BULLETIN №083Last updated · 10 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.1%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 16 Nov 2023 | Provvedimento del 16 novembre 2023 [9973749]An attorney was fined for unlawfully processing personal data by sending sensitive judicial documents via certified email. The authority found that the method of transmission breached data protection rules. | IT | Garante | GDPR | €500 | ↗ |
| 16 Nov 2023 | Provvedimento del 16 novembre 2023 [9960948]The Garante imposed an EUR 18,000 fine on a training company for the unauthorized online publication of personal data relating to health. The case concerned breaches of GDPR Articles 5 and 32 on data processing principles and security. | IT | Garante | GDPR | €18,000 | ↗ |
| 16 Nov 2023 | BEGIN RESTAURANTES, S.L.BEGIN RESTAURANTES, S.L. was fined by the AEPD EUR 2,000 for deficiencies in its cookie policy. The authority found the use of non-essential third-party cookies without proper consent and insufficient information in the main page banner. | ES | AEPD | ePrivacy | €2,000 | ↗ |
| 17 Nov 2023 | Gemeente VoorschotenThe municipality of Voorschoten unlawfully processed personal data about residents’ waste disposal history without a sufficient legal basis. It also failed to properly inform the affected residents, breaching GDPR Articles 5, 6 and 14. | NL | AP | GDPR | €30,000 | ↗ |
| 20 Nov 2023 | Libra Internet Bank SALibra Internet Bank SA was fined EUR 1,500 by ANSPDCP for GDPR violations. The case concerned non-compliance with personal data protection requirements. | RO | ANSPDCP | GDPR | €1,500 | ↗ |
| 22 Nov 2023 | ORTHOPHONISTE (procédure simplifiée)CNIL imposed a EUR 5,000 fine on ORTHOPHONISTE under a simplified procedure and issued an injunction. The case concerns a breach of the data protection authority’s requirements. | FR | CNIL | GDPR | €5,000 | ↗ |
| 22 Nov 2023 | ASOCIACIÓN COMUNIDAD DE VECINOS R.R.R.The association unlawfully processed personal data by sending all members a letter containing personal details of a person who was not part of the association. The authority found a breach of Article 6(1) GDPR and imposed a fine. | ES | AEPD | GDPR | €1,000 | ↗ |
| 22 Nov 2023 | LOS NIÑOS DE MONTESSORI, S.L.The company was fined by the AEPD for failing to publish a privacy policy on its website and for installing non-exempt cookies without informing users or obtaining consent. The case reflects deficiencies in basic transparency and consent requirements under data protection rules. | ES | AEPD | GDPR | €4,000 | ↗ |
| 23 Nov 2023 | Alpha BankAlpha Bank was fined for failing to satisfy the complainant’s request for access to personal data. The authority found breaches of GDPR Articles 15 and 5. | GR | HDPA | GDPR | €10,000 | ↗ |
| 23 Nov 2023 | SC Sweat Concept One SASC Sweat Concept One SA was fined 10,000 RON for failing to respond to a data subject’s request to exercise the right to erasure. The authority found a breach of the ePrivacy provisions. | RO | ANSPDCP | ePrivacy | €2,012 | ↗ |
| 24 Nov 2023 | Pitagorasz Oktatási Stúdió Kft.Pitagorasz Oktatási Stúdió Kft. was fined by NAIH for processing minors' personal data without a valid legal basis. The authority found breaches of GDPR principles, including accountability, purpose limitation, and transparency. | HU | NAIH | GDPR | €1,315 | ↗ |
| 28 Nov 2023 | Barn- och utbildningsnämnden, Östersunds kommunBarn- och utbildningsnämnden in Östersunds kommun was fined by IMY for failing to conduct a data protection impact assessment before deploying Google Workspace for Education in 24 schools. The authority found this to be a breach of Article 35 GDPR. | SE | IMY | GDPR | €26,241 | ↗ |
| 28 Nov 2023 | Arbeids- og velferdsetaten (NAV)The Norwegian DPA has notified NAV of a planned 20 million NOK fine for serious information security deficiencies in its IT systems. The issues included inadequate access control and a lack of systematic log monitoring, which may have compromised the confidentiality of sensitive personal data. | NO | Datatilsynet | GDPR | €1,707,000 | ↗ |
| 30 Nov 2023 | SIA "Landry"SIA "Landry" received a monetary penalty of EUR 500 imposed by the DVI. The decision is final and has entered into force. | LV | DVI | GDPR | €500 | ↗ |
| 30 Nov 2023 | Techno Security s.r.l.Techno Security s.r.l. was fined by the Garante in the amount of 1,000 EUR for failing to respond to a data subject request and for inadequate security measures in its installed security system. The authority found that these failures breached data protection rules. | IT | Garante | GDPR | €1,000 | ↗ |
| 30 Nov 2023 | Dane anonimowe (V. S.A. z siedzibą w P. ul.)UODO imposed an administrative fine of PLN 282,960 on the controller for failing to report a personal data breach to the supervisory authority. The authority also found that the affected data subject was not notified of the breach. | PL | UODO | GDPR | €65,064 | ↗ |
| 30 Nov 2023 | SzkołęUODO imposed an administrative fine of PLN 35,000 on Szkołę. The authority found that the company had not implemented appropriate technical and organizational measures to secure personal data processed in the application. It also noted the absence of regular testing, measurement, and assessment of the effectiveness of those safeguards. | PL | UODO | GDPR | €8,048 | ↗ |
| 30 Nov 2023 | Limit Call S.r.l.s.Limit Call S.r.l.s. was fined by the Italian supervisory authority, Garante, in the amount of €60,000. The case concerned a failure to respond to an information request linked to unsolicited phone calls made without consent, which breached data protection rules. | IT | Garante | GDPR | €60,000 | ↗ |
| 30 Nov 2023 | Dane anonimowe (L. Sp. z o.o. z siedzibą we W.)UODO imposed an administrative fine of PLN 117,900 on L. Sp. z o.o. for failing to implement appropriate technical and organizational measures proportionate to the risk of data processing. The authority found deficiencies in ensuring system availability, resilience, and the ability to quickly restore access to personal data after a physical or technical incident. | PL | UODO | GDPR | €27,110 | ↗ |
| 01 Dec 2023 | ENDESA, S.A.The Spanish data protection authority imposed a EUR 6.1 million fine on ENDESA in December 2023. The case involved a security breach that led to the sale of customer personal data through Facebook ads. | ES | Agencia Española de Protección de Datos | GDPR | €6,100,000 | ↗ |