BULLETIN №083Last updated · 07 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 10 Jun 2011 | Azienda mobilità trasporti di Bari s.p.a.Azienda mobilità trasporti di Bari s.p.a. was fined by the Garante for processing employees' biometric data without proper notice, consent, or adequate information. The authority found violations of several provisions of the Italian data protection code. | IT | Garante | GDPR | €34,000 | ↗ |
| 02 Dec 2015 | A.M.A.M. Azienda Meridionale Acque Messina s.p.a.A.M.A.M. Azienda Meridionale Acque Messina s.p.a. was fined by the Garante for processing employees' biometric data without notification and without requesting prior verification. The authority found that the company breached data protection rules. | IT | Garante | GDPR | €34,000 | ↗ |
| 06 Sept 2012 | Azienda sanitaria provinciale di EnnaAzienda sanitaria provinciale di Enna was fined 34,000 EUR by the Garante. The authority found a breach of notification obligations under data protection rules. | IT | Garante | GDPR | €34,000 | ↗ |
| 29 Apr 2026 | Pianeta s.r.l.Pianeta s.r.l. was fined by the Garante 34,000 EUR for unlawfully processing personal data linked to a loyalty card program. The data were used to initiate disciplinary action against an employee, which breached GDPR requirements. | IT | Garante | GDPR | €34,000 | ↗ |
| 01 Jan 2012 | LET’s BONUS, S.L.LET’s BONUS, S.L. was fined EUR 34,001 by the AEPD for sending unsolicited commercial emails to a user. The conduct continued despite multiple requests to stop, which breached Article 21 of the LSSI. | ES | AEPD | ePrivacy | €34,001 | ↗ |
| 07 Feb 2011 | EL CORTE INGLES, S.A.EL CORTE INGLES, S.A. was fined 35,000 EUR by the AEPD for sending nine commercial emails without the recipient’s consent. The authority found a breach of Article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €35,000 | ↗ |
| 22 Jul 2021 | Azienda sanitaria locale di BariAzienda sanitaria locale di Bari was fined EUR 35,000 by the Garante for failing to adopt minimum security measures. The breach resulted in exposure of health data, creating a significant compliance and privacy risk. | IT | Garante | GDPR | €35,000 | ↗ |
| 09 Apr 2021 | Miljø- og Kvalitetsledelse ASMiljø- og Kvalitetsledelse AS was fined 35,000 NOK by Datatilsynet for unlawfully sending personal data from camera recordings to an employer without a legal basis. The authority cited breaches of GDPR Articles 6 and 5. | NO | Datatilsynet | GDPR | €3,461 | ↗ |
| 30 Nov 2023 | SzkołęUODO imposed an administrative fine of PLN 35,000 on Szkołę. The authority found that the company had not implemented appropriate technical and organizational measures to secure personal data processed in the application. It also noted the absence of regular testing, measurement, and assessment of the effectiveness of those safeguards. | PL | UODO | GDPR | €8,048 | ↗ |
| 03 Dec 2019 | Nusvar ABNusvar AB was fined SEK 35,000 by IMY. The authority found unauthorized processing of personal data relating to criminal offenses and a failure to comply with data minimization principles in credit reporting activities. | SE | IMY | GDPR | €3,313 | ↗ |
| 23 Jan 2024 | CAIXA POPULAR - CAIXA RURAL SOC. COOP. DE CRÉDITO VCAIXA POPULAR was fined EUR 35,000 by the AEPD for a personal data breach. The incident allowed unauthorized third-party access and affected the confidentiality and integrity of the data. | ES | AEPD | GDPR | €35,000 | ↗ |
| 21 May 2015 | BONANZA DIGITAL SERVICES, S.L.BONANZA DIGITAL SERVICES, S.L. was fined EUR 35,000 by the AEPD for sending 20 unsolicited advertising SMS messages without prior consent. The company also failed to provide an opt-out mechanism, breaching the LSSI. | ES | AEPD | ePrivacy | €35,000 | ↗ |
| 12 Sept 2025 | A Düsseldorf-based personnel recruitment companyOn 2025-09-12, the LDI NRW announced a data protection fine of over 35,000 EUR against a Düsseldorf-based personnel recruitment company. The authority said the company repeatedly ignored job seekers’ requests for access and deletion and failed to respond to the supervisory authority’s inquiries. | DE | Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen | GDPR | €35,000 | ↗ |
| 18 Mar 2025 | ALVEA SOLUCIONES TECNOLÓGICAS, S.L.ALVEA Soluciones Tecnológicas, S.L. was fined 35,000 EUR by the AEPD for improper handling of personal data. The authority cited sharing data without consent and failing to comply with data retention policies. | ES | AEPD | GDPR | €35,000 | ↗ |
| 29 Oct 2013 | ESPASA CALPE, S.A.ESPASA CALPE, S.A. was fined EUR 35,000 by the AEPD for sending unsolicited commercial emails. The conduct breached Article 21 of the LSSI despite prior requests to be removed from the mailing list. | ES | AEPD | ePrivacy | €35,000 | ↗ |
| 25 Sept 2025 | E-Power S.r.l.E-Power S.r.l. was fined EUR 35,000 by the Garante for making promotional calls without a valid legal basis. The authority also found that the company failed to respond to data subject rights requests, which breaches GDPR requirements. | IT | Garante | GDPR | €35,000 | ↗ |
| 27 May 2019 | VODAFONE ESPAÑA, S.A.U.Vodafone España, S.A.U. was fined 35,000 EUR by the AEPD for processing personal data without consent. The case involved charging a former customer for services not contracted due to a technical error. | ES | AEPD | GDPR | €35,000 | ↗ |
| 13 Feb 2026 | Dane anonimowe (Komitet Wyborczy Kandydata na Prezydenta Rzeczypospolitej Polskiej M. W.)UODO imposed a fine of 35,582 PLN on the Election Committee of Presidential Candidate M. W. The authority found that campaign activities infringed the privacy of other individuals by using their personal data. The right to present truthful information about a candidate does not justify such processing. | PL | UODO | GDPR | €8,442 | ↗ |
| 24 Jul 2014 | Future srlFuture srl was fined EUR 36,000 by the Garante for making unsolicited promotional phone calls without proper consent. The authority found that the company’s conduct breached data protection rules. | IT | Garante | GDPR | €36,000 | ↗ |
| 10 Apr 2019 | Anonymizováno (ÚOOÚ UOOU-06298/18-38)The entity was fined for repeatedly sending commercial communications without recipients’ consent. This breached § 7(2) of the Czech Act on Certain Information Society Services. | CZ | UOOU | ePrivacy | €1,406 | ↗ |