BULLETIN №083Last updated · 11 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.1%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 08 Jul 2024 | COMERCIAL GIRONA DE LLIBRES, S.L.COMERCIAL GIRONA DE LLIBRES, S.L. was fined by the AEPD 20,000 EUR for inadequate security measures. The authority cited, among other issues, the sending of credentials by email, which breached Article 32 of the GDPR. | ES | AEPD | GDPR | €20,000 | ↗ |
| 08 Jul 2024 | CALLBELL S.A.S.CALLBELL S.A.S. was fined by the AEPD in the amount of 5,000 EUR for sending unsolicited commercial messages to a complainant despite a request to stop. The authority found this conduct breached Article 21 of the LSSI. | ES | AEPD | ePrivacy | €5,000 | ↗ |
| 10 Jul 2024 | Dane anonimowe (Panią A. Z. prowadzącą działalność gospodarczą pod firmą B. z siedzibą w W przy ul.)The President of UODO imposed an administrative fine on an individual conducting business activity. The sanction resulted from failure to cooperate with the authority and from not providing access to personal data and information necessary for supervisory tasks. | PL | UODO | GDPR | €5,129 | ↗ |
| 11 Jul 2024 | EOS MatrixAZOP imposed a EUR 5.47 million fine on EOS Matrix for a personal data protection breach following an incident involving the data of 181,641 debtors. The case was described as a GDPR violation and the largest fine in the authority's history. | HR | AZOP | GDPR | €5,470,000 | ↗ |
| 12 Jul 2024 | CLIDEA DESARROLLO, S.A.CLIDEA DESARROLLO, S.A. was fined by the AEPD 3,000 EUR for sending an email to 349 recipients without using the BCC field. This exposed the personal email addresses of all recipients. | ES | AEPD | GDPR | €3,000 | ↗ |
| 15 Jul 2024 | ASNEF-EQUIFAX, SERVICIOS DE INFORMACIÓN SOBRE SOLVENCIA Y CRÉDITO, S.L.ASNEF-EQUIFAX was fined by the AEPD 200,000 EUR for failing to properly handle a data subject’s request for deletion and for processing personal data without a legal basis. The case concerns breaches of core data protection obligations. | ES | AEPD | GDPR | €200,000 | ↗ |
| 16 Jul 2024 | A.S. Watson Health & Beauty Continental Europe B.V.A.S. Watson Health & Beauty Continental Europe B.V. was fined 600,000 EUR by the Dutch AP. The authority found that the company processed personal data without a lawful basis because it failed to obtain consent for tracking cookies on kruidvat.nl, breaching GDPR Articles 5 and 6. | NL | AP | GDPR | €600,000 | ↗ |
| 16 Jul 2024 | AS Watson / KruidvatThe Dutch data protection authority, Autoriteit Persoonsgegevens, imposed a fine of EUR 600,000 on AS Watson / Kruidvat. The case concerns a breach of GDPR cookie consent rules. | NL | Autoriteit Persoonsgegevens | GDPR | €600,000 | ↗ |
| 17 Jul 2024 | Iliad Italia S.p.A.Iliad Italia S.p.A. was fined EUR 50,000 by the Garante for sending promotional emails without obtaining proper customer consent. The authority found this conduct to be a breach of GDPR rules on electronic marketing. | IT | Garante | GDPR | €50,000 | ↗ |
| 17 Jul 2024 | IstitutoThe Garante fined Istituto EUR 10,000 for violations related to the processing of personal data in the context of medical and scientific research. The authority found that retention periods were not defined and transparency toward data subjects was insufficient. | IT | Garante | GDPR | €10,000 | ↗ |
| 17 Jul 2024 | Provvedimento del 17 luglio 2024 [10070330]The Garante imposed a fine of EUR 4,000 for violations related to the processing of health data. The case highlights the need to comply with data protection principles when handling special category data. | IT | Garante | GDPR | €4,000 | ↗ |
| 17 Jul 2024 | Azienda ULSS n. 14The Garante fined Azienda ULSS n. 14 EUR 22,000 for failing to implement adequate technical and organizational measures to ensure data security. The deficiencies resulted in a data breach involving sensitive health data. | IT | Garante | GDPR | €22,000 | ↗ |
| 17 Jul 2024 | Selectra S.p.A.Selectra S.p.A. was fined EUR 80,000 by the Garante for unlawfully accessing and retaining a former employee's email account after the end of the collaboration. The authority found that the company's conduct breached data protection rules. | IT | Garante | GDPR | €80,000 | ↗ |
| 17 Jul 2024 | Hera Comm S.p.A.Hera Comm S.p.A. was fined by the Garante 5,000,000 EUR for processing inaccurate and outdated personal data of customers. This led to the activation of unsolicited energy contracts and insurance policies with forged signatures. | IT | Garante | GDPR | €5,000,000 | ↗ |
| 17 Jul 2024 | Mark s.r.l.s.Mark s.r.l.s. was fined by the Garante for operating a video surveillance system without the required signage. The case concerned a breach of GDPR information obligations. | IT | Garante | GDPR | €5,000 | ↗ |
| 18 Jul 2024 | SIA "Doner King"A fine of EUR 500 was imposed on SIA "Doner King" by the DVI. The decision is final and has entered into force. | LV | DVI | GDPR | €500 | ↗ |
| 22 Jul 2024 | COMMUNECNIL imposed EUR 6,900 on COMMUNE as an astreinte liquidation. The case concerns enforcement of a prior obligation subject to supervisory authority action. | FR | CNIL | GDPR | €6,900 | ↗ |
| 23 Jul 2024 | SIA "Piesēst"A fine of EUR 500 was imposed on SIA "Piesēst" by the DVI. The decision is final and has entered into force. | LV | DVI | GDPR | €500 | ↗ |
| 23 Jul 2024 | VOLTIUM CONSULTORES 2020, S.L.VOLTIUM CONSULTORES 2020, S.L. was fined by the AEPD in the amount of EUR 600 for failing to provide access to information under Article 58(1) of the GDPR. The case concerns a breach of cooperation and transparency obligations toward the supervisory authority. | ES | AEPD | GDPR | €600 | ↗ |
| 24 Jul 2024 | MONUMENTAL FORMA SPORT, S.L.MONUMENTAL FORMA SPORT, S.L. was fined EUR 5,000 by the AEPD for sending unsolicited commercial SMS messages without recipient consent. The case concerned Article 21 of the LSSI, which requires prior consent for electronic marketing communications. | ES | AEPD | ePrivacy | €5,000 | ↗ |