BULLETIN №081Last updated · 27 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -20.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 08 Aug 2022 | EUROPYMES SERVICIOS INTEGRALES S.L.EUROPYMES SERVICIOS INTEGRALES S.L. failed to comply with a data deletion request, which constitutes a breach of Article 17 GDPR. The AEPD imposed a fine of EUR 1,000, later reduced due to early payment. | ES | AEPD | GDPR | €1,000 | ↗ |
| 16 Sept 2021 | Farpa s.r.l.Farpa s.r.l. was fined by the Garante 1,000 EUR for failing to provide proper information to data subjects, including workers, about the processing of personal data through a video surveillance system. The authority found that the information duty toward affected individuals was not met adequately. | IT | Garante | GDPR | €1,000 | ↗ |
| 13 Jan 2022 | Villa Masi Residenza per anzianiVilla Masi Residenza per anziani was fined EUR 1,000 by the Garante for a video surveillance system that did not comply with GDPR Article 13. The authority found that the required information notices for monitored individuals were not properly provided. | IT | Garante | GDPR | €1,000 | ↗ |
| 13 Aug 2025 | TELECONTACT LIST S.L.TELECONTACT LIST S.L. was fined by the AEPD €1,000 for failing to respond to a data subject’s requests to exercise the rights of access and erasure. The authority found a breach of GDPR obligations, including Article 17. | ES | AEPD | GDPR | €1,000 | ↗ |
| 18 Jul 2025 | ***COMUNIDAD.1The entity was fined for including personal data in community meeting minutes distributed to residents and for inadequate security measures on its community website. The authority found that these failures breached Article 32 of the GDPR on processing security. | ES | AEPD | GDPR | €1,000 | ↗ |
| 14 Apr 2025 | Office Nova Concept SRLThe National Supervisory Authority for Personal Data Processing imposed a fine on Office Nova Concept SRL for breaching Article 17 of the GDPR. The case concerned non-compliance with obligations related to the right to erasure. | RO | ANSPDCP | GDPR | €1,000 | ↗ |
| 28 Mar 2024 | SIA “JK Media group”The DVI imposed a fine of EUR 1,000 on SIA “JK Media group”. The decision is final and has entered into force. | LV | DVI | GDPR | €1,000 | ↗ |
| 13 Feb 2024 | DIGIMAN ALICANTE, S.L.DIGIMAN ALICANTE, S.L. was fined by the AEPD 1,000 EUR for operating a video surveillance system without the required signage. The authority found that the lack of notice breached the information obligations under GDPR Article 13. | ES | AEPD | GDPR | €1,000 | ↗ |
| 23 Oct 2025 | Provvedimento del 23 ottobre 2025 [10195910]A fine of EUR 1,000 was imposed for the unlawful online publication of personal data by a local authority. The conduct breached core data protection principles. | IT | Garante | GDPR | €1,000 | ↗ |
| 22 Nov 2023 | ASOCIACIÓN COMUNIDAD DE VECINOS R.R.R.The association unlawfully processed personal data by sending all members a letter containing personal details of a person who was not part of the association. The authority found a breach of Article 6(1) GDPR and imposed a fine. | ES | AEPD | GDPR | €1,000 | ↗ |
| 30 May 2024 | Corint Logistic SRLCorint Logistic SRL was fined EUR 1,000 by ANSPDCP for GDPR violations. The case concerned non-compliant processing of personal data. | RO | ANSPDCP | GDPR | €1,000 | ↗ |
| 09 Jul 2023 | PROSULTING, S.L.N.E.PROSULTING, S.L.N.E. was fined by the AEPD in the amount of 1,000 EUR for failing to provide data subjects with the information required under Article 13 GDPR. The case concerned a lack of proper notice about the processing of personal data. | ES | AEPD | GDPR | €1,000 | ↗ |
| 22 Jan 2024 | ASILO DE ANCIANOS SANTO DOMINGO Y SANTA ELOISAThe organization was fined for repeatedly sending emails with visible recipient addresses. The case involved a breach of data protection principles and a failure to implement adequate security measures. | ES | AEPD | GDPR | €1,000 | ↗ |
| 11 Oct 2023 | CONSULTORÍA PERITACIONES ALMERIENSES, S.L.The company was fined by the AEPD 1,000 EUR for not having a privacy policy on its website. The issue arose because it collected personal data through a contact form, triggering the information duties under GDPR Article 13. | ES | AEPD | GDPR | €1,000 | ↗ |
| 27 Jul 2016 | MUDICOM IMPORT S.L.MUDICOM IMPORT S.L. was fined by the AEPD EUR 1,000 for sending unsolicited commercial emails without the recipient's consent. The authority found this conduct breached Article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €1,000 | ↗ |
| 25 Mar 2024 | KUR KLINIKUM, S.L.KUR KLINIKUM, S.L. was fined EUR 1,000 by the AEPD for failing to comply with a data protection authority resolution. The case concerned the right of access to personal data. | ES | AEPD | GDPR | €1,000 | ↗ |
| 30 Nov 2023 | Techno Security s.r.l.Techno Security s.r.l. was fined by the Garante in the amount of 1,000 EUR for failing to respond to a data subject request and for inadequate security measures in its installed security system. The authority found that these failures breached data protection rules. | IT | Garante | GDPR | €1,000 | ↗ |
| 11 Jun 2024 | APARTAMENTOS BUENAVISTA HOMEAPARTAMENTOS BUENAVISTA HOME was fined EUR 1,000 by the AEPD for requesting guests to submit electronic images of their ID documents. The authority found that this practice breached the GDPR data minimization principle. | ES | AEPD | GDPR | €1,000 | ↗ |
| 07 Dec 2023 | Sirio S.p.A.Sirio S.p.A. was fined EUR 1,000 by the Garante for violating data protection rules. The case concerned the improper handling of an employee’s personal data in connection with issuing a new bank card. | IT | Garante | GDPR | €1,000 | ↗ |
| 31 Jan 2023 | Dent Estet Clinic SADent Estet Clinic SA was fined by ANSPDCP EUR 1,000 for breaches of the transparency obligations under GDPR Articles 12–14. The case concerned inadequate compliance with information duties toward data subjects. | RO | ANSPDCP | GDPR | €1,000 | ↗ |