BULLETIN №083Last updated · 09 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.1%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 19 Mar 2015 | Trust Center A.E.The company was fined for failing to adequately inform data subjects about the processing of their creditworthiness data. The authority found a breach of Article 11 of the Greek data protection law. | GR | HDPA | GDPR | €3,000 | ↗ |
| 31 Jul 2020 | ASOCIACIÓN DE VIGILANTES DE SEGURIDAD DEL AEROPUERTO DE BARCELONAThe organization was fined by the AEPD in the amount of 3,000 EUR for sending an electoral census of workers to private phones via WhatsApp. The authority found a breach of data protection principles. | ES | AEPD | GDPR | €3,000 | ↗ |
| 02 Apr 2025 | BINBOX GLOBAL SERVICES S.R.L.In March 2025, Romania’s data protection authority ANSPDCP completed an investigation into BINBOX GLOBAL SERVICES S.R.L. The authority found a GDPR violation and imposed a fine of EUR 3,000. | RO | ANSPDCP | GDPR | €3,000 | ↗ |
| 24 Nov 2022 | Ordine dei Medici Chirurghi e degli Odontoiatri della Provincia di CagliariOrdine dei Medici Chirurghi e degli Odontoiatri della Provincia di Cagliari was fined €3,000 by the Garante. The authority found breaches of lawfulness, fairness, transparency, and data minimization in the handling of personal data related to an individual's employment. | IT | Garante | GDPR | €3,000 | ↗ |
| 08 Jul 2025 | Selgros Cash & Carry SRLIn June 2025, ANSPDCP completed an investigation at Selgros Cash & Carry SRL and found a GDPR violation. The operator was fined EUR 3,000. | RO | ANSPDCP | GDPR | €3,000 | ↗ |
| 25 Sept 2020 | SINDICATO DE TRABAJADORES DE LA ADMINISTRACIÓN PÚBLICA (STAP-CGT)The labor union STAP-CGT was fined EUR 3,000 by the AEPD for unlawful processing of personal data. The case concerned publishing a video of a court hearing on YouTube without proper consent, in breach of GDPR Article 6(1)(a). | ES | AEPD | GDPR | €3,000 | ↗ |
| 16 Mar 2023 | Sancțiuni pentru încălcarea RGPDA healthcare operator was fined for failing to implement adequate security measures, which led to unauthorized access to personal data. The case indicates a breach of data protection obligations under the GDPR. | RO | ANSPDCP | GDPR | €3,000 | ↗ |
| 27 Feb 2025 | Ministero dell’Interno-Dipartimento per gli affari interni e territorialiThe Ministry of the Interior was fined EUR 3,000 for processing personal data through the CIE-Agenda Online service. The authority found that the processing did not comply with the principles of lawfulness, fairness, transparency, and purpose limitation. | IT | Garante | GDPR | €3,000 | ↗ |
| 16 Jun 2010 | Anonymised (HDPA 29/2010)The company was fined 3,000 EUR by the HDPA for unlawfully processing email addresses without prior consent. This conduct breached Greek data protection law. | GR | HDPA | GDPR | €3,000 | ↗ |
| 26 Mar 2026 | Comune di XXThe Garante fined Comune di XX EUR 3,000 for breaches of GDPR Articles 6 and 9 and Article 2-ter of the Italian Privacy Code. The case concerned processing personal data without a proper legal basis. | IT | Garante | GDPR | €3,000 | ↗ |
| 11 Dec 2008 | agenzia funebre floricoltura Rampura di Loi AlessandroThe funeral agency was fined by the Garante for providing clients with inadequate information. The authority found this to be a breach of data protection rules. | IT | Garante | GDPR | €3,000 | ↗ |
| 20 Mar 2008 | Frareg s.r.l.Frareg s.r.l. was fined by the Garante for sending advertising material by fax without providing prior and adequate information to recipients. The authority found this to be a breach of data protection rules. | IT | Garante | GDPR | €3,000 | ↗ |
| 01 Jan 2020 | GROW BEATS SL.GROW BEATS SL. was fined 3,000 EUR by the AEPD for failing to provide required privacy policy information and for improper use of cookies without user consent. The case concerned website practices and indicates deficiencies in notice and consent requirements. | ES | AEPD | ePrivacy | €3,000 | ↗ |
| 20 Mar 2008 | Cid-Centro informazioni didatticoCid-Centro informazioni didattico was fined 3,000 EUR by the Garante for sending advertising material by fax without providing prior and adequate information to recipients. The conduct breached data protection rules. | IT | Garante | GDPR | €3,000 | ↗ |
| 26 Jun 2008 | Contact point s.r.l.Contact point s.r.l. was fined 3,000 EUR by the Garante for violating data protection rules. The case concerned improper handling of personal data during opinion surveys. | IT | Garante | GDPR | €3,000 | ↗ |
| 17 Mar 2021 | SOLRAM T Y R S.L.SOLRAM T Y R S.L. was fined by the AEPD in the amount of 3,000 EUR for failing to delete personal data from its databases. The authority found a breach of Article 17 GDPR after the company continued sending unsolicited commercial messages via WhatsApp. | ES | AEPD | GDPR | €3,000 | ↗ |
| 12 Feb 2021 | ELECTROTECNIA BASTIDA, S.L.ELECTROTECNIA BASTIDA, S.L. was fined by the AEPD 3,000 EUR for leaving employees’ confidential medical information abandoned in a field. The incident constituted a breach of data protection rules and required supervisory action. | ES | AEPD | GDPR | €3,000 | ↗ |
| 17 Jul 2025 | AVOCAT (procédure simplifiée)The CNIL imposed an administrative fine of 3,000 EUR on AVOCAT and issued an injunction. The case was handled under a simplified procedure. | FR | CNIL | GDPR | €3,000 | ↗ |
| 15 Sept 2022 | ADENET SYSTEMS, S.L.ADENET SYSTEMS, S.L. was fined by the AEPD for obstructing the data protection authority’s inspection. The conduct breached Article 58(1) GDPR. | ES | AEPD | GDPR | €3,000 | ↗ |
| 22 Feb 2024 | Comune di MonterotondoThe Garante imposed a EUR 3,000 fine on Comune di Monterotondo for breaches involving data processing agreements and security measures. The case also involved improper use of video surveillance. The authority found that the controller did not meet data protection requirements. | IT | Garante | GDPR | €3,000 | ↗ |