BULLETIN №083Last updated · 06 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -22.8%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 09 Mar 2016 | PIXMANIA S.A.S.PIXMANIA S.A.S. was fined by the AEPD in the amount of €20,000 for sending unsolicited commercial emails to a user. The company continued sending messages despite multiple unsubscribe requests, which breached the LSSI. | ES | AEPD | ePrivacy | €20,000 | ↗ |
| 30 Oct 2015 | VACACIONES EDREAMS SOCIEDAD LIMITADA UNIPERSONALVACACIONES EDREAMS SOCIEDAD LIMITADA UNIPERSONAL was fined by the AEPD 20,000 EUR for sending unsolicited commercial emails. The messages continued despite multiple requests from the recipient to unsubscribe. | ES | AEPD | ePrivacy | €20,000 | ↗ |
| 09 Jan 2025 | National Bank of GreeceNational Bank of Greece was fined €20,000 by the HDPA. The authority found that the bank failed to provide data subjects with timely access to their personal data, breaching GDPR Articles 15 and 12. | GR | HDPA | GDPR | €20,000 | ↗ |
| 13 Feb 2025 | D.e.c. soc. coop.The Garante imposed a EUR 20,000 fine on D.e.c. soc. coop. for failing to deactivate an ex-employee's email account after the employment ended. The authority found this conduct breached GDPR principles of fair and transparent processing of personal data. | IT | Garante | GDPR | €20,000 | ↗ |
| 21 Apr 2016 | Estracom s.p.a.Estracom s.p.a. was fined EUR 20,000 by the Garante for retaining customers’ call data for more than thirty days. The authority found this to be a breach of data protection rules. | IT | Garante | GDPR | €20,000 | ↗ |
| 15 Mar 2018 | S.P. Selezione Personale s.r.l.S.P. Selezione Personale s.r.l. was fined by the Garante in the amount of EUR 20,000 for violations related to the processing of personal data in head hunting and recruitment activities. The case concerned irregularities in the handling of candidate data. | IT | Garante | GDPR | €20,000 | ↗ |
| 19 Jan 2024 | GEO ALTERNATIVA, S.L.GEO ALTERNATIVA, S.L. was fined by the AEPD for unlawfully processing personal data. The company included a customer's information in a credit file even though an agreement had already been reached regarding the disputed gas bill. | ES | AEPD | GDPR | €20,000 | ↗ |
| 03 Nov 2015 | VACACIONES EDREAMS SOCIEDAD LIMITADA UNIPERSONALVACACIONES EDREAMS was fined EUR 20,000 by the AEPD for continuing to send newsletters to the complainant despite multiple unsubscribe requests. The authority found this conduct breached Article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €20,000 | ↗ |
| 03 Sept 2025 | SOCIETE AYANT POUR ACTIVITE LA PROMOTION IMMOBILIERE DE LOGEMENTS (procédure simplifiée)CNIL imposed an administrative fine of 20,000 EUR on SOCIETE AYANT POUR ACTIVITE LA PROMOTION IMMOBILIERE DE LOGEMENTS. The case was handled under a simplified procedure. | FR | CNIL | GDPR | €20,000 | ↗ |
| 20 Jul 2017 | Centro Laser s.r.l.Centro Laser s.r.l. was fined EUR 20,400 by the Garante for using inadequate password procedures and failing to provide required information on data processing to users. The case concerns breaches of data protection rules. | IT | Garante | GDPR | €20,400 | ↗ |
| 21 May 2025 | Menarini Silicon Biosystems SpAThe Garante imposed a 21,000 EUR fine on Menarini Silicon Biosystems SpA for violations related to personal data processing. The case involved inadequate safeguards in the use of algorithms to identify at-risk patients and online reports accessible to other patients. | IT | Garante | GDPR | €21,000 | ↗ |
| 05 Jan 2021 | Dane anonimowe (M. Sp. z o.o. z siedzibą w Z. przy)The President of UODO imposed an administrative fine of PLN 21,397 on M. Sp. z o.o. The company failed to cooperate with the authority and did not provide information needed to assess a complaint concerning personal data processing. | PL | UODO | GDPR | €4,705 | ↗ |
| 10 Jul 2024 | Dane anonimowe (Panią A. Z. prowadzącą działalność gospodarczą pod firmą B. z siedzibą w W przy ul.)The President of UODO imposed an administrative fine on an individual conducting business activity. The sanction resulted from failure to cooperate with the authority and from not providing access to personal data and information necessary for supervisory tasks. | PL | UODO | GDPR | €5,129 | ↗ |
| 24 Nov 2011 | Gema s.p.a.Gema s.p.a. was fined by the Italian data protection authority, Garante, for failing to provide the required data protection information to users and entities through its website. The authority also found that the company used a video surveillance system without proper notification, in breach of the Italian Data Protection Code. | IT | Garante | GDPR | €22,000 | ↗ |
| 01 Jan 2025 | SGKLegalThe Greek data protection authority, ΑΠΔΠΧ, imposed a fine of EUR 22,000 on SGKLegal for a GDPR violation. The case involved recorded conversations and deficiencies in personal data protection compliance. | GR | Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (ΑΠΔΠΧ) | GDPR | €22,000 | ↗ |
| 11 Apr 2013 | Travel Factory srl in liquidazioneTravel Factory srl in liquidazione was fined EUR 22,000 by the Garante. The authority found that the company sent promotional faxes and collected data through web forms without providing the required privacy information notice. | IT | Garante | GDPR | €22,000 | ↗ |
| 17 Jul 2024 | Azienda ULSS n. 14The Garante fined Azienda ULSS n. 14 EUR 22,000 for failing to implement adequate technical and organizational measures to ensure data security. The deficiencies resulted in a data breach involving sensitive health data. | IT | Garante | GDPR | €22,000 | ↗ |
| 21 May 2025 | NN ΕλληνικήThe Greek Data Protection Authority imposed a €22,000 fine on NN Ελληνική for refusing to provide recorded telephone calls in response to a data subject access request. The case concerns failure to comply with access rights obligations under data protection law. | GR | Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα | GDPR | €22,000 | ↗ |
| 06 Jun 2018 | Dalmesse Italia s.r.l.Dalmesse Italia s.r.l. was fined €22,000 by the Italian supervisory authority, Garante. The case concerned the processing of personal data, including sensitive health data, without proper compliance with data protection rules. | IT | Garante | GDPR | €22,000 | ↗ |
| 15 Feb 2018 | Innovastem s.r.l.Innovastem s.r.l. was fined by the Garante for processing personal data without providing the required information notice and for handling health-related data without proper consent. The case indicates breaches of transparency obligations and the rules governing the lawful processing of sensitive data. | IT | Garante | GDPR | €22,400 | ↗ |