BULLETIN №083Last updated · 11 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.1%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 20 Jun 2024 | Max & Mix Ferrara s.r.l.Max & Mix Ferrara s.r.l. was fined €5,000 by the Garante for operating a video surveillance system with 32 cameras without the required informational signage. The authority found this to be a breach of GDPR information obligations. | IT | Garante | GDPR | €5,000 | ↗ |
| 20 Jun 2024 | TS Food Processing S.r.l.TS Food Processing S.r.l. was fined by the Garante for refusing an employee's request to access personal data related to employment. The authority found a breach of GDPR Article 15. | IT | Garante | GDPR | €10,000 | ↗ |
| 21 Jun 2024 | ADMINISTRACIONES BENIPON, S.L.ADMINISTRACIONES BENIPON, S.L. was fined 2,200 EUR by the AEPD for failing to provide access to information as required under Article 58(1) GDPR. The case concerns non-compliance with the supervisory authority’s information access requirements. | ES | AEPD | GDPR | €2,200 | ↗ |
| 24 Jun 2024 | WWPD CINVENTO INTERNATIONAL PATENT TRADING, S.L.The entity sent postal advertising to an individual without any prior commercial relationship, using data from the Official Industrial Property Bulletin. The authority found this to be a breach of data protection rules. | ES | AEPD | GDPR | €500 | ↗ |
| 25 Jun 2024 | LOS NIÑOS DE MONTESSORI, S.L.The entity was fined for failing to provide information or obtain consent for the use of cookies on its website. This conduct breached the LSSI. | ES | AEPD | ePrivacy | €5,000 | ↗ |
| 25 Jun 2024 | AvanzaAvanza Bank AB was fined by IMY for failing to implement appropriate technical and organizational measures to ensure an adequate level of security for personal data. This resulted in unauthorized transfers of personal data to Meta. | SE | IMY | GDPR | €1,336,000 | ↗ |
| 25 Jun 2024 | COMUNIDAD.1The community of property owners disclosed a resident’s personal data, including their DNI, in meeting minutes. AEPD found this breached confidentiality principles and imposed a 300 EUR fine. | ES | AEPD | GDPR | €300 | ↗ |
| 25 Jun 2024 | RIVENDELL TECHNOLOGY, S.L.RIVENDELL TECHNOLOGY, S.L. failed to properly handle a data subject access request, which constitutes a breach of Article 15 GDPR. The company was fined for not complying with the data protection authority's resolution. | ES | AEPD | GDPR | €900 | ↗ |
| 27 Jun 2024 | METRO AEBEThe supervisory authority found that the company did not properly investigate and notify a personal data breach. It also failed to comply with data subject requests for access and erasure. | GR | HDPA | GDPR | €20,000 | ↗ |
| 27 Jun 2024 | SOCIETE SPECIALISEE EN GESTION IMMOBILIERE ET EN EXPLOITATION COMMERCIALE SOCIETE DIFFUSANT DES CONTENUS JOURNALISTIQUES (procédure simplifiée)The CNIL imposed an administrative fine of EUR 12,000 on SOCIETE SPECIALISEE EN GESTION IMMOBILIERE ET EN EXPLOITATION COMMERCIALE SOCIETE DIFFUSANT DES CONTENUS JOURNALISTIQUES under a simplified procedure. The case concerned a breach of rules supervised by the CNIL. | FR | CNIL | GDPR | €12,000 | ↗ |
| 01 Jul 2024 | Anonymised (IDPC 4794_001)The case concerns a breach of GDPR Articles 21(2) and 5(2) by Anonymised (IDPC 4794_001). The IDPC imposed an administrative fine of EUR 15,000. | MT | IDPC | GDPR | €15,000 | ↗ |
| 02 Jul 2024 | ALDI MAGYARORSZÁG ÉLELMISZER Élelmiszer Kereskedelmi Betéti TársaságALDI Magyarország was fined by the NAIH 80,000,000 HUF for failing to ensure transparency in data processing related to the purchase of alcoholic beverages. The authority found breaches of GDPR transparency and data minimization principles. | HU | NAIH | GDPR | €202,000 | ↗ |
| 02 Jul 2024 | ALDI MAGYARORSZÁG ÉLELMISZER Élelmiszer Kereskedelmi Betéti TársaságNAIH imposed a HUF 95,000,000 fine on ALDI Magyarország for GDPR violations linked to data processing during alcohol purchases. The authority cited improper age verification and insufficient personal data protection measures. | HU | NAIH | GDPR | €240,000 | ↗ |
| 04 Jul 2024 | Provvedimento del 4 luglio 2024 [10068075]The Garante imposed a EUR 400 fine on an individual for improperly installing a surveillance system. The cameras captured public street areas, which breached privacy rules. | IT | Garante | GDPR | €400 | ↗ |
| 04 Jul 2024 | Nomodidattica S.r.l.Nomodidattica S.r.l. was fined EUR 10,000 by the Garante for publishing a court ruling online without anonymizing minors' data. The authority found this breached GDPR data protection principles. | IT | Garante | GDPR | €10,000 | ↗ |
| 04 Jul 2024 | Lapis SasThe Garante fined Lapis Sas EUR 1,500 for incorrectly presenting itself as the data controller. This created public confusion and constituted a prolonged breach of GDPR requirements. | IT | Garante | GDPR | €1,500 | ↗ |
| 04 Jul 2024 | Comune di TrevisoThe Garante fined Comune di Treviso EUR 7,000 for failing to adopt internal measures governing data processing in connection with the TrevisoSicura application. The authority also found that the municipality incorrectly assumed the role of data processor instead of properly defining its data protection responsibilities. | IT | Garante | GDPR | €7,000 | ↗ |
| 04 Jul 2024 | Postel S.p.A.Postel S.p.A. was fined by the Garante EUR 900,000 for a data breach following a ransomware attack. The attack exploited vulnerabilities in the Microsoft Exchange platform, resulting in unauthorized access to data and publication on the dark web. | IT | Garante | GDPR | €900,000 | ↗ |
| 04 Jul 2024 | Comune di VillasimiusComune di Villasimius was fined for failing to respond to a request to remove personal data from its website and for unlawfully publishing personal data. The authority found breaches of lawfulness, fairness, transparency, and data minimization. | IT | Garante | GDPR | €4,000 | ↗ |
| 05 Jul 2024 | PUBLICACIONES Y EDICIONES BARACA 208, S.L.The company published personal data, including health information, in a digital newspaper article. The authority found a breach of data minimisation and the rules on special category data under GDPR Articles 5(1)(c) and 9. | ES | AEPD | GDPR | €10,000 | ↗ |