BULLETIN №083Last updated · 11 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.1%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 23 Apr 2024 | ALPHA BANK ROMANIA SAALPHA BANK ROMANIA SA was fined by ANSPDCP for a data security breach caused by improper management of a record system by an employee. This led to unauthorized disclosure and access to the personal data of certain clients. | RO | ANSPDCP | GDPR | €2,000 | ↗ |
| 23 Apr 2024 | Odsherred KommuneOdsherred Kommune was fined by Datatilsynet for failing to implement adequate security measures, including encryption of laptops containing sensitive personal data. The deficiency resulted in a data breach. | DK | Datatilsynet | GDPR | €13,404 | ↗ |
| 24 Apr 2024 | C.I.EL. S.p.A.C.I.EL. S.p.A. was fined 10,000 EUR by the Garante following a complaint from a former employee. The case concerned violations related to the right of access to training certificates. | IT | Garante | GDPR | €10,000 | ↗ |
| 24 Apr 2024 | Rossi Carta S.r.l. UnipersonaleRossi Carta S.r.l. Unipersonale was fined by the Garante 30,000 EUR for sending unsolicited promotional emails and failing to respond to a data subject rights request. The authority also noted the use of an outdated content management system on the company website, which created potential security risks for personal data. | IT | Garante | GDPR | €30,000 | ↗ |
| 24 Apr 2024 | I.N.P.A.S.The Garante imposed a fine on I.N.P.A.S. for violations related to the processing of employees' personal data, including sensitive data. The authority found that the processing did not ensure lawfulness, fairness, transparency, and data minimization. | IT | Garante | GDPR | €3,000 | ↗ |
| 24 Apr 2024 | Dane anonimowe (Komitet Inicjatywy Ustawodawczej W. na rzecz ustawy o zmianie ustawy z dn. 24 lipca 2015 r. Prawo o zgromadzeniach oraz niektórych innych ustaw)UODO imposed an administrative fine on the entity responsible for a list of citizens supporting a legislative initiative. The authority found inadequate technical and organisational measures for the risk, a failure to regularly test security controls, and delays in reporting and notifying the personal data breach. | PL | UODO | GDPR | €2,527 | ↗ |
| 24 Apr 2024 | Dly S.r.l.Dly S.r.l. was fined by the Garante EUR 5,000 for deploying a non-compliant video surveillance system. The system recorded both customers and employees, in breach of data protection rules. | IT | Garante | GDPR | €5,000 | ↗ |
| 24 Apr 2024 | Gestore Dei Servizi Energetici - Gse S.p.A.The Garante fined Gestore Dei Servizi Energetici - Gse S.p.A. 30,000 EUR for failing to respond to a data subject access request. The request concerned the individual's personal performance evaluation records for 2019 and 2020. | IT | Garante | GDPR | €30,000 | ↗ |
| 25 Apr 2024 | SOCIETE EXPLOITANT DES MAGASINS DE CHAUSSURES ET D'HABILLEMENT DE SPORT (procédure simplifiée)The CNIL imposed an administrative fine of EUR 15,000 on SOCIETE EXPLOITANT DES MAGASINS DE CHAUSSURES ET D'HABILLEMENT DE SPORT. The case was handled under a simplified procedure. | FR | CNIL | GDPR | €15,000 | ↗ |
| 25 Apr 2024 | ALL IN DIGITAL MARKETING, S.L.ALL IN DIGITAL MARKETING, S.L. was fined by the AEPD EUR 3,000 for sending unsolicited commercial emails without prior consent from recipients. The authority found this conduct to be in breach of Article 21 of the LSSI. | ES | AEPD | ePrivacy | €3,000 | ↗ |
| 25 Apr 2024 | REVUE LITTERAIRE FRANCAISE (procédure simplifiée)The CNIL imposed a EUR 3,000 penalty on REVUE LITTERAIRE FRANCAISE under a simplified procedure. The case concerns the liquidation of an astreinte, meaning enforcement of a previously ordered monetary obligation. | FR | CNIL | GDPR | €3,000 | ↗ |
| 25 Apr 2024 | ASSOCIATION PARTICIPANT AUX ACTIVITES DES ORGANISATIONS POLITIQUES (procédure simplifiée)The CNIL imposed an administrative fine of EUR 16,000 on ASSOCIATION PARTICIPANT AUX ACTIVITES DES ORGANISATIONS POLITIQUES. The authority also issued an injunction requiring corrective action. | FR | CNIL | GDPR | €16,000 | ↗ |
| 26 Apr 2024 | Nationalt Genom CenterThe Danish DPA fined Nationalt Genom Center 50,000 DKK for processing personal data without consulting the supervisory authority. Its own DPIA identified a high risk, which should have triggered prior consultation before processing began. | DK | Datatilsynet | GDPR | €6,705 | ↗ |
| 26 Apr 2024 | SANTANDER CONSUMER, S.A.SANTANDER CONSUMER, S.A. was fined by the AEPD in the amount of 50,000 EUR for sending postal advertising after the complainant had exercised the right to object to processing for marketing purposes. The case concerns failure to respect the data subject’s objection to commercial use of personal data. | ES | AEPD | GDPR | €50,000 | ↗ |
| 29 Apr 2024 | Csomagküldő cég adatkezeléseThe controller was fined for sending emails without a proper legal basis and for failing to respond to a data protection complaint. The authority found breaches of GDPR Articles 5 and 13. | HU | NAIH | GDPR | €12,750 | ↗ |
| 29 Apr 2024 | Dane anonimowe (A. Sp. k. z siedzibą w T.)UODO imposed a PLN 238,345 administrative fine on A. Sp. k. for failing to implement appropriate technical and organizational measures proportionate to the risk of data processing, including the use of external storage media. The authority also found a lack of regular testing, measurement, and evaluation of the effectiveness of the security measures in place. | PL | UODO | GDPR | €55,103 | ↗ |
| 30 Apr 2024 | Dane anonimowe (Stowarzyszenie F. z siedzibą w X. przy ul.)UODO imposed an administrative fine on Association F. for failing to notify the supervisory authority of a personal data breach without undue delay, and no later than 72 hours after becoming aware of it. The case concerns the obligation to report data security incidents within the required timeframe. | PL | UODO | GDPR | €212 | ↗ |
| 03 May 2024 | D.D.D.The entity published images of a minor on its Telegram channel without consent, breaching data protection rules. AEPD imposed a fine of EUR 5,000. | ES | AEPD | GDPR | €5,000 | ↗ |
| 06 May 2024 | DQG NORTE A.I.E.DQG NORTE A.I.E. was fined by the AEPD for collecting copies of identity documents and personal data of minors and their guardians without proper data protection information. The authority found breaches of GDPR data minimization and transparency principles. | ES | AEPD | GDPR | €5,000 | ↗ |
| 07 May 2024 | PINKGREEN BARCELONA, S.L.PINKGREEN BARCELONA, S.L. was fined by the AEPD 4,000 EUR for disclosing personal data of individuals in responses to negative Google reviews. The authority found that the processing breached Articles 6 and 9 of the GDPR. | ES | AEPD | GDPR | €4,000 | ↗ |