BULLETIN №083Last updated · 10 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.1%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 03 Oct 2023 | Utbildningsnämnden i Stockholms stad – Aspuddens skolaThe Stockholm City Education Committee was fined by IMY 800,000 SEK for unlawful camera surveillance at Aspuddens school. The authority found breaches of legality and data minimization principles, as well as a failure to provide the required information under GDPR. | SE | IMY | GDPR | €68,744 | ↗ |
| 04 Oct 2023 | Amazon EuropeThe CNPD imposed a fine of EUR 746,000,000 on Amazon Europe for breaches of data protection rules. The case concerned shortcomings in the processing of personal data and compliance with GDPR requirements. | LU | CNPD | GDPR | €746,000,000 | ↗ |
| 05 Oct 2023 | DPP Law LtdThe Information Commissioner's Office issued a monetary penalty notice against DPP Law Ltd. The firm was fined GBP 60,000 for failing to implement appropriate technical and organisational measures to secure personal data. | GB | Information Commissioner's Office | GDPR | €69,282 | ↗ |
| 06 Oct 2023 | Ítélet a NAIH-19-18-2024 sz. ügyben (Kúria Kfv.IV.37.804/2025/2)The entity was fined for improper processing of personal data in a nationwide energy efficiency program. The authority found inadequate transparency and consent procedures, as well as insufficient data security measures. | HU | NAIH | GDPR | €194,000 | ↗ |
| 06 Oct 2023 | Texas Andreas Petersen A/SThe Danish Data Protection Authority reported Texas Andreas Petersen A/S to the police and recommended a fine of at least DKK 200,000. The case concerned the collection and sharing of website visitors' personal data without a legal basis. | DK | Datatilsynet | GDPR | €26,818 | ↗ |
| 06 Oct 2023 | SOCIETE DE CONSEILS EN SYSTEMES ET LOGICIELS INFORMATIQUES (procédure simplifiée)CNIL imposed a fine of EUR 20,000 on SOCIETE DE CONSEILS EN SYSTEMES ET LOGICIELS INFORMATIQUES under a simplified procedure. The decision concerns a breach of personal data protection rules. | FR | CNIL | GDPR | €20,000 | ↗ |
| 10 Oct 2023 | UAB RamidonasThe supervisory authority imposed a €6,000 fine on UAB Ramidonas for personal data security violations. The case concerned deficiencies in data protection controls that could have exposed individuals’ information to risk. | LT | Valstybinė duomenų apsaugos inspekcija | GDPR | €6,000 | ↗ |
| 10 Oct 2023 | American ExpressCNIL imposed a EUR 1,500,000 fine on American Express for placing cookies without prior user consent. The case concerns breaches of GDPR and privacy law requirements. | FR | CNIL | GDPR | €1,500,000 | ↗ |
| 10 Oct 2023 | ComuneThe Italian data protection authority fined a municipality EUR 12,000 for unlawfully publishing personal data online in access request registers. Documents in the transparency section of the municipal website exposed names, protocol numbers, and other sensitive details of hundreds of citizens. | IT | Garante per la protezione dei dati personali | GDPR | €12,000 | ↗ |
| 10 Oct 2023 | TemuThe European Commission imposed a EUR 200 million fine on Temu under the Digital Services Act. The authority said Temu failed to identify, analyse, and assess systemic risks linked to illegal products offered on its platform. | EU | European Commission | DSA | €200,000,000 | ↗ |
| 10 Oct 2023 | Hogeschool van Arnhem en Nijmegen (HAN)The Autoriteit Persoonsgegevens imposed a fine of EUR 175,000 on Hogeschool van Arnhem en Nijmegen (HAN). The authority found that the institution did not provide sufficient protection for students’ personal data. | NL | Autoriteit Persoonsgegevens | GDPR | €175,000 | ↗ |
| 10 Oct 2023 | GALENICUM HEALTH, S.L.U.GALENICUM HEALTH, S.L.U. was fined EUR 500 by the AEPD for failing to display informational signage about its video surveillance system. The authority found a breach of Article 5(1)(c) GDPR in relation to transparency and proper notice. | ES | AEPD | GDPR | €500 | ↗ |
| 11 Oct 2023 | CONSULTORÍA PERITACIONES ALMERIENSES, S.L.The company was fined by the AEPD 1,000 EUR for not having a privacy policy on its website. The issue arose because it collected personal data through a contact form, triggering the information duties under GDPR Article 13. | ES | AEPD | GDPR | €1,000 | ↗ |
| 11 Oct 2023 | COM. PROP. ***COMUNIDAD.1The entity installed surveillance cameras oriented toward public roads without prior administrative authorization. This breached data protection rules and resulted in a fine by the AEPD. | ES | AEPD | GDPR | €1,000 | ↗ |
| 11 Oct 2023 | B.B.B.The entity installed surveillance cameras without consent in a rented equestrian club. The recordings captured minors and disabled individuals, which constituted a privacy violation. | ES | AEPD | GDPR | €2,000 | ↗ |
| 12 Oct 2023 | Onda Più S.r.l.Onda Più S.r.l. was fined EUR 200,000 by the Garante for activating energy supply contracts without customer consent. The authority also found the use of inaccurate and outdated personal data. | IT | Garante | GDPR | €200,000 | ↗ |
| 12 Oct 2023 | SOCIETE EDITANT DES CHAINES ET DISTRIBUANT DES OFFRES DE TELEVISION PAYANTESCNIL imposed a fine of EUR 600,000 on SOCIETE EDITANT DES CHAINES ET DISTRIBUANT DES OFFRES DE TELEVISION PAYANTES. The case concerns a confirmed regulatory breach, with no further details provided in the record. | FR | CNIL | GDPR | €600,000 | ↗ |
| 12 Oct 2023 | S.T.A. Società Trattamento Acque s.r.l.S.T.A. Società Trattamento Acque s.r.l. was fined €75,000 by the Garante. The authority found a breach of Article 15 GDPR after the company failed to respond to an employee's request for access to professional training records. | IT | Garante | GDPR | €75,000 | ↗ |
| 12 Oct 2023 | Scionti Selezioni Superiori S.r.l.Scionti Selezioni Superiori S.r.l. was fined EUR 70,000 by the Garante for failing to implement adequate measures to prevent unauthorized access to customer data. The data was then used for promotional purposes without the individuals' consent. | IT | Garante | GDPR | €70,000 | ↗ |
| 13 Oct 2023 | COMUNIDAD DE PROPIETARIOS ***COMUNIDAD.1The entity installed a video surveillance system with cameras directed toward public areas without prior administrative authorization. In addition, unauthorized personnel had access to the system, creating a data protection compliance breach. | ES | AEPD | GDPR | €1,000 | ↗ |