BULLETIN №083Last updated · 11 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.1%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 06 Sept 2024 | GESTIÓN DE VENTAS IBERIA S.L.GESTIÓN DE VENTAS IBERIA S.L. was fined 4,000 EUR by the AEPD for failing to provide access as required under Article 58.1 of the GDPR. The case concerns non-compliance with a supervisory authority request. | ES | AEPD | GDPR | €4,000 | ↗ |
| 10 Sept 2024 | Fundația Pro Economica – Pro Economica AlapítványThe foundation was fined EUR 1,000 by ANSPDCP after a data security incident caused by a cyberattack. The attack led to the deletion of personal data from its server, affecting data availability. | RO | ANSPDCP | GDPR | €1,000 | ↗ |
| 10 Sept 2024 | Okmánymásolat feltöltését is előíró regisztrációs folyamattal és regisztrációs adatbázissal kapcsolatos jogellenes adatkezelésThe authority imposed a fine for negligent GDPR violations between December 2021 and November 2023. The breaches concerned transparency and data processing principles in connection with the registration process and the registration database. | HU | NAIH | GDPR | €189,000 | ↗ |
| 10 Sept 2024 | HWM PSI, S.L.HWM PSI, S.L. was fined by the AEPD 100 EUR for sending an email to multiple recipients without using BCC. This exposed recipients’ personal email addresses and breached data protection rules. | ES | AEPD | GDPR | €100 | ↗ |
| 11 Sept 2024 | KVIKU SPAIN, S.L.KVIKU SPAIN, S.L. was fined by the AEPD for failing to provide access to personal data and information requested by the data protection authority. The case concerned non-compliance with Article 58.1 of the GDPR. | ES | AEPD | GDPR | €1,200 | ↗ |
| 11 Sept 2024 | NEGOCIOS R&R 2020 S.L.NEGOCIOS R&R 2020 S.L. was fined by the AEPD 12,000 EUR for failing to provide access under Article 58(1) of the GDPR. The authority treated this as a serious breach of data protection obligations. | ES | AEPD | GDPR | €12,000 | ↗ |
| 11 Sept 2024 | Universitetet i AgderThe Norwegian DPA, Datatilsynet, fined the University of Agder 150,000 NOK for failing to implement adequate measures to protect personal data in Microsoft Teams. The incident exposed sensitive information relating to around 16,000 individuals. | NO | Datatilsynet | GDPR | €12,566 | ↗ |
| 12 Sept 2024 | Medic4All Italia S.r.l.Medic4All Italia S.r.l. was fined by the Garante 15,000 EUR for failing to respond to a data subject access request. The conduct breached Article 15 GDPR, which requires controllers to provide access to personal data upon request. | IT | Garante | GDPR | €15,000 | ↗ |
| 12 Sept 2024 | Top Quality Corporation S.r.l.s.Top Quality Corporation S.r.l.s. was fined by the Garante 5,000 EUR for failing to respond to a data subject’s request to access personal data related to employment. The authority found a breach of GDPR Articles 12 and 15. | IT | Garante | GDPR | €5,000 | ↗ |
| 12 Sept 2024 | Ordine delle Professioni Infermieristiche di UdineOrdine delle Professioni Infermieristiche di Udine was fined 8,000 EUR by the Garante for breaches of data protection rules. The authority found improper disclosure of data to third parties and a failure to provide proper information to data subjects. | IT | Garante | GDPR | €8,000 | ↗ |
| 12 Sept 2024 | SOCIETE EXPLOITANT UN CASINO ET UN HOTEL (procédure simplifiée)The CNIL imposed an administrative fine of EUR 12,000 on SOCIETE EXPLOITANT UN CASINO ET UN HOTEL under a simplified procedure. The case concerns a confirmed breach of rules supervised by the CNIL. | FR | CNIL | GDPR | €12,000 | ↗ |
| 12 Sept 2024 | Ordine delle Professioni Infermieristiche di GoriziaThe Garante imposed a fine of EUR 5,000 on the Ordine delle Professioni Infermieristiche di Gorizia for breaches of data protection rules. The case concerned non-compliance with requirements governing the processing of personal data. | IT | Garante | GDPR | €5,000 | ↗ |
| 12 Sept 2024 | Provvedimento del 12 settembre 2024 [10065894]The Garante imposed a EUR 400 fine for the improper installation of surveillance cameras oriented toward private residences. The conduct breached privacy and personal data protection rules. | IT | Garante | GDPR | €400 | ↗ |
| 12 Sept 2024 | Ordine delle Professioni Infermieristiche di TriesteThe Garante fined the Ordine delle Professioni Infermieristiche di Trieste EUR 4,000 for breaches of data protection rules. The case involved improper disclosure of data to third parties and a failure to provide adequate information to data subjects. | IT | Garante | GDPR | €4,000 | ↗ |
| 12 Sept 2024 | B.B.B.B.B.B. was fined by the AEPD €4,000 for failing to properly inform individuals about the presence of surveillance cameras. The authority also found the surveillance system disproportionate because it recorded audio and retained images longer than permitted. | ES | AEPD | GDPR | €4,000 | ↗ |
| 12 Sept 2024 | Ordine delle Professioni Infermieristiche di PordenoneOrdine delle Professioni Infermieristiche di Pordenone was fined 6,000 EUR by the Garante for breaching data protection rules. The authority found that the organization mishandled a data subject request and failed to respect privacy rights. | IT | Garante | GDPR | €6,000 | ↗ |
| 12 Sept 2024 | Sky Italia S.r.l.Sky Italia S.r.l. was fined EUR 842,062 by the Garante for telemarketing violations. The authority found that the company contacted individuals without proper consent and failed to consult the Public Register of Objections before promotional campaigns. | IT | Garante | GDPR | €842,000 | ↗ |
| 13 Sept 2024 | DIGITAL PHOTO IMAGE, S.A.DIGITAL PHOTO IMAGE, S.A. was fined EUR 20,000 by the AEPD for breaching the LSSI. The company sent emails without providing recipients with a valid means to exercise their right to stop receiving such communications. | ES | AEPD | ePrivacy | €20,000 | ↗ |
| 13 Sept 2024 | COMMUNE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 20,000 on COMMUNE (procédure simplifiée) and issued an injunction. The decision concerns a confirmed breach of rules supervised by the CNIL. | FR | CNIL | GDPR | €20,000 | ↗ |
| 13 Sept 2024 | ARES CAPITAL, S.A.ARES CAPITAL, S.A. was fined by the AEPD for requiring employees to use personal phones for work together with continuous monitoring apps. The authority found that the company did not provide sufficient information about data collection, breaching GDPR rules on lawful basis, transparency, and data processing principles. | ES | AEPD | GDPR | €200,000 | ↗ |