BULLETIN №083Last updated · 10 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.1%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 30 Aug 2023 | LORO PARQUE, S.A.LORO PARQUE, S.A. was fined by the AEPD 250,000 EUR for processing biometric data without a proper legal basis. The authority classified this as a very serious breach of Article 9 GDPR. | ES | AEPD | GDPR | €250,000 | ↗ |
| 30 Aug 2023 | Dane anonimowe (A. S.A. z siedzibą w W. przy ul.)The President of UODO imposed an administrative fine of PLN 56,592 on the company. The sanction resulted from failure to cooperate with the authority and from not providing access to personal data and information necessary for its tasks. | PL | UODO | GDPR | €12,652 | ↗ |
| 31 Aug 2023 | GEDI News Network S.p.a.The Garante imposed a EUR 30,000 fine on GEDI News Network S.p.a. for publishing a photo of minors with insufficient pixelation, making them identifiable. The authority found this to be a breach of data protection rules concerning children. | IT | Garante | GDPR | €30,000 | ↗ |
| 31 Aug 2023 | operator persoană fizicăA EUR 2,000 fine was imposed on an individual operator for photographing or filming a patient in a medical unit without consent. The authority also applied a corrective measure to ensure compliance of data processing operations with the GDPR. | RO | ANSPDCP | GDPR | €2,000 | ↗ |
| 31 Aug 2023 | B.B.B.B.B.B. was fined 300 EUR by the AEPD after a complaint about a surveillance camera installed by a neighbor. The authority found that the device could have captured images of a private property and a private street, creating a potential data protection breach. | ES | AEPD | GDPR | €300 | ↗ |
| 31 Aug 2023 | Provvedimento del 31 agosto 2023 [9938463]The decision concerned a breach of rules on the processing of health data by a medical center. Garante imposed a fine of EUR 10,000. | IT | Garante | GDPR | €10,000 | ↗ |
| 31 Aug 2023 | RCS Mediagroup S.p.a.RCS Mediagroup S.p.a. was fined by the Garante EUR 10,000 for publishing an article on the Corriere della Sera website. The article included a photograph of a holographic will that disclosed a witness’s personal data without consent. | IT | Garante | GDPR | €10,000 | ↗ |
| 31 Aug 2023 | Robin S.r.l.The Garante fined Robin S.r.l. 25,000 EUR for publishing a photograph of minors with insufficient anonymization. The case concerns a breach of personal data protection rules applicable to children. | IT | Garante | GDPR | €25,000 | ↗ |
| 31 Aug 2023 | Ordine degli Avvocati di XXThe Garante fined the Ordine degli Avvocati di XX EUR 8,000 for unlawfully disclosing personal data without a legal basis. The authority found breaches of the principles of lawfulness, fairness, and transparency. | IT | Garante | GDPR | €8,000 | ↗ |
| 01 Sept 2023 | TikTok Technology Limited (TTL)The Irish DPC imposed a fine of EUR 345,000,000 on TikTok Technology Limited (TTL) following an inquiry. The matter remains ongoing because the decision is under appeal. | IE | DPC | GDPR | €345,000,000 | ↗ |
| 04 Sept 2023 | ASSOCIACIO OASIS CULTURALASSOCIACIO OASIS CULTURAL was fined by the AEPD EUR 10,000 for unlawful processing of personal data. The case concerned the publication on TikTok of a video showing minors performing dances with sexual connotations without a legal basis under Article 6(1) GDPR. | ES | AEPD | GDPR | €10,000 | ↗ |
| 06 Sept 2023 | Simply Connecting LtdSimply Connecting Ltd sent 441,830 direct marketing text messages to individuals in breach of regulation 22 of PECR. The ICO imposed a £40,000 fine and issued an enforcement notice. | GB | ICO | ePrivacy | €46,780 | ↗ |
| 06 Sept 2023 | Háskóli ÍslandsThe University of Iceland was fined for inadequate signage and insufficient information about electronic surveillance on its premises. The authority found a breach of GDPR transparency and information obligations. | IS | Persónuvernd | GDPR | €10,425 | ↗ |
| 07 Sept 2023 | IBERIA LÍNEAS AÉREAS DE ESPAÑA, S.A. OPERADORAIberia was fined by the AEPD EUR 50,000 for a breach related to personal data handling during a flight from Quito to Dublin. Passengers were asked to provide identity documents and marriage certificates to justify travel during COVID-19 restrictions. | ES | AEPD | GDPR | €50,000 | ↗ |
| 07 Sept 2023 | ISRA Center Marketing Research SRLIn August 2023, the Romanian supervisory authority ANSPDCP completed an investigation into ISRA Center Marketing Research SRL. It found a GDPR violation and imposed a fine of EUR 2,000. | RO | ANSPDCP | GDPR | €2,000 | ↗ |
| 12 Sept 2023 | LEADDESK, S.L.LEADDESK, S.L. was fined by the AEPD for failing to provide access to information required under Article 58(1) of the GDPR. The conduct was treated as an obstruction of the data protection authority’s investigative functions. | ES | AEPD | GDPR | €4,000 | ↗ |
| 14 Sept 2023 | GFB One s.r.l.GFB One s.r.l. was fined EUR 90,000 by the Italian Garante. The case concerned its failure to respond to requests for information relating to the unauthorized activation of SIM cards and the misuse of personal identification documents. | IT | Garante | GDPR | €90,000 | ↗ |
| 14 Sept 2023 | društvo XThe company processed excessive personal data, including CVC/CVV numbers and copies of identity documents, without a legal basis during hotel booking. It also failed to provide transparent information to data subjects, which constitutes a GDPR breach. | HR | AZOP | GDPR | €15,000 | ↗ |
| 14 Sept 2023 | Azienda Sanitaria dell'Alto Adige - Suedtiroler SanitaetsbetriebThe Garante fined Azienda Sanitaria dell'Alto Adige EUR 10,000 for failing to provide an adequate response to a data subject's rights request. The case also concerned the processing of sensitive data related to vaccination status. | IT | Garante | GDPR | €10,000 | ↗ |
| 14 Sept 2023 | Comune di San SeveroThe Municipality of San Severo was fined EUR 10,000 by the Garante for publishing employees’ personal data, including names and productivity bonuses, on its institutional website. The authority found breaches of lawfulness, fairness, transparency, and data minimization principles. | IT | Garante | GDPR | €10,000 | ↗ |