BULLETIN №083Last updated · 11 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.1%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 22 Feb 2024 | Unica s.r.l.s.Unica s.r.l.s. was fined by the Garante EUR 2,000 for using a facial recognition system to record employee attendance without a proper legal basis. The authority found that the processing of biometric data breached GDPR requirements. | IT | Garante | GDPR | €2,000 | ↗ |
| 22 Feb 2024 | Comune di Civita CastellanaComune di Civita Castellana was fined EUR 3,000 by the Garante for improper handling of personal data during COVID-19 data transmission. The authority found that GDPR formalities were not properly complied with. | IT | Garante | GDPR | €3,000 | ↗ |
| 22 Feb 2024 | Ordine dei Medici Veterinari della Provincia di LatinaOrdine dei Medici Veterinari della Provincia di Latina was fined by the Garante 5,000 EUR for breaches of data protection principles. The case involved the unlawful communication of personal data to its members. | IT | Garante | GDPR | €5,000 | ↗ |
| 22 Feb 2024 | BLU MANAGEMENT SPAIN, S.L.BLU MANAGEMENT SPAIN, S.L. was fined €2,000 by the AEPD for sharing a job applicant’s contact details without consent. The authority treated this as a breach of data protection rules. | ES | AEPD | GDPR | €2,000 | ↗ |
| 22 Feb 2024 | Trasporto Passeggeri Emilia-Romagna S.p.A.The Garante fined Trasporto Passeggeri Emilia-Romagna S.p.A. 50,000 EUR for improper data processing and a lack of transparency in collecting consent for marketing purposes. The case concerned failures to properly inform data subjects and to meet consent requirements. | IT | Garante | GDPR | €50,000 | ↗ |
| 22 Feb 2024 | Ordine dei Medici Chirurghi e Odontoiatri di PadovaOrdine dei Medici Chirurghi e Odontoiatri di Padova was fined 5,000 EUR by the Garante. The authority found breaches of lawfulness, fairness, transparency, and data minimization in the handling of personal data. | IT | Garante | GDPR | €5,000 | ↗ |
| 22 Feb 2024 | Sigma s.r.l.Sigma s.r.l. was fined EUR 150,000 by the Garante for unauthorized activation of paid services and devices using customer data without consent. The authority found that the company’s conduct breached GDPR rules on personal data processing. | IT | Garante | GDPR | €150,000 | ↗ |
| 22 Feb 2024 | L’Igiene Urbana Evolution s.r.l.L’Igiene Urbana Evolution s.r.l. was fined €70,000 by the Garante for unlawfully processing biometric data through facial recognition to monitor employee attendance. The authority found that this practice violated GDPR requirements. | IT | Garante | GDPR | €70,000 | ↗ |
| 22 Feb 2024 | Airone società consortile a r.l.Airone società consortile a r.l. was fined EUR 5,000 by Garante for unlawfully processing biometric data through facial recognition to monitor employee attendance. The authority found that the same purpose could have been achieved by less intrusive means. | IT | Garante | GDPR | €5,000 | ↗ |
| 22 Feb 2024 | Comune di MonterotondoThe Garante imposed a EUR 3,000 fine on Comune di Monterotondo for breaches involving data processing agreements and security measures. The case also involved improper use of video surveillance. The authority found that the controller did not meet data protection requirements. | IT | Garante | GDPR | €3,000 | ↗ |
| 23 Feb 2024 | ENERGY WINNER, S.L.ENERGY WINNER, S.L. was fined EUR 600 by the AEPD. The case concerned the failure to provide access to personal data and information requested by the data protection authority, which constitutes a breach of Article 58.1 GDPR. | ES | AEPD | GDPR | €600 | ↗ |
| 25 Feb 2024 | SOCIEDAD ANDALUZA DE CHARTERS ATLÁNTICOS S.L.The company was fined EUR 500 by the AEPD for collecting excessive personal data during guest registration. In particular, it obtained full copies of ID documents and facial photographs, which breached the data minimization principle. | ES | AEPD | GDPR | €500 | ↗ |
| 26 Feb 2024 | Ministry of DefenceThe UK Ministry of Defence sent emails using the “To” field instead of “BCC”, which disclosed 265 unique email addresses. The ICO found this breached GDPR Article 5(1)(f) and imposed a fine of 350,000 GBP. | GB | ICO | GDPR | €409,000 | ↗ |
| 26 Feb 2024 | VESTAS CEU ROMÂNIA SRLThe company was fined EUR 3,000 by ANSPDCP for unauthorized disclosure of personal data. The breach included names, place of residence, salary, and CV details. | RO | ANSPDCP | GDPR | €3,000 | ↗ |
| 28 Feb 2024 | Hellenic Post S.A.Hellenic Post S.A. was fined by the HDPA for insufficient technical and organizational measures to protect data. The deficiencies led to unauthorized access and a data breach. | GR | HDPA | GDPR | €2,995,000 | ↗ |
| 29 Feb 2024 | WATIUM S.L.WATIUM S.L. was fined by the Spanish Data Protection Agency (AEPD) in the amount of EUR 160,000. The case concerned the failure to provide the required information, which constitutes a breach of Article 58.1 of the GDPR. | ES | AEPD | GDPR | €160,000 | ↗ |
| 29 Feb 2024 | SOCIETE AYANT POUR ACTIVITE LA RECHERCHE ET LE DEVELOPPEMENT SCIENTIFIQUE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 10,000 on SOCIETE AYANT POUR ACTIVITE LA RECHERCHE ET LE DEVELOPPEMENT SCIENTIFIQUE under a simplified procedure. The case concerns a violation identified by the French supervisory authority. | FR | CNIL | GDPR | €10,000 | ↗ |
| 29 Feb 2024 | CHIRURGIEN DENTISTE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 4,000 on CHIRURGIEN DENTISTE under a simplified procedure. The case concerns a breach of rules covered by the supervisory authority’s decision. | FR | CNIL | GDPR | €4,000 | ↗ |
| 03 Mar 2024 | FUNDACIÓN C.R.E.T.A. CENTRO PARA EL ESTUDIO Y REPRESENTACIÓN DEL TEATRO ANTIGUOThe organization failed to properly handle a data subject access request. AEPD imposed a fine of 1,000 EUR for non-compliance with GDPR obligations. | ES | AEPD | GDPR | €1,000 | ↗ |
| 04 Mar 2024 | EXESRIVAS GESTIÓN PATRIMONIALThe entity sent unsolicited commercial messages via WhatsApp despite the complainant's explicit refusal to receive such communications. AEPD found a breach of Article 21 of the LSSI and imposed a 300 EUR fine. | ES | AEPD | ePrivacy | €300 | ↗ |