BULLETIN №083Last updated · 07 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 09 Oct 2018 | OTEThe Hellenic Data Protection Authority imposed a fine of EUR 150,000 on OTE. The case concerned unsolicited promotional calls made to subscribers who had previously opted out of such contact. | GR | HDPA | ePrivacy | €150,000 | ↗ |
| 09 Oct 2018 | CosmoteCosmote was fined EUR 150,000 by the HDPA for making unsolicited promotional calls to subscribers who had opted out of such contact. The authority found that this conduct breached privacy and personal data protection rules. | GR | HDPA | ePrivacy | €150,000 | ↗ |
| 27 Sept 2018 | Anonymisiert (DSB DSB-D550.084/0002-DSB/2018)The authority imposed a EUR 300 fine for operating dash-cams in a vehicle without proper signage. It found breaches of GDPR principles of lawfulness, fairness, transparency, and data minimization. | AT | DSB | GDPR | €300 | ↗ |
| 27 Sept 2018 | Anonymizováno (ÚOOÚ UOOU-05291/17-44)The entity was fined for repeatedly sending commercial communications to specified electronic addresses without consent and without proper labeling. The authority found a breach of Czech rules on information society services. | CZ | UOOU | ePrivacy | €3,111 | ↗ |
| 26 Sept 2018 | VILAN DATAMINING SLVILAN DATAMINING SL was fined by the AEPD €800 for sending unsolicited commercial emails. The messages did not provide a way to exercise the rights of access, rectification, cancellation, or objection. | ES | AEPD | ePrivacy | €800 | ↗ |
| 21 Sept 2018 | XFERA MÓVILES, S.A.U.XFERA MÓVILES, S.A.U. was fined by the AEPD in the amount of 4,000 EUR for sending unsolicited commercial SMS messages without the recipient’s consent. The conduct breached Article 21.1 of the LSSI, which requires prior consent for marketing communications. | ES | AEPD | ePrivacy | €4,000 | ↗ |
| 21 Sept 2018 | Anonymizováno (ÚOOÚ UOOU-01895/18-25)The entity was fined by the UOOU for processing personal data without consent and for failing to implement adequate security measures. The authority found these actions to be in breach of Czech data protection law. | CZ | UOOU | GDPR | €1,173 | ↗ |
| 17 Sept 2018 | TELEFONICA MOVILES ESPAÑA, S.A.U.TELEFONICA MOVILES ESPAÑA, S.A.U. was fined by the AEPD EUR 900 for sending unsolicited advertising emails to an individual who was not a customer. The case concerns a breach of data protection rules governing direct marketing communications. | ES | AEPD | ePrivacy | €900 | ↗ |
| 14 Sept 2018 | IAHORRO BUSINESS SOLUTIONS SLIAHORRO BUSINESS SOLUTIONS SL was fined by the AEPD €1,000 for sending unsolicited commercial electronic communications. The company also failed to provide a procedure for exercising rights of access, rectification, cancellation, or objection. | ES | AEPD | ePrivacy | €1,000 | ↗ |
| 29 Aug 2018 | Anonymizováno (ÚOOÚ UOOU-08277/18-40)The entity was fined for sending unsolicited commercial communications by electronic means without recipients' consent. This breached Czech rules on information society services. | CZ | UOOU | ePrivacy | €3,496 | ↗ |
| 21 Aug 2018 | Eurobank Ergasias A.E.Eurobank Ergasias A.E. was fined by the HDPA in the amount of 5,000 EUR for failing to maintain and process accurate data of its debtors. The authority found that the company’s handling of debtor information breached data protection requirements. | GR | HDPA | GDPR | €5,000 | ↗ |
| 21 Aug 2018 | Alpha BankAlpha Bank was fined by the HDPA for failing to maintain and process accurate data of its debtors. The authority found that the bank’s conduct breached data protection requirements. | GR | HDPA | GDPR | €10,000 | ↗ |
| 21 Aug 2018 | National Bank of GreeceNational Bank of Greece was fined EUR 5,000 by the HDPA for failing to maintain accurate data about its debtors. The case concerned compliance with data protection obligations. | GR | HDPA | GDPR | €5,000 | ↗ |
| 20 Aug 2018 | Anonymizováno (ÚOOÚ UOOU-06831/16-239)The entity was fined for repeatedly sending unsolicited commercial communications, concealing the sender's identity, and failing to provide a valid unsubscribe address. The conduct breached the Czech law on certain information society services. | CZ | UOOU | ePrivacy | €54,460 | ↗ |
| 09 Aug 2018 | InsingerGilissen Bankiers N.V.Theodoor Gilissen Bankiers N.V. failed to provide a complete overview of personal data processing upon request, which breached data protection rules. Its successor, InsingerGilissen Bankiers N.V., was fined EUR 48,000. | NL | AP | GDPR | €48,000 | ↗ |
| 30 Jul 2018 | А.С.К. УМБАЛ ЕООДThe CPDP found that “А.С.К. УМБАЛ ЕООD” unlawfully processed personal data by providing it to “МБАЛ-В. ЕООD” without consent. This breached data protection rules and resulted in a fine of BGN 1,000. | BG | CPDP | GDPR | €511 | ↗ |
| 27 Jul 2018 | Anonymizováno (ÚOOÚ UOOU-08596/17-64)The individual was fined for publishing the personal data of a municipal social department employee on Facebook. The authority found a breach of confidentiality obligations under Czech law. | CZ | UOOU | GDPR | €117 | ↗ |
| 26 Jul 2018 | Mercati s.p.aMercati s.p.a was fined 18,000 EUR by the Garante for failing to provide adequate information to users about data collection through a reservation form. The authority also found that the company used a video surveillance system without proper notice, in breach of Article 13 of the Italian Privacy Code. | IT | Garante | GDPR | €18,000 | ↗ |
| 26 Jul 2018 | Primo s.r.l.Primo s.r.l., a dental center, was fined by the Italian Garante in the amount of 10,000 EUR. The authority found inadequate security measures in the processing of patients’ personal data. | IT | Garante | GDPR | €10,000 | ↗ |
| 26 Jul 2018 | Associazione MEVALAUTE ONLUSThe association was fined by the Garante for sending unsolicited PEC communications. The authority found that personal data were processed without consent, in breach of data protection rules. | IT | Garante | GDPR | €26,000 | ↗ |