BULLETIN №083Last updated · 11 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.1%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 11 Apr 2024 | BAR DEL PORTICO S.A.S.BAR DEL PORTICO S.A.S. was fined EUR 1,000 by the Garante for operating active video surveillance. The system recorded both customers and employees without meeting GDPR requirements. | IT | Garante | GDPR | €1,000 | ↗ |
| 11 Apr 2024 | Facile.Energy S.r.l.Facile.Energy S.r.l. was fined EUR 100,000 by the Garante for making unsolicited promotional calls without prior consent and activating energy supplies without a request from the customer. The authority found that these practices breached GDPR rules on data protection and security measures. | IT | Garante | GDPR | €100,000 | ↗ |
| 11 Apr 2024 | Innova Camera – Azienda speciale della Camera di commercio, industria, artigianato e agricoltura di RomaInnova Camera was fined by the Garante EUR 25,000 for inadequate data security measures. The breach resulted in personal data being accessed and published online following an SQL Injection attack. | IT | Garante | GDPR | €25,000 | ↗ |
| 11 Apr 2024 | Olimpia S.r.l.Olimpia S.r.l. was fined for making unsolicited promotional calls without prior consent and for using numbers listed in the Public Opposition Register. The conduct breached GDPR requirements on data protection and security measures. | IT | Garante | GDPR | €100,000 | ↗ |
| 11 Apr 2024 | Libero Consorzio comunale di EnnaThe Garante fined Libero Consorzio comunale di Enna €6,000 for improperly assigning tasks to the Data Protection Officer. Those tasks should have been performed by the data controller or processor, not the DPO. | IT | Garante | GDPR | €6,000 | ↗ |
| 11 Apr 2024 | Comune di MadignanoThe Garante fined Comune di Madignano EUR 3,000 for unlawfully using surveillance data in a disciplinary proceeding against an employee. The authority found breaches of data protection and transparency principles. | IT | Garante | GDPR | €3,000 | ↗ |
| 11 Apr 2024 | GS S.p.A.GS S.p.A. was fined by the Garante for failing to respond to an employee's access request. The request concerned disciplinary records and work time stamps, which constitutes a breach of GDPR Article 15. | IT | Garante | GDPR | €10,000 | ↗ |
| 11 Apr 2024 | Istituto Nazionale Previdenza Sociale - INPSThe Italian Data Protection Authority fined INPS EUR 20,000 for violating data protection principles. The case concerned the improper handling of candidates’ personal data in a public competition. | IT | Garante | GDPR | €20,000 | ↗ |
| 12 Apr 2024 | Centrul Medical dr. Furtună DanThe National Supervisory Authority for Personal Data Processing imposed a fine on Centrul Medical dr. Furtună Dan for breaching Article 6 of the GDPR. The infringement concerned the absence of a proper legal basis for personal data processing. | RO | ANSPDCP | GDPR | €1,500 | ↗ |
| 12 Apr 2024 | TECNOCRÁTICA CENTRO DE DATOS S.L.TECNOCRÁTICA CENTRO DE DATOS S.L. was fined by the AEPD for failing to provide access to personal data and information requested during an investigation. The authority found a breach of Article 58.1 of the GDPR. | ES | AEPD | GDPR | €6,000 | ↗ |
| 12 Apr 2024 | DATACENTRICDATACENTRIC was fined by the AEPD 60,000 EUR for processing personal data of self-employed individuals without a valid legal basis. The data was also exposed online and used for marketing purposes, breaching GDPR Articles 6(1) and 14. | ES | AEPD | GDPR | €60,000 | ↗ |
| 15 Apr 2024 | BANCO BILBAO VIZCAYA ARGENTARIA, S.A.Banco Bilbao Vizcaya Argentaria, S.A. was fined by the AEPD for including personal data in a credit solvency file without proper prior notice. The authority found this to be a breach of data protection rules. | ES | AEPD | GDPR | €200,000 | ↗ |
| 16 Apr 2024 | ARRENDAMIENTOS DEUDORES, S.L.ARRENDAMIENTOS DEUDORES, S.L. accessed personal data in the ASNEF file without proper authorization. The AEPD found a breach of Article 6(1) GDPR and imposed a fine of EUR 2,000. | ES | AEPD | GDPR | €2,000 | ↗ |
| 17 Apr 2024 | BANCO BILBAO VIZCAYA ARGENTARIA, S.A.BBVA was fined EUR 100,000 by the AEPD for processing a payment to a new account without the account holder’s explicit consent. The authority found this conduct to be a breach of GDPR Article 6. | ES | AEPD | GDPR | €100,000 | ↗ |
| 18 Apr 2024 | COMUNIDAD DE PROPIETARIOS R.R.R.The entity was fined for sending an email to all community members containing a list of individual heating consumption linked to specific apartments. The authority found this to be a breach of data protection rules. | ES | AEPD | GDPR | €600 | ↗ |
| 18 Apr 2024 | DELPASO CAR HIRE, S.L.U.DELPASO CAR HIRE, S.L.U. was fined by the AEPD EUR 2,000 for failing to provide a customer with access to their personal data. The authority found a breach of Article 15 of the GDPR. | ES | AEPD | GDPR | €2,000 | ↗ |
| 18 Apr 2024 | MOURO PRODUCCIONES, S.R.L.MOURO PRODUCCIONES, S.R.L. was fined by the AEPD 20,000 EUR for collecting copies of identity documents and personal data of minors and their guardians without proper data protection information. The authority found breaches of the data minimization and transparency principles. | ES | AEPD | GDPR | €20,000 | ↗ |
| 18 Apr 2024 | H&M Hennes & MauritzH&M Hennes & Mauritz GBC AB was fined for conducting camera surveillance without a legal basis and for failing to provide required information to data subjects. The authority found breaches of GDPR Articles 6(1) and 13. | SE | IMY | GDPR | €25,779 | ↗ |
| 22 Apr 2024 | S.C. Tensa Art Design S.A.In April 2024, ANSPDCP completed an investigation into S.C. Tensa Art Design S.A., the operator of www.lensa.ro. The authority found GDPR violations and imposed a fine of EUR 2,000. | RO | ANSPDCP | GDPR | €2,000 | ↗ |
| 22 Apr 2024 | B.B.B.The entity did not provide a way for the user to unsubscribe from the website. As a result, personal data was indexed on Google without the data subject’s consent. | ES | AEPD | GDPR | €300 | ↗ |