 Jun 2023 | NH Italia S.p.A.NH Italia S.p.A. was fined EUR 200,000 by the Garante for failing to appoint specific data processors responsible for the installation and maintenance of video surveillance systems. The authority found this breached the GDPR principles of lawful, fair, and transparent processing of personal data. | IT | Garante | GDPR | €200,000 | ↗ |
| 02 Jun 2023 | Dane anonimowe (T. sp. z o.o. z siedzibą w K. przy ul.)The President of UODO imposed a fine of PLN 18,864 on T. sp. z o.o. The company failed to cooperate with the authority in the performance of its duties and did not provide access to information necessary for those duties. | PL | UODO | GDPR | €4,194 | ↗ |
| 05 Jun 2023 | HIPER STORE, S.L.HIPER STORE, S.L. was fined EUR 500 by the AEPD for not properly signposting its video surveillance system. The authority also found that the company failed to provide customers with the required data protection information under Article 13 GDPR. | ES | AEPD | GDPR | €500 | ↗ |
| 05 Jun 2023 | CHINA CENTER LLEIDACHINA CENTER LLEIDA was fined EUR 700 by the AEPD for failing to properly sign its video surveillance system and for not providing customers with required data protection information. The authority found a breach of Article 13 of the GDPR. | ES | AEPD | GDPR | €700 | ↗ |
| 06 Jun 2023 | S.C.In May 2023, ANSPDCP completed an investigation at operator S.C. and found a violation of GDPR provisions. As a result, a fine of EUR 3,000 was imposed. | RO | ANSPDCP | GDPR | €3,000 | ↗ |
| 07 Jun 2023 | ELECTRAWORKS - CEUTA, S.A.ELECTRAWORKS - CEUTA, S.A. did not comply with a data deletion request and retained personal data for 10 years without proper justification. The AEPD found this to be a breach of Article 13 GDPR and imposed a 10,000 EUR fine. | ES | AEPD | GDPR | €10,000 | ↗ |
| 08 Jun 2023 | La Rinascente S.p.A.La Rinascente S.p.A. was fined by the Garante for unauthorized access to customer data and its modification. The breach led to the issuance of a new loyalty card containing incorrect personal details. | IT | Garante | GDPR | €300,000 | ↗ |
| 08 Jun 2023 | AziendaThe company was fined for failing to process personal data in a lawful, fair, and transparent manner. The authority also found breaches of data minimization and inadequate security measures. | IT | Garante | GDPR | €5,000 | ↗ |
| 08 Jun 2023 | RCS Mediagroup S.p.a.RCS Mediagroup S.p.a. was fined EUR 40,660 by the Italian Garante. The case concerned the publication of unauthorized photographs of a private individual taken inside her home, which infringed her privacy rights. | IT | Garante | GDPR | €40,660 | ↗ |