BULLETIN №083Last updated · 11 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.1%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 19 Mar 2024 | LOCAL VERTICALS, S.L.LOCAL VERTICALS, S.L. was fined by the AEPD 10,000 EUR for storing cookies without user consent and for failing to provide a legal notice on its website. The case concerns breaches of data protection rules and website transparency obligations. | ES | AEPD | ePrivacy | €10,000 | ↗ |
| 20 Mar 2024 | Stjarnan ehf.Stjarnan ehf., operating Subway in Iceland, was fined by Persónuvernd for unlawful electronic surveillance of employees. The authority found that employees were not properly notified and were not adequately informed about their rights. | IS | Persónuvernd | GDPR | €10,095 | ↗ |
| 21 Mar 2024 | Azienda sanitaria locale Roma 3The Garante fined Azienda sanitaria locale Roma 3 10,000 EUR for failing to adequately protect personal data. The breach led to attempted unauthorized access to user accounts and indicated insufficient cybersecurity controls. | IT | Garante | GDPR | €10,000 | ↗ |
| 21 Mar 2024 | Budapesti Rendőr-főkapitányság XI. kerületi RendőrkapitányságBudapesti Rendőr-főkapitányság XI. kerületi Rendőrkapitányság was fined by NAIH 300,000 HUF for violations related to the closed handling of personal data. The authority found breaches of several provisions of the Hungarian Information Act (Infotv.). | HU | NAIH | GDPR | €762 | ↗ |
| 21 Mar 2024 | Regione LazioThe Garante fined Regione Lazio EUR 120,000 for inadequate security measures that led to attempted unauthorized access to user accounts. The authority found a breach of GDPR requirements on data protection and processing security. | IT | Garante | GDPR | €120,000 | ↗ |
| 21 Mar 2024 | Imperatori Immobiliari s.r.l.The Garante fined Imperatori Immobiliari s.r.l. 4,000 EUR for operating a surveillance system without the required informational signage. The authority treated this as a breach of data protection rules. | IT | Garante | GDPR | €4,000 | ↗ |
| 21 Mar 2024 | Estlevante s.r.l.s.The Garante imposed a EUR 2,000 fine on Estlevante s.r.l.s. for failing to provide the required privacy notice for its video surveillance system. The breach concerned Article 13 of the GDPR. | IT | Garante | GDPR | €2,000 | ↗ |
| 21 Mar 2024 | LAZIOcrea S.p.a.LAZIOcrea S.p.a. was fined by the Garante for failing to implement adequate technical and organizational measures to ensure data security. The deficiencies led to unauthorized access attempts and temporary unavailability of regional services. | IT | Garante | GDPR | €271,000 | ↗ |
| 22 Mar 2024 | NH HOTEL GROUP S.A.NH HOTEL GROUP S.A. was fined by the AEPD EUR 10,000 for using cookies on its website without obtaining user consent. The authority found this to be a breach of the LSSI rules on cookie consent. | ES | AEPD | ePrivacy | €10,000 | ↗ |
| 25 Mar 2024 | KUR KLINIKUM, S.L.KUR KLINIKUM, S.L. was fined EUR 1,000 by the AEPD for failing to comply with a data protection authority resolution. The case concerned the right of access to personal data. | ES | AEPD | GDPR | €1,000 | ↗ |
| 28 Mar 2024 | SIA “JK Media group”The DVI imposed a fine of EUR 1,000 on SIA “JK Media group”. The decision is final and has entered into force. | LV | DVI | GDPR | €1,000 | ↗ |
| 01 Apr 2024 | Your Consulting SRLANSPDCP imposed a fine on Your Consulting SRL for GDPR violations related to insufficient technical and organizational security measures. The security gap allowed unauthorized access to personal data through one of the company’s applications. | RO | ANSPDCP | GDPR | €3,000 | ↗ |
| 03 Apr 2024 | Fiziska personaA fine of EUR 150 was imposed by the DVI. The decision is final and has entered into force. | LV | DVI | GDPR | €150 | ↗ |
| 04 Apr 2024 | COMMERCE DE DETAIL DE MATERIEL DE TELECOMMUNICATIONCNIL imposed an administrative fine of EUR 525,000 on COMMERCE DE DETAIL DE MATERIEL DE TELECOMMUNICATION. The case concerns identified breaches of rules supervised by CNIL. | FR | CNIL | GDPR | €525,000 | ↗ |
| 04 Apr 2024 | SOCIETE AYANT POUR ACTIVITE LA PROSPECTION COMMERCIALE PAR COURRIEL POUR LE COMPTE D'ANNONCEURSThe CNIL imposed EUR 25,000 on SOCIETE AYANT POUR ACTIVITE LA PROSPECTION COMMERCIALE PAR COURRIEL POUR LE COMPTE D'ANNONCEURS as a liquidation of a penalty. The measure relates to non-compliance with a prior obligation and is enforcement in nature. | FR | CNIL | GDPR | €25,000 | ↗ |
| 04 Apr 2024 | GAFAS EN RED DE ÓPTICAS, S.L.GAFAS EN RED DE ÓPTICAS, S.L. was fined €10,000 by the AEPD for sending unsolicited advertising SMS messages without providing an opt-out link. The conduct breached the LSSI rules governing electronic marketing communications. | ES | AEPD | ePrivacy | €10,000 | ↗ |
| 05 Apr 2024 | PALANCAMAR, S.L.PALANCAMAR, S.L. was fined EUR 5,000 by the AEPD for failing to inform a customer about the processing of their personal data during a vehicle purchase. The authority treated this as a breach of Article 13 GDPR. | ES | AEPD | GDPR | €5,000 | ↗ |
| 08 Apr 2024 | VODAFONE ESPAÑA, S.A.U.The AEPD imposed a fine of 250,000 EUR on VODAFONE ESPAÑA, S.A.U. for failing to implement adequate measures to prevent unauthorized access to personal data. The authority found a breach of the GDPR confidentiality requirements. | ES | AEPD | GDPR | €250,000 | ↗ |
| 08 Apr 2024 | IBERDROLA CLIENTES, S.A.U.IBERDROLA CLIENTES, S.A.U. was fined by the AEPD 200,000 EUR for unlawfully including personal data in a credit information system without proper notification. The authority found this to be a breach of data protection rules. | ES | AEPD | GDPR | €200,000 | ↗ |
| 09 Apr 2024 | ADNAYA GREEN SOLUTIONS, S.L.ADNAYA GREEN SOLUTIONS, S.L. was fined by the AEPD EUR 10,000 for unlawfully sharing personal data with a third party without consent. The authority found this conduct breached Article 6(1) of the GDPR. | ES | AEPD | GDPR | €10,000 | ↗ |