BULLETIN №083Last updated · 07 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 30 Apr 2025 | BITDEFENDER SRLIn April 2025, the Romanian authority ANSPDCP completed an investigation into BITDEFENDER SRL and found a GDPR violation. The company was fined EUR 10,000. | RO | ANSPDCP | GDPR | €10,000 | ↗ |
| 30 Jun 2022 | Continental Automotive Romania SRLThe company was fined for failing to implement adequate technical and organizational measures and for not periodically assessing those measures in relation to employee video processing. The breach concerned the security of video processing and the prevention of unauthorized processing. | RO | ANSPDCP | GDPR | €2,000 | ↗ |
| 18 Dec 2024 | Electrica Furnizare S.A.The National Supervisory Authority for Personal Data Processing completed an investigation in November 2024 at Electrica Furnizare S.A. and found violations of GDPR provisions. As a result, a fine of EUR 3,000 was imposed. | RO | ANSPDCP | GDPR | €3,000 | ↗ |
| 06 Mar 2023 | Finopro IFN SAFinopro IFN SA was fined by ANSPDCP EUR 2,250 for a data security breach caused by a ransomware attack. The incident led to unauthorized access and loss of integrity and availability of personal data. | RO | ANSPDCP | GDPR | €2,250 | ↗ |
| 26 Jan 2024 | Allium UPI OÜEstonia’s Data Protection Inspectorate fined Allium UPI OÜ, operator of the Apotheka loyalty program, 3 million euros. The authority found that the company failed to protect customer data and used inadequate security measures, exposing the data of more than 750,000 people. | EE | Andmekaitse Inspektsioon | GDPR | €3,000,000 | ↗ |
| 01 Dec 2023 | ENDESA, S.A.The Spanish data protection authority imposed a EUR 6.1 million fine on ENDESA in December 2023. The case involved a security breach that led to the sale of customer personal data through Facebook ads. | ES | Agencia Española de Protección de Datos | GDPR | €6,100,000 | ↗ |
| 15 Jan 2021 | VODAFONE ESPAÑA, S.A.U.The Spanish data protection authority imposed a total fine of EUR 8,150,000 on VODAFONE ESPAÑA, S.A.U. The sanction covers breaches of GDPR Articles 28 and 44, as well as additional violations of LSSICE and tax-related rules. | ES | Agencia Española de Protección de Datos | GDPR | €8,150,000 | ↗ |
| 01 Jan 2026 | CloudflareAGCOM issued an ordinanza ingiunzione against Cloudflare under the Digital Services Act. The fine is 100,000 EUR and relates to a breach of DSA obligations. | IT | AGCOM | DSA | €100,000 | ↗ |
| 08 Feb 2024 | AREIA CONSULTING, LTDAREIA CONSULTING, LTD was fined by the AEPD in the amount of 2,000 EUR for sending unsolicited commercial emails without prior recipient consent. The authority found this conduct breached Article 21 of the LSSI. | ES | AEPD | ePrivacy | €2,000 | ↗ |
| 23 Jun 2023 | LINKEDIN IRELAND LIMITEDThe AEPD fined LinkedIn Ireland Limited EUR 10,000 for sending advertising emails after the recipient had opted out. The authority found a breach of Article 21.1 of the LSSI governing unsolicited marketing communications. | ES | AEPD | ePrivacy | €10,000 | ↗ |
| 14 Apr 2010 | Espectáculos InterfaceEspectáculos Interface was fined EUR 1,200 by the AEPD for sending commercial emails without prior consent from recipients. The case concerned Article 21 of the LSSI, which governs unsolicited commercial communications. | ES | AEPD | ePrivacy | €1,200 | ↗ |
| 09 Mar 2023 | EASYJET AIRLINE COMPANY LIMITEDEasyJet Airline Company Limited was fined by the AEPD 10,000 EUR for failing to provide timely access to personal data requested by an individual. The authority found a breach of Article 15 GDPR, which governs the right of access. | ES | AEPD | GDPR | €10,000 | ↗ |
| 12 Feb 2020 | AEMA HISPANICA, S.L.AEMA HISPANICA, S.L. was fined by the AEPD 6,000 EUR for sending one employee's payroll to another employee. The incident constituted a breach of data protection rules. | ES | AEPD | GDPR | €6,000 | ↗ |
| 25 Jul 2021 | CALDERERIA Y SOLDADURA DE ESTRUCTURAS METALICAS, S.L.The company was fined by the AEPD for processing personal data without consent, which breaches Article 6 of the GDPR. The case indicates that no valid legal basis was in place for the processing activity. | ES | AEPD | GDPR | €5,000 | ↗ |
| 01 Jan 2015 | LA QUINIELA INTELIGENTE S.L.LA QUINIELA INTELIGENTE S.L. was fined by the AEPD EUR 1,800 for sending unsolicited commercial emails. The messages did not provide recipients with an opt-out mechanism, which breached Article 21 of the LSSI. | ES | AEPD | ePrivacy | €1,800 | ↗ |
| 28 Apr 2026 | RESIDENCIAL ETXE-LAN, S.L.RESIDENCIAL ETXE-LAN, S.L. was fined by the AEPD for failing to provide the required information to the supervisory authority. The breach concerned Article 58(1) GDPR and hindered the authority’s supervisory powers. | ES | AEPD | GDPR | €3,000 | ↗ |
| 23 Mar 2023 | B.B.B.B.B.B. was fined 300 EUR by the AEPD for installing surveillance cameras that could capture images of a neighboring property without prior authorization. The authority found this to be a breach of the data minimization principle under Article 5(1)(c) GDPR. | ES | AEPD | GDPR | €300 | ↗ |
| 07 Mar 2012 | INSTITUTO TECNOLOGICO AUTESEL SLINSTITUTO TECNOLOGICO AUTESEL SL was fined by the AEPD EUR 600 for sending unsolicited commercial emails. The conduct breached Article 21 of the LSSI, which restricts marketing communications without prior consent. | ES | AEPD | ePrivacy | €600 | ↗ |
| 19 Apr 2023 | MULTIGAS ASESORES S.L.MULTIGAS ASESORES S.L. was fined EUR 500 by the AEPD. The company failed to provide access required under Article 58(1) GDPR, obstructing the data protection authority’s inspection function. | ES | AEPD | GDPR | €500 | ↗ |
| 27 Oct 2014 | TRADEINN RETAIL SERVICES, S.L.TRADEINN RETAIL SERVICES, S.L. was fined EUR 60,000 by the AEPD for sending unsolicited commercial emails to a non-customer. The authority found this breached Article 21 of the LSSI on electronic marketing communications. | ES | AEPD | ePrivacy | €60,000 | ↗ |