BULLETIN №083Last updated · 09 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.1%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 05 Jul 2023 | Anonymisé (CNPD decision-05-fr-2023)The company did not inform data subjects about the recipients of their personal data. It also failed to implement appropriate technical and organizational measures required under the GDPR, breaching Articles 13 and 24. | LU | CNPD | GDPR | €1,500 | ↗ |
| 05 Jul 2023 | UPMOBILE SOLUTIONS, S.L.UPMOBILE SOLUTIONS, S.L. was fined EUR 500 by the AEPD for failing to provide access during the investigation. The authority treated this as a breach of Article 58(1) GDPR and an obstruction of its supervisory function. | ES | AEPD | GDPR | €500 | ↗ |
| 05 Jul 2023 | BILBAO AD INFINITUM, S.L.BILBAO AD INFINITUM, S.L. was fined by the AEPD EUR 500 for installing surveillance cameras directed at a public square without prior administrative authorization. The authority found that this conduct breached GDPR requirements on lawful processing. | ES | AEPD | GDPR | €500 | ↗ |
| 06 Jul 2023 | AcegasApsAmga S.p.A.AcegasApsAmga S.p.A. was fined €10,000 by the Italian supervisory authority, Garante. The sanction concerned the company’s failure to respond to a data subject’s request for access to personal data, in breach of GDPR Article 15. | IT | Garante | GDPR | €10,000 | ↗ |
| 06 Jul 2023 | Romagna Dolciumi s.r.l.Romagna Dolciumi s.r.l. was fined by the Garante in the amount of €10,000 for failing to provide an employee with access to their personal data. The authority also found that the company engaged a private investigative agency to carry out defensive investigations without proper authorization, in breach of GDPR requirements. | IT | Garante | GDPR | €10,000 | ↗ |
| 06 Jul 2023 | Comune di AvianoThe Garante fined Comune di Aviano EUR 3,000 for publishing employees’ personal data, including names and productivity bonuses, on its institutional website. The authority found a breach of data minimization and transparency principles. | IT | Garante | GDPR | €3,000 | ↗ |
| 06 Jul 2023 | SUROVI (Surovi Ristorante indiano e kebab di Chowdhury Monika)The Garante fined SUROVI restaurant EUR 1,000 for operating a video surveillance system without the required privacy notice. The authority found this to be a breach of Article 13 of the GDPR. | IT | Garante | GDPR | €1,000 | ↗ |
| 06 Jul 2023 | Ristorante Francesco s.r.l.Ristorante Francesco s.r.l. was fined by the Garante in the amount of 5,000 EUR for operating surveillance cameras without the required notices to affected individuals. The authority treated this as a breach of privacy rules. | IT | Garante | GDPR | €5,000 | ↗ |
| 06 Jul 2023 | Provvedimento del 6 luglio 2023 [9925450The Garante imposed a EUR 2,000 fine on an individual for posting images of other people on social media without their consent. The authority found a breach of GDPR rights, including the rights to erasure and objection. | IT | Garante | GDPR | €2,000 | ↗ |
| 06 Jul 2023 | Regione SicilianaThe Garante fined Regione Siciliana EUR 7,000 for publishing personal data of numerous individuals, including sensitive employment-related information. The authority found breaches of lawfulness, fairness, transparency, and data minimization principles. | IT | Garante | GDPR | €7,000 | ↗ |
| 06 Jul 2023 | Ad Maiora Distribuzioni S.a.s. di Editrice Ad Maiora S.r.l.s. & C.Ad Maiora Distribuzioni was fined EUR 15,000 by the Garante. The authority found that the company made unsolicited promotional calls and failed to respond to requests for access to and deletion of personal data. | IT | Garante | GDPR | €15,000 | ↗ |
| 07 Jul 2023 | THE COMAKING SPACE, S.L.U.THE COMAKING SPACE, S.L.U. was fined by the AEPD EUR 2,000 for sending unsolicited commercial emails without recipient consent. The conduct breached the LSSI rules on electronic marketing communications. | ES | AEPD | ePrivacy | €2,000 | ↗ |
| 07 Jul 2023 | Személyes adatok forrása és adatgyűjtés távhőszolgáltatás nyújtásáhozThe supervisory authority found a GDPR breach because the controller did not inform data subjects about the source of their personal data. It also failed to demonstrate accountability and compliance with data protection principles. | HU | NAIH | GDPR | €2,580 | ↗ |
| 09 Jul 2023 | PROSULTING, S.L.N.E.PROSULTING, S.L.N.E. was fined by the AEPD in the amount of 1,000 EUR for failing to provide data subjects with the information required under Article 13 GDPR. The case concerned a lack of proper notice about the processing of personal data. | ES | AEPD | GDPR | €1,000 | ↗ |
| 10 Jul 2023 | C.C.C.The entity was fined for operating a video surveillance system that captured public areas and neighboring properties without the required authorization. Required informational signage was also not displayed. | ES | AEPD | GDPR | €600 | ↗ |
| 10 Jul 2023 | B.B.B.The AEPD imposed a 300 EUR fine on B.B.B. after a surveillance camera was directed toward the complainant's property. The authority found a breach of data protection rules due to unauthorized processing of image data. | ES | AEPD | GDPR | €300 | ↗ |
| 12 Jul 2023 | Dane anonimowe (Panią K.W. prowadzącą działalność gospodarczą pod nazwą W. z miejscem wykonywania działalności w O. przy ul.)UODO imposed an administrative fine on the business for failing to report a personal data breach to the supervisory authority within 72 hours. The authority also found that the affected individuals were not notified without undue delay. | PL | UODO | GDPR | €2,651 | ↗ |
| 12 Jul 2023 | B.B.B.The entity installed a surveillance camera without authorization and captured images of communal areas. This breached Article 6(1) GDPR. | ES | AEPD | GDPR | €300 | ↗ |
| 13 Jul 2023 | B.B.B.B.B.B. was fined by the AEPD 600 EUR for installing a surveillance camera directed at a public area without prior administrative authorization and without proper signage. The authority found breaches of Articles 5(1)(c) and 13 GDPR. | ES | AEPD | GDPR | €600 | ↗ |
| 13 Jul 2023 | EUROPA PRESS DE CATALUNYA, S.A.EUROPA PRESS DE CATALUNYA, S.A. was fined by the AEPD 50,000 EUR for publishing audio of a victim's court statement in a high-profile case. The authority found that the company processed excessive personal data in breach of GDPR Article 5(1)(c). | ES | AEPD | GDPR | €50,000 | ↗ |