BULLETIN №083Last updated · 08 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.6%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 29 Apr 2025 | Cooperativa Sociale QuadrifoglioThe Garante imposed a fine of EUR 20,000 on Cooperativa Sociale Quadrifoglio for violations related to data processing. The case concerned non-compliance with personal data protection requirements. | IT | Garante | GDPR | €20,000 | ↗ |
| 10 Jul 2025 | Cooperativa Sociale CoopseliosCooperativa Sociale Coopselios was fined by the Garante €10,000 for failing to properly handle data subject requests. The нарушения concerned the GDPR rights of access, rectification, and data portability. | IT | Garante | GDPR | €10,000 | ↗ |
| 19 Sept 2013 | Cooperativa di servizi AggregoCooperativa di servizi Aggrego was fined €6,400 by the Garante. The case concerned the sending of unsolicited promotional faxes without prior consent, in breach of data protection rules. | IT | Garante | GDPR | €6,400 | ↗ |
| 04 Nov 2019 | Coöperatie VGZ U.A.The Autoriteit Persoonsgegevens imposed a EUR 150,000 penalty on Coöperatie VGZ U.A. for failing to implement appropriate technical measures to protect personal data from unauthorized access. The authority found a breach of data protection law. | NL | AP | GDPR | €150,000 | ↗ |
| 04 Nov 2019 | Coöperatie Menzis U.A.The Dutch Data Protection Authority, AP, imposed a fine of EUR 150,000 on Coöperatie Menzis U.A. The authority found that the company had inadequate technical measures to prevent unauthorized access to personal health data. | NL | AP | GDPR | €150,000 | ↗ |
| 04 Nov 2019 | Coöperatie Menzis U.A.Menzis was fined by the AP for failing to implement appropriate technical measures to protect personal data. The authority found a breach of Article 32 GDPR. | NL | AP | GDPR | €50,000 | ↗ |
| 21 May 2021 | COOPERA RC SERVICES, S.L.COOPERA RC SERVICES, S.L. was fined by the AEPD 2,000 EUR for failing to provide the contact details needed to exercise data protection rights. The authority found a breach of the information obligations under Article 13 GDPR. | ES | AEPD | GDPR | €2,000 | ↗ |
| 05 Mar 2020 | CoolblueCoolblue was fined 40,000 EUR by the Dutch Data Protection Authority, Autoriteit Persoonsgegevens, for unlawfully collecting personal data through cookies without active consent. The violation occurred in 2020, and the company updated its cookie banner after the authority’s investigation. | NL | Autoriteit Persoonsgegevens | GDPR | €40,000 | ↗ |
| 25 Mar 2021 | Convitto Nazionale Statale "Giordano Bruno"Convitto Nazionale Statale "Giordano Bruno" was fined by the Garante for breaching data protection principles. The authority found that personal data had been made available online for an extended period, contrary to the principles of lawfulness, fairness, transparency, and data minimization. | IT | Garante | GDPR | €1,000 | ↗ |
| 12 Feb 2026 | Conversion Media S.r.l.Conversion Media S.r.l. was fined EUR 10,000 by the Garante for failing to meet data protection obligations. The case concerned telemarketing activities in which required transparency and information duties toward data subjects were not fulfilled. | IT | Garante | GDPR | €10,000 | ↗ |
| 19 Sept 2016 | CONVERSALES INNOVA, S.L.CONVERSALES INNOVA, S.L. was fined by the AEPD €3,000 for sending unsolicited commercial emails without prior consent from recipients. This conduct breached Article 21 of the LSSI. | ES | AEPD | ePrivacy | €3,000 | ↗ |
| 11 Jul 2012 | Control Distribución Marketing, S.L.Control Distribución Marketing, S.L. was fined by the AEPD for sending unsolicited commercial emails. The company also failed to honor requests to stop such communications, breaching Article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €1,200 | ↗ |
| 30 Oct 2013 | Continental Terme srlContinental Terme srl was fined EUR 12,400 by the Garante for providing inadequate privacy notices and obtaining a single consent for multiple data processing activities. The authority found this to be a breach of the Italian Data Protection Code. | IT | Garante | GDPR | €12,400 | ↗ |
| 30 Jun 2022 | Continental Automotive Romania SRLThe company was fined for failing to implement adequate technical and organizational measures and for not periodically assessing those measures in relation to employee video processing. The breach concerned the security of video processing and the prevention of unauthorized processing. | RO | ANSPDCP | GDPR | €2,000 | ↗ |
| 05 Jan 2022 | CONTIMAG INVEST, S.L.CONTIMAG INVEST, S.L. was fined by the AEPD 1,200 EUR for operating a video surveillance system without the required informational signage. The authority found a breach of Article 13 GDPR on transparency and information duties. | ES | AEPD | GDPR | €1,200 | ↗ |
| 25 Jul 2019 | CONTAPUBLI RIOJA, S.L. (GESTIRIOJA)CONTAPUBLI RIOJA, S.L. was fined by the AEPD 2,500 EUR for sending unsolicited commercial emails. The conduct continued despite the recipient's objection and request for data deletion. | ES | AEPD | ePrivacy | €2,500 | ↗ |
| 26 Jun 2008 | Contact point s.r.l.Contact point s.r.l. was fined by the Garante 10,000 EUR for breaching data protection rules. The case concerned improper handling of personal data during opinion surveys. | IT | Garante | GDPR | €10,000 | ↗ |
| 26 Jun 2008 | Contact point s.r.l.Contact point s.r.l. was fined 3,000 EUR by the Garante for violating data protection rules. The case concerned improper handling of personal data during opinion surveys. | IT | Garante | GDPR | €3,000 | ↗ |
| 11 Oct 2023 | CONSULTORÍA PERITACIONES ALMERIENSES, S.L.The company was fined by the AEPD 1,000 EUR for not having a privacy policy on its website. The issue arose because it collected personal data through a contact form, triggering the information duties under GDPR Article 13. | ES | AEPD | GDPR | €1,000 | ↗ |
| 13 Dec 2022 | CONSULTORÍA PERITACIONES ALMERIENSES, S.L.The company did not respond to a data access request and failed to publish information on data processing or the data controller on its website. AEPD treated this as a breach of the information obligations under Article 13 GDPR. | ES | AEPD | GDPR | €2,000 | ↗ |