BULLETIN №083Last updated · 10 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.1%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 17 Oct 2023 | H&M Hennes & MauritzH&M Hennes & Mauritz GBC AB was fined for processing personal data for direct marketing without a lawful basis. The authority also found that the company failed to stop processing after objections were raised, breaching GDPR Articles 6, 12, and 21. | SE | IMY | GDPR | €30,356 | ↗ |
| 17 Oct 2023 | MOBILITY AUTOCENTRO, S.L.MOBILITY AUTOCENTRO, S.L. was fined by the AEPD in the amount of 2,000 EUR for sending unsolicited commercial SMS messages. The authority found that recipients were not given an opt-out option, which breached the Spanish LSSI. | ES | AEPD | ePrivacy | €2,000 | ↗ |
| 17 Oct 2023 | Íþrótta- og sýningahöllin hf.Íþrótta- og sýningahöllin hf. was fined by Persónuvernd 3,500,000 ISK for unlawful electronic surveillance at Laugardalshöll. The case involved processing sensitive personal data without proper authorization, including data relating to children. | IS | Persónuvernd | GDPR | €23,905 | ↗ |
| 18 Oct 2023 | Dane anonimowe (J. Towarzystwo Ubezpieczeń S.A. z siedzibą w N.)UODO imposed an administrative fine of PLN 103,752 on J. Towarzystwo Ubezpieczeń S.A. The authority found that the company failed to notify the supervisory authority of a personal data breach without undue delay. | PL | UODO | GDPR | €23,362 | ↗ |
| 20 Oct 2023 | DANTE INTERNAȚIONAL SADANTE INTERNAȚIONAL SA was fined EUR 1,000 by ANSPDCP for processing the complainant's phone number for direct marketing without consent. The case involved sending commercial SMS messages without a valid legal basis. | RO | ANSPDCP | GDPR | €1,000 | ↗ |
| 20 Oct 2023 | Outsource Strategies LtdOutsource Strategies Ltd made 1,346,503 unwanted marketing calls between 11 February 2021 and 22 March 2022 to numbers registered with the TPS. The ICO received 74 complaints, including reports of repeated calls despite requests to stop and aggressive caller behaviour. | GB | ICO | GDPR | €275,000 | ↗ |
| 23 Oct 2023 | EDITEUR DE BLOG EN LIGNE DEDIE A LA LUTTE CONTRE LA PEDOCRIMINALITE (procédure simplifiée)The CNIL imposed a fine of 2,000 EUR on EDITEUR DE BLOG EN LIGNE DEDIE A LA LUTTE CONTRE LA PEDOCRIMINALITE (procédure simplifiée). The matter was handled under a simplified procedure. | FR | CNIL | GDPR | €2,000 | ↗ |
| 23 Oct 2023 | EDITEUR DE SITE WEB DEDIE A LA PRESSE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 5,000 on EDITEUR DE SITE WEB DEDIE A LA PRESSE and issued an injunction. The case was handled under a simplified procedure. | FR | CNIL | GDPR | €5,000 | ↗ |
| 24 Oct 2023 | Mensajero SRLMensajero SRL was fined EUR 3,000 by ANSPDCP for a data security breach on its website. A link allowed access to downloadable files containing customer invoices and product warranty certificates. | RO | ANSPDCP | GDPR | €3,000 | ↗ |
| 24 Oct 2023 | FIBRA ÓPTICA MÁLAGA, S.L.FIBRA ÓPTICA MÁLAGA, S.L. changed a customer's contact email and bank account details without consent. The AEPD found a breach of GDPR Article 6(1) and imposed a 70,000 EUR fine. | ES | AEPD | GDPR | €70,000 | ↗ |
| 24 Oct 2023 | UNIPREX, S.A.UNIPREX, S.A. was fined 50,000 EUR by the AEPD for processing an excessive amount of personal data. The authority found that the data collected went beyond what was necessary for the intended purpose. | ES | AEPD | GDPR | €50,000 | ↗ |
| 25 Oct 2023 | SC Spark Car Sharing SRLANSPDCP completed an investigation in October 2023 at SC Spark Car Sharing SRL and found a breach of personal data processing principles. The company received a EUR 1,000 fine and a warning. | RO | ANSPDCP | GDPR | €1,000 | ↗ |
| 26 Oct 2023 | Edizioni Proposta Sud S.r.l.The Garante fined Edizioni Proposta Sud S.r.l. €20,000 for publishing false information about an individual's health status without verifying its accuracy. The authority found this breached GDPR principles on data protection and accuracy. | IT | Garante | GDPR | €20,000 | ↗ |
| 26 Oct 2023 | Argentum Data Solutions LtdBetween 1 January 2021 and 31 January 2022, a total of 2,330,423 SMS messages were sent without consent. Argentum Data Solutions Ltd sent 24,309 messages directly and allowed its lines to be used by third parties to send the remaining 2,306,114. The conduct breached regulation 22 of PECR and came to the ICO’s attention through complaints reported via the 7726 spam tool. | GB | ICO | ePrivacy | €74,568 | ↗ |
| 26 Oct 2023 | Regione LombardiaThe Garante fined Regione Lombardia EUR 20,000 for improperly publishing the personal data of numerous workers online. The disclosed information also included health-related data, which breached privacy rules. | IT | Garante | GDPR | €20,000 | ↗ |
| 26 Oct 2023 | SOCIETE AYANT POUR ACTIVITE PRINCIPALE L'EVENEMENTIEL (procédure simplifiée)The CNIL imposed a EUR 2,000 fine on SOCIETE AYANT POUR ACTIVITE PRINCIPALE L'EVENEMENTIEL under a simplified procedure. The case concerned a breach of personal data protection rules. | FR | CNIL | GDPR | €2,000 | ↗ |
| 26 Oct 2023 | Azienda Sanitaria Locale TO3Azienda Sanitaria Locale TO3 was fined by the Garante for a health data breach affecting four individuals. The incident lasted nine days and was deemed negligent. | IT | Garante | GDPR | €6,000 | ↗ |
| 26 Oct 2023 | Provvedimento del 26 ottobre 2023 [9960920]The Garante imposed a EUR 1,000 fine on a condominium administrator for installing a video surveillance system without a proper legal basis or assembly resolution. The conduct was found to breach GDPR rules on lawful processing. | IT | Garante | GDPR | €1,000 | ↗ |
| 26 Oct 2023 | A.C. Group S.r.l.s.A.C. Group S.r.l.s. was fined by the Garante 10,000 EUR for making an unsolicited marketing call to a number listed in the Public Register of Objections without prior informed consent. The authority also found that the company failed to adequately respond to a data subject rights request. | IT | Garante | GDPR | €10,000 | ↗ |
| 27 Oct 2023 | Telemach HrvatskaAZOP imposed a EUR 4.5 million fine on Telemach Hrvatska for GDPR violations. The authority found that the company transferred personal data to Serbia without valid transfer safeguards, failed to properly inform data subjects, and overprocessed copies of employee ID documents. | HR | AZOP | GDPR | €4,500,000 | ↗ |