BULLETIN №083Last updated · 10 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.1%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 28 Sept 2023 | COMMERCE INTERENTREPRISES DE PRODUITS SURGELES (procédure simplifiée)The CNIL imposed an administrative fine of EUR 20,000 on COMMERCE INTERENTREPRISES DE PRODUITS SURGELES under a simplified procedure. The case concerns a confirmed breach of rules supervised by the CNIL. | FR | CNIL | GDPR | €20,000 | ↗ |
| 28 Sept 2023 | Asl Napoli 3 SudThe Garante fined Asl Napoli 3 Sud EUR 30,000 for inadequate security measures that led to a data breach. The incident caused limited service disruption. | IT | Garante | GDPR | €30,000 | ↗ |
| 28 Sept 2023 | SOCIETE DE FABRICATION DE PRODUITS DE CONSOMMATION COURANTE EN MATIERES PLASTIQUES (procédure simplifiée)The CNIL imposed a fine of EUR 20,000 on SOCIETE DE FABRICATION DE PRODUITS DE CONSOMMATION COURANTE EN MATIERES PLASTIQUES under a simplified procedure. The decision concerns a breach of the rules covered by the administrative proceeding. | FR | CNIL | GDPR | €20,000 | ↗ |
| 28 Sept 2023 | SOCIETE AYANT UNE ACTIVITE DE COMMERCE DE DETAIL OPTIQUE (procédure simplifiée)CNIL imposed a fine of EUR 20,000 on SOCIETE AYANT UNE ACTIVITE DE COMMERCE DE DETAIL OPTIQUE and issued an injunction. The case was handled under a simplified procedure. | FR | CNIL | GDPR | €20,000 | ↗ |
| 28 Sept 2023 | Azienda Usl Toscana centroThe Garante imposed a fine of EUR 50,000 on Azienda Usl Toscana centro for data protection violations related to the former Sanatorio Guido Banti premises. The case concerned irregularities in the processing of personal data in that context. | IT | Garante | GDPR | €50,000 | ↗ |
| 28 Sept 2023 | Axpo Italia S.p.A.Axpo Italia S.p.A. was fined by the Garante 10,000,000 EUR for processing inaccurate and outdated personal data of customers. This led to the conclusion of unsolicited contracts for electricity and gas supply. | IT | Garante | GDPR | €10,000,000 | ↗ |
| 28 Sept 2023 | Palombaro s.r.l.Palombaro s.r.l. was fined by the Garante in the amount of 3,000 EUR for operating a video surveillance system without adequate informational signage. The authority found a breach of GDPR transparency requirements toward individuals being recorded. | IT | Garante | GDPR | €3,000 | ↗ |
| 28 Sept 2023 | MCP Online LtdThe ICO fined MCP Online Ltd 55,000 GBP after finding that 20,939 calls were made between 1 January 2022 and 28 September 2022 to numbers registered with the CTPS or TPS. The conduct breached Regulations 21 and 24 of PECR and came to light through Operation Torc, which investigates unsolicited pensions calls. | GB | ICO | ePrivacy | €63,707 | ↗ |
| 01 Oct 2023 | Capita plc and CPSLThe Information Commissioner's Office imposed a GBP 2,000,000 fine on Capita plc and CPSL. The case concerned data protection breaches linked to unsolicited marketing calls, indicating improper use of contact data. | GB | Information Commissioner's Office | GDPR | €2,313,000 | ↗ |
| 01 Oct 2023 | Anonymised (IDPC CDP_COMP_344_2022)The IDPC imposed a EUR 2,500 fine on the anonymised entity for breaches of multiple GDPR provisions. The case concerned, among others, lawfulness and transparency, information duties, and controller accountability. | MT | IDPC | GDPR | €2,500 | ↗ |
| 01 Oct 2023 | TrustpilotThe Italian Competition Authority (AGCM) fined Trustpilot EUR 4,000,000. The authority found that the company misled consumers about the authenticity of reviews and how they were moderated. | IT | Italian Competition Authority (AGCM) | Omnibus | €4,000,000 | ↗ |
| 01 Oct 2023 | Anonymised (IDPC CDP_COMP_259_2022)The IDPC imposed a EUR 5,000 fine on Anonymised (IDPC CDP_COMP_259_2022) for breaches of Articles 5(1)(a), 5(1)(b), 5(1)(c) and 6 GDPR. The case concerned personal data processing that did not comply with the principles of lawfulness, fairness, data minimisation and purpose limitation. | MT | IDPC | GDPR | €5,000 | ↗ |
| 01 Oct 2023 | ExperianThe Dutch data protection authority, Autoriteit Persoonsgegevens, imposed a fine of €2.7 million on Experian. The case concerns a GDPR violation by the credit company. | NL | Autoriteit Persoonsgegevens | GDPR | €2,700,000 | ↗ |
| 01 Oct 2023 | wspólnota mieszkaniowaUODO found that the housing community breached GDPR requirements. The case concerned improper processing of personal data and required supervisory intervention. | PL | UODO | GDPR | €1,080 | ↗ |
| 02 Oct 2023 | AVENTURA EN TRAMPOLINES, S.L.Aventura en Trampolines, S.L. was fined by the AEPD EUR 2,000 for breaching GDPR Article 7. The company required consent for image use without allowing users to refuse specific terms, which did not meet data protection requirements. | ES | AEPD | GDPR | €2,000 | ↗ |
| 02 Oct 2023 | COMUNIDAD DE PROPIETARIOS A.A.A.The president of a homeowners' association shared a bank receipt containing personal data in a WhatsApp group. AEPD found a breach of confidentiality principles under GDPR and imposed a EUR 2,000 fine. | ES | AEPD | GDPR | €2,000 | ↗ |
| 02 Oct 2023 | Cez Vânzare S.A.Cez Vânzare S.A. was fined by ANSPDCP EUR 1,000 for a data protection breach. The incident resulted in unauthorized disclosure or access to personal data, including names, correspondence addresses, and customer codes of both individuals and legal entities. | RO | ANSPDCP | GDPR | €1,000 | ↗ |
| 03 Oct 2023 | ASOCIACIÓN DE PROFESIONALES DE LA SEGURIDAD PRIVADA DE ESPAÑAThe association was fined for sending emails from personal email addresses instead of corporate ones. The authority found that this practice breached GDPR confidentiality and security requirements. | ES | AEPD | GDPR | €1,500 | ↗ |
| 03 Oct 2023 | MAPFRE ESPAÑA COMPAÑÍA DE SEGUROS Y REASEGUROS, S.A.MAPFRE España was fined by the AEPD 1,140,000 EUR for requesting excessive personal data from a guarantor in a rental contract. The authority found breaches of GDPR data minimization and transparency principles. | ES | AEPD | GDPR | €1,140,000 | ↗ |
| 03 Oct 2023 | Digivo Media LimitedBetween 24 March 2021 and 7 September 2021, 415,041 text messages were sent without valid consent, breaching Regulation 22 of PECR. The ICO identified the matter after reviewing debt management complaints submitted via the SPAM reporting tool. | GB | ICO | ePrivacy | €57,620 | ↗ |