BULLETIN №083Last updated · 11 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.1%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 08 May 2024 | CENTRUL MEDICAL UNIREA SRLCENTRUL MEDICAL UNIREA SRL was fined EUR 5,000 by ANSPDCP for unauthorized disclosure of personal data on the internet. The case indicates a breach of data protection rules and warrants review of security controls and publication procedures. | RO | ANSPDCP | GDPR | €5,000 | ↗ |
| 08 May 2024 | CREMA GAMES, S.L.CREMA GAMES, S.L. was fined EUR 5,000 by the AEPD for breaching Article 15 of the GDPR. The company obstructed the complainant’s exercise of the right of access to their personal data. | ES | AEPD | GDPR | €5,000 | ↗ |
| 08 May 2024 | Genpact România SRLThe ANSPDCP imposed a fine of EUR 3,000 on Genpact România SRL. The sanction concerned sending a file containing recruitment data to an unauthorized employee email address. The incident indicates a failure to control access to personal data and maintain confidentiality. | RO | ANSPDCP | GDPR | €3,000 | ↗ |
| 08 May 2024 | DIMAGAZA, S.L.DIMAGAZA, S.L. was fined by the AEPD 1,000 EUR for posting personal data of employees affected by a collective dismissal on a notice board accessible to outsiders. The authority found a breach of the principles of integrity and confidentiality. | ES | AEPD | GDPR | €1,000 | ↗ |
| 08 May 2024 | KVIKU SPAIN, S.L.KVIKU SPAIN, S.L. was fined EUR 600 by the AEPD for failing to provide access to personal data and related information. The authority found a breach of Article 58(1) of the GDPR. | ES | AEPD | GDPR | €600 | ↗ |
| 09 May 2024 | Azzurro Club Hotels S.r.l.Azzurro Club Hotels S.r.l. was fined by the Garante 10,000 EUR for sending promotional emails without consent. The company also failed to respond to a data subject’s request for information under Article 15 GDPR. | IT | Garante | GDPR | €10,000 | ↗ |
| 09 May 2024 | Ordine dei Tecnici Sanitari di Radiologia Medica e delle Professioni Sanitarie Tecniche, della Riabilitazione e della Prevenzione della provincia di MantovaThe Garante imposed a 3,000 EUR fine on the Ordine dei Tecnici Sanitari di Radiologia Medica e delle Professioni Sanitarie Tecniche, della Riabilitazione e della Prevenzione della provincia di Mantova for breaches of data protection principles. The authority found non-compliance with lawfulness, fairness, transparency, and data minimization. The infringement affected a significant number of data subjects. | IT | Garante | GDPR | €3,000 | ↗ |
| 09 May 2024 | Polisportiva Mimmo Ferrito s.r.l.The Garante fined Polisportiva Mimmo Ferrito s.r.l. EUR 3,000 for failing to respond to a data subject's request to exercise their rights. The case concerns non-compliance with data protection obligations. | IT | Garante | GDPR | €3,000 | ↗ |
| 09 May 2024 | HEADBLUE MARKETING, S.L.HEADBLUE MARKETING, S.L. was fined by the AEPD in the amount of 1,000 EUR for sending unsolicited commercial electronic communications without consent. The authority also found a failure to respond to access requests. | ES | AEPD | ePrivacy | €1,000 | ↗ |
| 09 May 2024 | MEDICOVER SRLMEDICOVER SRL was fined EUR 1,000 by ANSPDCP for the unauthorized disclosure of personal data from a medical consultation report to an unintended patient. The case concerns a breach of confidentiality involving special-category data and indicates a need to strengthen access controls and recipient verification procedures. | RO | ANSPDCP | GDPR | €1,000 | ↗ |
| 09 May 2024 | Provvedimento del 9 maggio 2024 [10027595]The authority imposed a fine on an anonymized healthcare entity for unauthorized access to patient health records by personnel without proper authorization. The case concerned GDPR requirements on data protection and processing security. | IT | Garante | GDPR | €25,000 | ↗ |
| 09 May 2024 | Unicredit S.p.a.Unicredit S.p.a. was fined EUR 30,000 by the Garante for failing to respond to a personal data access request submitted by an heir. The authority found a breach of GDPR Article 15 and the Italian privacy code. | IT | Garante | GDPR | €30,000 | ↗ |
| 09 May 2024 | Vodafone Italia S.p.A.Vodafone Italia S.p.A. was fined EUR 500,000 by the Garante for violations related to telemarketing and teleselling. The authority found that individuals listed in the opposition register were contacted without proper consent. | IT | Garante | GDPR | €500,000 | ↗ |
| 09 May 2024 | IRIDEX GROUP SALUBRIZARE SRLIRIDEX GROUP SALUBRIZARE SRL was fined by ANSPDCP 2,000 EUR for sending a collective email to clients with recipients' email addresses visible. The incident resulted in unauthorized disclosure of personal data. | RO | ANSPDCP | GDPR | €2,000 | ↗ |
| 09 May 2024 | Caffetteria 77 di Dughetti BarbaraThe Garante fined Caffetteria 77 di Dughetti Barbara EUR 3,000 for operating a video surveillance system without meeting the legal requirements. The system captured both customers and employees, creating a data protection compliance breach. | IT | Garante | GDPR | €3,000 | ↗ |
| 10 May 2024 | EUSKALTEL, S.A.EUSKALTEL, S.A. was fined 400,000 EUR by the AEPD for failing to comply with a resolution requiring access to geolocation data. The authority found a breach of Article 58.2 of the GDPR. | ES | AEPD | GDPR | €400,000 | ↗ |
| 13 May 2024 | INDEPENDENTS DE VALLROMANESThe political party Independents de Vallromanes was fined by the AEPD €2,000. The case concerned posting images of a court judgment on social media that included the complainant’s first and last name. | ES | AEPD | GDPR | €2,000 | ↗ |
| 16 May 2024 | EDITAURI S.L.EDITAURI S.L. was fined by the AEPD EUR 600 for not having a privacy policy on its online store. The authority found a breach of Article 13 GDPR because users were not provided with the required information about data processing. | ES | AEPD | GDPR | €600 | ↗ |
| 16 May 2024 | Fiziska personaA fine of EUR 100 was imposed by DVI. The decision became effective on 2024-05-16. | LV | DVI | GDPR | €100 | ↗ |
| 17 May 2024 | Nem közszereplő személyes és különleges adatainak online sajtótermékben történő nyilvánosságra hozatalaThe controller published personal data in an online news outlet without a valid legal basis. It also failed to delete unlawfully processed personal data, resulting in breaches of several GDPR provisions. | HU | NAIH | GDPR | €25,800 | ↗ |