BULLETIN №083Last updated · 11 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.1%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 05 Mar 2024 | ROCA & ASOCIADOS ABOGADOS Y ECONOMISTAS, S.L.P.ROCA & ASOCIADOS ABOGADOS Y ECONOMISTAS, S.L.P. was fined 5,000 EUR by the AEPD. The authority found that the company published employees’ personal data on its website without consent, breaching Article 6(1) of the GDPR. | ES | AEPD | GDPR | €5,000 | ↗ |
| 05 Mar 2024 | EURO MINI STORAGE ROMANIA SRLEURO MINI STORAGE ROMANIA SRL was fined by ANSPDCP EUR 5,000 for a data security breach caused by a cyber attack. The incident led to unauthorized access to personal data and affected data availability for several weeks. | RO | ANSPDCP | GDPR | €5,000 | ↗ |
| 06 Mar 2024 | The Central Young Men’s Christian AssociationThe Central YMCA sent an email to participants in a programme for people living with HIV using “CC” instead of “BCC”, which exposed recipients’ email addresses to all recipients. From those addresses, 166 individuals could be identified or potentially identified, allowing an inference that they were likely living with HIV. The ICO imposed a £7,500 fine and issued a reprimand. | GB | ICO | GDPR | €8,772 | ↗ |
| 06 Mar 2024 | Sectorul 1 al Municipiului BucureștiSectorul 1 of Bucharest was fined 159,000 RON by ANSPDCP for failing to comply with a remediation measure. The authority had required the requested information to be provided within 10 days, but the obligation was not met. | RO | ANSPDCP | GDPR | €31,988 | ↗ |
| 07 Mar 2024 | Banca di Credito Cooperativo Appulo Lucana soc. cooperativaThe Garante fined Banca di Credito Cooperativo Appulo Lucana 20,000 EUR for failing to provide adequate access to personal data requested by a former employee. The authority found a breach of GDPR Article 15 on the right of access. | IT | Garante | GDPR | €20,000 | ↗ |
| 07 Mar 2024 | CAIXABANK, S.A.CAIXABANK, S.A. was fined by the AEPD EUR 2,000,000 for pre-setting consent to share data with the Social Security Treasury without giving customers the option to refuse. The authority found this practice breached GDPR requirements for valid consent. | ES | AEPD | GDPR | €2,000,000 | ↗ |
| 07 Mar 2024 | BdM Banca S.p.a.BdM Banca S.p.a. was fined 10,000 EUR by the Garante for failing to provide an adequate response to a data access request submitted by an heir. The authority found that the response did not meet the requirements of GDPR Article 15. | IT | Garante | GDPR | €10,000 | ↗ |
| 07 Mar 2024 | Pinnacle Life LimitedBetween 5 May 2021 and 5 May 2022, the company made 47,998 connected unsolicited direct marketing calls to subscribers registered with the TPS who had not consented to receive such calls. Four complaints were submitted, and the ICO imposed a fine of 80,000 GBP. | GB | ICO | GDPR | €93,624 | ↗ |
| 07 Mar 2024 | Giuliana VinziThe Garante fined Giuliana Vinzi, owner of Rocky Bar, 2,000 EUR for operating video surveillance without the required notices to data subjects. The authority also found that authorization from the Labor Inspectorate was missing, resulting in a GDPR breach. | IT | Garante | GDPR | €2,000 | ↗ |
| 07 Mar 2024 | Centro Riparazioni Piacentino S.p.A.Centro Riparazioni Piacentino S.p.A. was fined by the Garante for continuing to operate individual company accounts months after employment ended and for accessing messages without proper deletion. The authority also found inadequate information and insufficient access rights for former employees. | IT | Garante | GDPR | €20,000 | ↗ |
| 07 Mar 2024 | Ministero della saluteThe Italian Ministry of Health was fined EUR 100,000 by the Garante for inadequate data protection and communication measures in the National Health Information System. The authority found breaches of GDPR requirements on data security and breach notification. | IT | Garante | GDPR | €100,000 | ↗ |
| 07 Mar 2024 | Hotel Milano di Foschi Eros e Righini Rina & C. SncThe Garante fined Hotel Milano EUR 3,000 for improper installation of surveillance cameras. The cameras captured public streets and third-party properties, and the informational signage was inadequate. | IT | Garante | GDPR | €3,000 | ↗ |
| 12 Mar 2024 | SARARTE, S.L.SARARTE, S.L. was fined 6,000 EUR by the AEPD for disclosing personal data, including a private mobile number, to 18 people without consent. The case indicates a breach of data protection rules and unauthorized sharing of information. | ES | AEPD | GDPR | €6,000 | ↗ |
| 12 Mar 2024 | DKN.5131.28.2023StatusprawomocnaTytuUODO imposed an administrative fine of PLN 78,575.4 for failing to report a personal data breach without undue delay. The incident was not notified to the supervisory authority within 72 hours of becoming aware of the breach. | PL | UODO | GDPR | €18,331 | ↗ |
| 12 Mar 2024 | Dane anonimowe (U.)An administrative fine was imposed for failing to notify the supervisory authority of a personal data breach within the required 72 hours after detection. The authority also found that the affected individuals were not informed without undue delay. | PL | UODO | GDPR | €336,000 | ↗ |
| 12 Mar 2024 | Fiziska personaA monetary penalty of 150 EUR was imposed by DVI. The decision is final and has entered into force. | LV | DVI | GDPR | €150 | ↗ |
| 15 Mar 2024 | LEADDESK, S.L.LEADDESK, S.L. was fined by the AEPD for failing to provide information requested by the data protection authority during an investigation. The conduct breached Article 58(1) GDPR and hindered supervisory oversight. | ES | AEPD | GDPR | €6,000 | ↗ |
| 18 Mar 2024 | Arbeids- og velferdsetaten (NAV)On 18.03.2024, Datatilsynet imposed a NOK 20 million administrative fine and additional orders on Arbeids- og velferdsetaten (NAV). The case concerned inadequate protection of confidentiality through access control and log monitoring, with several serious compliance deficiencies identified. | NO | Datatilsynet | GDPR | €1,730,000 | ↗ |
| 18 Mar 2024 | Arbeids- og velferdsetaten (NAV)The Norwegian DPA, Datatilsynet, fined NAV 20,000,000 NOK for inadequate confidentiality safeguards in access control and logging. The authority identified structural and organizational weaknesses in the protection of personal data. | NO | Datatilsynet | GDPR | €1,730,000 | ↗ |
| 19 Mar 2024 | DIGI SPAIN TELECOM, S.L.DIGI SPAIN TELECOM, S.L. was fined by the AEPD for failing to verify the identity of a person who obtained a SIM duplicate. This omission led to unauthorized transactions and was treated as a breach of Article 6(1) GDPR. | ES | AEPD | GDPR | €200,000 | ↗ |