BULLETIN №083Last updated · 10 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.1%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 04 Dec 2023 | CARSO TRADING, S.L.CARSO TRADING, S.L. was fined by the AEPD for sending unsolicited commercial emails without prior consent from recipients. The company also failed to respond to a request to stop such communications, which constitutes a breach of the LSSI. | ES | AEPD | ePrivacy | €1,000 | ↗ |
| 04 Dec 2023 | GRIMEY WEAR, S.L.GRIMEY WEAR, S.L. was fined by the AEPD 5,000 EUR for failing to delete a customer's personal data within the legal timeframe. The case concerns a breach of data protection rules and the controller's obligation to comply with a deletion request. | ES | AEPD | ePrivacy | €5,000 | ↗ |
| 06 Dec 2023 | ReykjanesbærReykjanesbær was fined by Persónuvernd 2,500,000 ISK for using Google Workspace for Education in schools without full compliance with data protection rules. The authority cited the failure to carry out timely data protection impact assessments and to define processing purposes clearly. | IS | Persónuvernd | GDPR | €16,650 | ↗ |
| 07 Dec 2023 | Hora Credit IFN SAThe authority fined Hora Credit IFN SA for sending documents containing another client's personal data to the complainant's email address. The incident indicates a breach of confidentiality and proper personal data processing requirements. | RO | ANSPDCP | GDPR | €2,000 | ↗ |
| 07 Dec 2023 | Hora Credit IFN SAThe authority fined Hora Credit IFN SA for sending documents containing another client's personal data to the complainant's email address. The incident indicates a breach of confidentiality and proper personal data processing requirements. | RO | ANSPDCP | GDPR | €20,000 | ↗ |
| 07 Dec 2023 | Sirio S.p.A.Sirio S.p.A. was fined EUR 1,000 by the Garante for violating data protection rules. The case concerned the improper handling of an employee’s personal data in connection with issuing a new bank card. | IT | Garante | GDPR | €1,000 | ↗ |
| 07 Dec 2023 | Azienda socio sanitaria territoriale nord MilanoAzienda socio sanitaria territoriale nord Milano was fined by the Garante EUR 40,000 for allowing unrestricted access to patient data across hospital departments. The authority found breaches of data minimization and purpose limitation principles during the COVID-19 emergency. | IT | Garante | GDPR | €40,000 | ↗ |
| 07 Dec 2023 | Mushtaq RubinaThe Garante fined Mushtaq Rubina 2,000 EUR for operating a video surveillance system without adequate informational signage. The authority found a breach of GDPR transparency requirements toward recorded individuals. | IT | Garante | GDPR | €2,000 | ↗ |
| 07 Dec 2023 | ASESORÍA Y PROGRAMACIÓN PROFESIONAL, S.L.The entity was fined for continuing to send advertising emails despite the recipient's attempts to unsubscribe. This conduct breached Article 21 of the LSSI and resulted in a EUR 5,000 penalty. | ES | AEPD | ePrivacy | €5,000 | ↗ |
| 07 Dec 2023 | Anonymised (CyDPC ΑΠΟΦΑΣΗ ΓεΣΥ 77.pdf)A doctor accessed a patient's health records in the General Health System (GHS) without proper authorization or referral. The authority found this breached GDPR principles of lawful and transparent processing of personal data. | CY | CyDPC | GDPR | €1,500 | ↗ |
| 07 Dec 2023 | Nirvam S.r.l.Nirvam S.r.l., an online dating platform, was fined 200,000 EUR by the Garante. The authority found inadequate personal data protection measures and GDPR breaches related to data processing and security. | IT | Garante | GDPR | €200,000 | ↗ |
| 07 Dec 2023 | Dane anonimowe (N. Sp. z o.o. z siedzibą w W. przy ul.)The President of UODO imposed a PLN 11,790 administrative fine on N. Sp. z o.o. The company failed to cooperate with the authority in the performance of its duties and did not provide access to personal data and information necessary for those duties. | PL | UODO | GDPR | €2,722 | ↗ |
| 07 Dec 2023 | B.B.B.The educational institution did not inform parents about data processing on Chromebooks used by students. It also failed to have a contract with the data processor, which breaches GDPR Articles 13 and 28. | ES | AEPD | GDPR | €5,000 | ↗ |
| 07 Dec 2023 | N*** Gastronomie GmbHN*** Gastronomie GmbH was fined by the DSB EUR 20,000 for unlawfully processing personal data through video surveillance without a legal basis. The authority also found that the company failed to maintain a record of processing activities required under the GDPR. | AT | DSB | GDPR | €20,000 | ↗ |
| 07 Dec 2023 | Azienda OspedalieraAzienda Ospedaliera was fined EUR 8,000 by the Garante for breaches of data protection rules. The case concerned data processing principles and insufficient security measures. | IT | Garante | GDPR | €8,000 | ↗ |
| 07 Dec 2023 | Hora Credit IFN SAThe authority fined Hora Credit IFN SA for sending documents containing another client's personal data to the complainant's email address. The incident indicates a breach of confidentiality and proper personal data processing requirements. | RO | ANSPDCP | GDPR | €2,000 | ↗ |
| 07 Dec 2023 | H**** Gemeinnützige Wohnungs AGThe entity was fined for failing to cooperate with the Data Protection Authority during a complaint procedure. It did not respond to requests for statements, which constitutes a breach of Article 31 GDPR. | AT | DSB | GDPR | €10,000 | ↗ |
| 11 Dec 2023 | PERSONNALITE POLITIQUE (procédure simplifiée)The CNIL imposed a EUR 3,000 fine on PERSONNALITE POLITIQUE and issued an injunction. The case was handled under a simplified procedure. | FR | CNIL | GDPR | €3,000 | ↗ |
| 11 Dec 2023 | Veranda Obor S.A.The National Supervisory Authority for Personal Data Processing imposed a fine on Veranda Obor S.A. for violating GDPR provisions. The case concerned non-compliance with personal data protection requirements. | RO | ANSPDCP | GDPR | €3,000 | ↗ |
| 11 Dec 2023 | C*** Bank AGC*** Bank AG was fined by the DSB EUR 9,500 for breaching Article 15 GDPR. The bank treated an access request as a deletion request and deleted the data instead of providing the requested information. | AT | DSB | GDPR | €9,500 | ↗ |