BULLETIN №083Last updated · 10 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.1%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 27 Oct 2023 | Asociația de Proprietari bloc A1The homeowners association was fined by ANSPDCP for failing to implement measures ordered by the authority and for unlawfully disclosing owners’ names on maintenance lists without consent. The case concerns breaches of personal data protection rules and non-compliance with supervisory instructions. | RO | ANSPDCP | GDPR | €501 | ↗ |
| 30 Oct 2023 | CLÍNICA PARÍS, S.L.CLÍNICA PARÍS, S.L. was fined 1,000 EUR by the AEPD for failing to properly handle a data subject access request. The authority found a breach of GDPR obligations. | ES | AEPD | GDPR | €1,000 | ↗ |
| 02 Nov 2023 | ASYMECO, S.A.ASYMECO, S.A. was fined EUR 5,000 by the AEPD for sending clients’ personal data to an employee’s private WhatsApp without proper authorization. The authority found this breached GDPR Articles 6(1) and 32. | ES | AEPD | GDPR | €5,000 | ↗ |
| 02 Nov 2023 | KOMPASS SPAIN, S.L.U.KOMPASS SPAIN, S.L.U. was fined by the AEPD in the amount of 5,000 EUR for sending unsolicited email messages. The emails were sent despite the recipient’s attempts to unsubscribe and their inclusion on the Robinson List. | ES | AEPD | ePrivacy | €5,000 | ↗ |
| 03 Nov 2023 | OTP BANK ROMANIA SAThe National Supervisory Authority for Personal Data Processing imposed a fine of EUR 3,000 on OTP BANK ROMANIA SA for GDPR violations. The case concerned non-compliance with personal data protection requirements. | RO | ANSPDCP | GDPR | €3,000 | ↗ |
| 07 Nov 2023 | FondrådgivareIndecap AB was fined by IMY SEK 500,000 for failing to ensure an appropriate level of security for personal data. As a result, an email was sent to unauthorized recipients and contained sensitive customer information. | SE | IMY | GDPR | €42,845 | ↗ |
| 08 Nov 2023 | SOCIETE AYANT POUR ACTIVITE LE DEVELOPPEMENT ET LA MISE EN OEUVRE DE LOGICIELS DE SURVEILLANCE DES EMPLOYES (procédure simplifiée)CNIL imposed an administrative fine of 20,000 EUR on the company under a simplified procedure. The decision concerns breaches linked to the company's activity in employee monitoring software. | FR | CNIL | GDPR | €20,000 | ↗ |
| 09 Nov 2023 | Complete Marketing Services LtdBetween 8 June 2021 and 4 February 2022, Complete Marketing Services Ltd instigated 242,497 unsolicited direct marketing calls in breach of PECR. The ICO became aware of the matter after complaints about live marketing calls relating to road traffic accidents and personal injury claims were reported via the TPS. | GB | ICO | ePrivacy | €172,000 | ↗ |
| 09 Nov 2023 | DPG Professional Services LtdBetween 3 August 2021 and 3 August 2022, DPG made 74,119 unsolicited calls for direct marketing purposes, breaching Reg 21 of PECR. The activity resulted in 13 complaints and came to the Commissioner’s attention through an operation focused on life insurance and later life planning marketing. | GB | ICO | ePrivacy | €103,000 | ↗ |
| 10 Nov 2023 | VERNE INFORMATION TECHNOLOGY, S.L.VERNE INFORMATION TECHNOLOGY, S.L. was fined 2,000 EUR by the AEPD. The case concerned sending unsolicited commercial electronic communications without prior consent or an existing contractual relationship. | ES | AEPD | ePrivacy | €2,000 | ↗ |
| 13 Nov 2023 | Rompetrol Downstream SRLRompetrol Downstream SRL was fined EUR 110,000 by ANSPDCP for failing to ensure the security of personal data. The authority found a breach of Article 32 GDPR, which requires appropriate technical and organizational measures. | RO | ANSPDCP | GDPR | €110,000 | ↗ |
| 13 Nov 2023 | RECICLAJES LOGROÑO, S.L.RECICLAJES LOGROÑO, S.L. was fined by the AEPD 10,000 EUR for photocopying a customer's ID without consent and for failing to provide privacy policy information. The authority found breaches of GDPR data minimization and transparency principles. | ES | AEPD | GDPR | €10,000 | ↗ |
| 13 Nov 2023 | Kerepesi Polgármesteri HivatalKerepesi Polgármesteri Hivatal was fined by NAIH for unlawful data processing linked to the operation of a public surveillance camera system. The authority found violations of several provisions of the Infotv. | HU | NAIH | GDPR | €21,200 | ↗ |
| 15 Nov 2023 | COMMUNE (procédure simplifiée)CNIL imposed a EUR 6,000 fine on COMMUNE under a simplified procedure. The case concerns an administrative sanction decision. | FR | CNIL | GDPR | €6,000 | ↗ |
| 16 Nov 2023 | SOCIETE AYANT UNE ACTIVITE DE SOUTIEN AUX ENTREPRISES, NOTAMMENT POUR LES EVENEMENTS TELEVISES (procédure simplifiée)The CNIL imposed a fine of EUR 8,000 on SOCIETE AYANT UNE ACTIVITE DE SOUTIEN AUX ENTREPRISES, NOTAMMENT POUR LES EVENEMENTS TELEVISES. The case was handled under a simplified procedure. | FR | CNIL | GDPR | €8,000 | ↗ |
| 16 Nov 2023 | Autostrade per l’Italia S.p.A.Autostrade per l’Italia S.p.A. was fined by the Garante 100,000 EUR for failing to respond to employees' requests for access and rectification of personal data linked to annual severance pay calculations. The case concerns a failure to meet obligations for handling data subject rights requests. | IT | Garante | GDPR | €100,000 | ↗ |
| 16 Nov 2023 | Amazon Italia Transport s.r.l.Amazon Italia Transport s.r.l. was fined €40,000 by the Garante for failing to respond to a former employee’s request for access to personal data. The authority found a breach of Article 15 GDPR. | IT | Garante | GDPR | €40,000 | ↗ |
| 16 Nov 2023 | Dane anonimowe (W. sp. j. z siedzibą we W. przy ul.)The President of the Personal Data Protection Office imposed an administrative fine of PLN 14,148 on the company. The sanction was issued because the company failed to provide access to personal data and information necessary for the authority’s tasks. | PL | UODO | GDPR | €3,235 | ↗ |
| 16 Nov 2023 | Intelling LtdBetween 1 January 2021 and 11 November 2021, Intelling sent 1,164,877 direct marketing messages in breach of Regulation 22 of PECR. The Commissioner opened the case after receiving 1,103 complaints via the 7726 Spam Reporting Service. | GB | ICO | ePrivacy | €79,982 | ↗ |
| 16 Nov 2023 | NEW BUY GOLD DI EMANUELE VITA & C. S.A.S.The company was fined EUR 1,000 by the Italian supervisory authority, Garante. The penalty was imposed because it operated a video surveillance system without the required information notice for data subjects, in breach of Article 13 GDPR. | IT | Garante | GDPR | €1,000 | ↗ |