BULLETIN №083Last updated · 08 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.6%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 05 Oct 2017 | Qiu JunjieQiu Junjie was fined EUR 10,000 by the Garante for failing to protect video surveillance recordings with a password. The authority found this breached the minimum security measures required under the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 04 Oct 2017 | PRENATAL SAPRENATAL SA was fined by the AEPD EUR 20,000 for sending commercial SMS messages without providing recipients with an opt-out mechanism. The case concerns a breach of electronic communications rules and marketing consent requirements. | ES | AEPD | ePrivacy | €20,000 | ↗ |
| 21 Sept 2017 | Tra.n.sider S.p.A.Tra.n.sider S.p.A. was fined EUR 20,000 by the Italian Garante. The case concerned the failure to notify the installation of a geolocation system on company vehicles, breaching data protection notification requirements. | IT | Garante | GDPR | €20,000 | ↗ |
| 21 Sept 2017 | AMI S.p.A.AMI S.p.A. was fined by the Garante for installing electronic monitoring and localization devices on public transport vehicles without proper notification. The authority found this to be a breach of data protection rules. | IT | Garante | GDPR | €40,000 | ↗ |
| 21 Sept 2017 | Unidata s.p.a.Unidata s.p.a. was fined EUR 36,000 by the Garante for failing to implement adequate security measures for personal data processing. The authority noted, among other issues, the use of passwords shorter than eight characters, which breached data protection requirements. | IT | Garante | GDPR | €36,000 | ↗ |
| 19 Sept 2017 | CEPSA COMERCIAL PETRÓLEO, S.A.U.CEPSA was fined by the AEPD 3,300 EUR for sending two unsolicited commercial emails without prior consent from the recipients. The authority found this breached Article 21 of the LSSI on commercial communications. | ES | AEPD | ePrivacy | €3,300 | ↗ |
| 13 Sept 2017 | Coleman s.p.a.Coleman s.p.a. was fined by the Garante 20,000 EUR for failing to implement minimum security measures for online booking requests. This allowed access to personal data without authentication. | IT | Garante | GDPR | €20,000 | ↗ |
| 13 Sept 2017 | NO QUIERO PERDER EL TIEMPO, S.L.The company was fined by the AEPD for displaying the AEPD quality seal and another association’s seal on its website without authorization. The authority also found inadequate information and no valid consent for data collection. | ES | AEPD | ePrivacy | €8,000 | ↗ |
| 13 Sept 2017 | Jump 3000 s.r.l.Jump 3000 s.r.l. was fined by the Garante 14,800 EUR for providing clients with inadequate data protection information. The authority found that the privacy notices did not properly identify the data controller. | IT | Garante | GDPR | €14,800 | ↗ |
| 13 Sept 2017 | MASTERZEN, S.L.MASTERZEN, S.L. was fined by the AEPD €4,500 for sending unsolicited marketing emails without the recipient’s consent. The emails were sent despite the recipient’s objection, indicating a breach of rules on direct electronic marketing. | ES | AEPD | ePrivacy | €4,500 | ↗ |
| 13 Sept 2017 | Serval s.r.l.Serval s.r.l. was fined by the Garante in the amount of €10,000 for failing to adopt minimum security measures. The authority also found that employees were not appointed as data processors, in breach of the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 12 Sept 2017 | Little Kook - K. Tzortzis – I. Thanos I.K.EThe company was fined EUR 7,000 by the HDPA for operating a video surveillance system without proper notification to the authority. It also monitored employee workspaces, which breached privacy requirements. | GR | HDPA | GDPR | €7,000 | ↗ |
| 06 Sept 2017 | ORANGE ESPAGNE, S.A.U.ORANGE ESPAGNE, S.A.U. was fined EUR 66,000 by the AEPD for sending commercial SMS messages without consent. The authority also found that recipients were not given an effective option to object, in breach of the LSSI rules. | ES | AEPD | ePrivacy | €66,000 | ↗ |
| 04 Aug 2017 | VodafoneVodafone was fined 5,000 EUR by the HDPA for failing to satisfy the complainant’s request to access their personal data. The case concerns a breach of the data subject’s access rights under the controller’s obligations. | GR | HDPA | GDPR | €5,000 | ↗ |
| 04 Aug 2017 | STAPLES PRODUCTOS DE OFICINA S.L.U.STAPLES PRODUCTOS DE OFICINA S.L.U. was fined EUR 2,000 by the AEPD for sending unsolicited commercial emails. The breach involved continuing to contact recipients despite requests to cancel consent. | ES | AEPD | ePrivacy | €2,000 | ↗ |
| 04 Aug 2017 | VodafoneThe HDPA imposed a €10,000 fine on Vodafone for unlawfully processing the complainant's credit card data without consent. The case concerns a breach of the legal basis requirements for personal data processing. | GR | HDPA | GDPR | €10,000 | ↗ |
| 04 Aug 2017 | VODAFONE ONO, S.A.U.VODAFONE ONO, S.A.U. was fined by the AEPD in the amount of 6,000 EUR for making numerous advertising calls to numbers registered on the Robinson List. The conduct breached privacy rules and the right to object to direct marketing. | ES | AEPD | ePrivacy | €6,000 | ↗ |
| 26 Jul 2017 | Equilibra s.r.l.Equilibra s.r.l. was fined by the Garante for failing to provide adequate data protection information to individuals and for not appointing the required data processing officers. The case concerned breaches of the Italian Data Protection Code. | IT | Garante | GDPR | €12,400 | ↗ |
| 26 Jul 2017 | Istituto scolastico "A. Mantegna"Istituto scolastico "A. Mantegna" was fined by the Garante for unlawfully publishing students’ personal data, including sensitive information, on its website without a legal basis. The case concerned a breach of lawfulness and data minimization requirements. | IT | Garante | GDPR | €4,000 | ↗ |
| 26 Jul 2017 | Cloud Europa s.r.l.Cloud Europa s.r.l. was fined EUR 40,000 by the Garante. The authority found that the company failed to respond to requests for information concerning unsolicited promotional phone calls, in breach of data protection rules. | IT | Garante | GDPR | €40,000 | ↗ |