BULLETIN №083Last updated · 10 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.1%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 31 Jan 2024 | MARINA SALUD, S.A.MARINA SALUD, S.A. was fined by the AEPD 500,000 EUR for failing to comply with data processing agreement obligations under Article 28 GDPR. The case involved the handling of sensitive health data, which increased the compliance risk. | ES | AEPD | GDPR | €500,000 | ↗ |
| 31 Jan 2024 | Uber Technologies Inc. en Uber B.V.Uber Technologies Inc. and Uber B.V. were fined by the AP for failing to provide guidance notes in local languages, for making data access request information insufficiently accessible, and for giving inadequate privacy policy details on data retention and transfer. The authority found these shortcomings breached GDPR transparency requirements. | NL | AP | GDPR | €10,000,000 | ↗ |
| 31 Jan 2024 | SOCIETE AYANT POUR ACTIVITE LE SOUTIEN AUX ENTREPRISES (procédure simplifiée)The CNIL imposed an administrative fine of EUR 10,000 on SOCIETE AYANT POUR ACTIVITE LE SOUTIEN AUX ENTREPRISES. The decision concerns a breach of rules supervised by the CNIL. | FR | CNIL | GDPR | €10,000 | ↗ |
| 31 Jan 2024 | EDITEUR DE SITE WEB - ACTUALITES DANS LE DOMAINE DES NOUVELLES TECHNOLOGIES (procédure simplifiée)The CNIL imposed an administrative fine of EUR 20,000 on EDITEUR DE SITE WEB - ACTUALITES DANS LE DOMAINE DES NOUVELLES TECHNOLOGIES under a simplified procedure. The case concerned a breach of personal data protection rules. | FR | CNIL | GDPR | €20,000 | ↗ |
| 31 Jan 2024 | SOCIETE AYANT POUR ACTIVITE LA COMMERCIALISATION ET GESTION DE PROGRAMMES ET CARTES DE FIDELITECNIL imposed an administrative fine of EUR 310,000 on SOCIETE AYANT POUR ACTIVITE LA COMMERCIALISATION ET GESTION DE PROGRAMMES ET CARTES DE FIDELITE. The case concerns identified breaches of rules supervised by CNIL. | FR | CNIL | GDPR | €310,000 | ↗ |
| 31 Jan 2024 | CHIRURGIEN DENTISTE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 5,000 on CHIRURGIEN DENTISTE. The case was handled under a simplified procedure. | FR | CNIL | GDPR | €5,000 | ↗ |
| 31 Jan 2024 | PARTICULIER (procédure simplifiée)CNIL imposed an administrative fine of EUR 500 on PARTICULIER under a simplified procedure. The case concerned a regulatory breach, with no further details provided in the record. | FR | CNIL | GDPR | €500 | ↗ |
| 01 Feb 2024 | HOGAR LUZ Y GAS S.L.HOGAR LUZ Y GAS S.L. was fined EUR 4,000 by the Spanish Data Protection Agency (AEPD). The case concerned the failure to provide requested information, which breaches Article 58.1 of the GDPR. | ES | AEPD | GDPR | €4,000 | ↗ |
| 01 Feb 2024 | Capio A/SThe Danish Data Protection Authority reported Capio A/S to the police and recommended a fine of at least DKK 1,500,000. The case concerned insufficient supervision of data processors, breaching the GDPR accountability principle. | DK | Datatilsynet | GDPR | €201,000 | ↗ |
| 02 Feb 2024 | SIA "AQUAPHOTO"DVI imposed a fine of 1,000 EUR on SIA "AQUAPHOTO". The decision has been appealed to court. | LV | DVI | GDPR | €1,000 | ↗ |
| 02 Feb 2024 | [...] Zrt.The controller did not provide adequate information about data processing through camera systems in bank branches. This constituted a breach of GDPR Articles 12 and 13. | HU | NAIH | GDPR | €156,000 | ↗ |
| 05 Feb 2024 | Asociație de proprietari din Miercurea CiucIn January 2024, ANSPDCP completed an investigation at a homeowners’ association in Miercurea Ciuc and found a breach of GDPR provisions. The operator was fined EUR 500. | RO | ANSPDCP | GDPR | €500 | ↗ |
| 06 Feb 2024 | GESTIÓN DE PATRIMONIOS ANFIPOLIS SOCIEDAD DE RESPONSABILIDAD LIMITADAThe AEPD fined GESTIÓN DE PATRIMONIOS ANFIPOLIS SOCIEDAD DE RESPONSABILIDAD LIMITADA EUR 2,000 for sending unsolicited commercial communications without the recipient's consent. The authority noted that the messages were sent despite the recipient's opposition. | ES | AEPD | ePrivacy | €2,000 | ↗ |
| 07 Feb 2024 | Account Exchange SRLAccount Exchange SRL was fined EUR 2,000 by ANSPDCP for violating GDPR provisions related to data processing. The case concerned non-compliant processing of personal data. | RO | ANSPDCP | GDPR | €2,000 | ↗ |
| 07 Feb 2024 | GESTIÓN DE PATRIMONIOS ANFIPOLIS SOCIEDAD DE RESPONSABILIDAD LIMITADAThe entity was fined by the AEPD 4,000 EUR for failing to provide access to personal data and the information requested by the data protection authority. The case concerns non-compliance with Article 58.1 of the GDPR. | ES | AEPD | GDPR | €4,000 | ↗ |
| 08 Feb 2024 | AREIA CONSULTING, LTDAREIA CONSULTING, LTD was fined by the AEPD in the amount of 2,000 EUR for sending unsolicited commercial emails without prior recipient consent. The authority found this conduct breached Article 21 of the LSSI. | ES | AEPD | ePrivacy | €2,000 | ↗ |
| 08 Feb 2024 | Agenzia territoriale della Regione Puglia per il servizio di gestione dei rifiuti (AGER)The Garante fined Agenzia territoriale della Regione Puglia per il servizio di gestione dei rifiuti (AGER) EUR 6,000. The authority found that the organization failed to appoint a Data Protection Officer in a timely manner, despite the GDPR requirement being in force for about three years. | IT | Garante | GDPR | €6,000 | ↗ |
| 08 Feb 2024 | ADADE BURGOS, S.L.ADADE BURGOS, S.L. was fined by the AEPD 5,000 EUR for improper use of personal data. The company informed clients about an employee’s disciplinary dismissal in a manner that breached data protection rules. | ES | AEPD | GDPR | €5,000 | ↗ |
| 08 Feb 2024 | Medtronic Italia S.p.a.Medtronic Italia S.p.a. was fined by the Garante in the amount of €300,000 for a data protection breach. The authority found inadequate technical and organizational measures that led to unauthorized disclosure of data. | IT | Garante | GDPR | €300,000 | ↗ |
| 12 Feb 2024 | MEYDIS, S.L.MEYDIS, S.L. was fined EUR 80,000 by the AEPD for failing to provide required information during an investigation. The authority found a breach of Article 58.1 of the GDPR. | ES | AEPD | GDPR | €80,000 | ↗ |