BULLETIN №083Last updated · 09 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.1%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 19 Jul 2018 | BUTALI S.P.A.BUTALI S.P.A. was fined €16,000 by the Garante for activating a SIM card without providing the required privacy information and obtaining the customer’s specific consent. The authority found this to be a breach of data protection rules. | IT | Garante | GDPR | €16,000 | ↗ |
| 11 Jul 2018 | BUSITALIA VENETO S.p.A.BUSITALIA VENETO S.p.A. was fined by the Garante for unlawful processing of personal data through the installation of a geolocation system on its public transport vehicles. The measure infringed employee privacy and data protection rules. | IT | Garante | GDPR | €10,000 | ↗ |
| 08 May 2013 | Business Services s.r.lBusiness Services s.r.l was fined EUR 6,400 by the Garante. The case concerned the sending of promotional faxes without the required information and without obtaining explicit consent from recipients. | IT | Garante | GDPR | €6,400 | ↗ |
| 01 Jan 2015 | BUSCANDO SUERTE S.L.BUSCANDO SUERTE S.L. was fined by the AEPD €2,300 for sending unsolicited SMS messages. The messages misled recipients into replying and caused charges without any legitimate purpose. | ES | AEPD | ePrivacy | €2,300 | ↗ |
| 09 Jul 2020 | Burgo Group S.p.A.Burgo Group S.p.A. was fined EUR 20,000 by the Garante for violating GDPR principles. The case concerned improper restriction of access to an employee’s corporate email account, which was accessible to other staff members without the employee’s consent. | IT | Garante | GDPR | €20,000 | ↗ |
| 07 May 2015 | Burger Joint/Maria Galioni I.K.E.The company was fined for unlawfully operating a video surveillance system in the workplace. The authority found a privacy violation because employees and customers were monitored without proper justification. | GR | HDPA | GDPR | €3,000 | ↗ |
| 06 Jul 2020 | Bureau Krediet Registratie (BKR)Bureau Krediet Registratie (BKR) was fined EUR 830,000 by the AP for not providing free electronic access to personal data. The authority found this practice breached the GDPR right of access. | NL | AP | GDPR | €830,000 | ↗ |
| 19 Oct 2010 | BUONGIORNO MARKETING SERVICES ESPAÑA S.L.U.BUONGIORNO MARKETING SERVICES ESPAÑA S.L.U. was fined by the AEPD for sending unsolicited commercial SMS messages. The conduct breached Article 21 of the LSSI, which governs marketing communications without prior consent. | ES | AEPD | ePrivacy | €1,200 | ↗ |
| 03 Dec 2021 | Bűnügyi személyes adatok kezelése magánvádló általThe controller unlawfully transferred the complainant's criminal personal data, breaching the principles of lawful and fair processing and purpose limitation. The authority also found no legal basis for processing under the GDPR. | HU | NAIH | GDPR | €825 | ↗ |
| 11 Jan 2024 | Build Lenders S.r.l.Build Lenders S.r.l. was fined EUR 10,000 by the Garante for unlawfully publishing personal data and failing to respond to a data deletion request. The authority found that the company breached GDPR rules on data protection and data subject rights. | IT | Garante | GDPR | €10,000 | ↗ |
| 21 Mar 2024 | Budapesti Rendőr-főkapitányság XI. kerületi RendőrkapitányságBudapesti Rendőr-főkapitányság XI. kerületi Rendőrkapitányság was fined by NAIH 300,000 HUF for violations related to the closed handling of personal data. The authority found breaches of several provisions of the Hungarian Information Act (Infotv.). | HU | NAIH | GDPR | €762 | ↗ |
| 25 Jun 2019 | Budapesti Rendőr-főkapitányságBudapesti Rendőr-főkapitányság was fined by NAIH 5,000,000 HUF for failing to report a personal data breach within the 72-hour deadline. The incident involved the loss of a pendrive containing personal data, in breach of GDPR Article 33. | HU | NAIH | GDPR | €15,400 | ↗ |
| 10 Dec 2020 | Budapesti Műszaki és Gazdaságtudományi EgyetemThe university processed personal data during the submission and evaluation of social scholarship applications without a valid legal basis. This also included special category data processed without appropriate GDPR grounds. | HU | NAIH | GDPR | €22,480 | ↗ |
| 05 Apr 2019 | Budapesti Műszaki és Gazdaságtudományi EgyetemBudapest University of Technology and Economics was fined 600,000 HUF by NAIH. The authority found that the university failed to comply with a data subject's request for access to personal data. | HU | NAIH | GDPR | €1,872 | ↗ |
| 25 Apr 2022 | Budapest Főváros XVIII. kerület Pestszentlőrinc - Pestszentimre ÖnkormányzataThe authority fined the municipality for failing to provide adequate information to data subjects about the collection and use of their personal data. It also found processing of personal and health data without a valid legal basis or proper consent. | HU | NAIH | GDPR | €8,010 | ↗ |
| 24 Mar 2021 | Budapest Főváros Kormányhivatala XI. kerületi HivatalaBudapest Főváros Kormányhivatala XI. kerületi Hivatala failed to implement adequate security measures for health data related to Covid-19 tests. The office also did not report a high-risk personal data breach to NAIH or notify the affected individuals. | HU | NAIH | GDPR | €27,400 | ↗ |
| 08 Feb 2022 | Budapest Bank Zrt.Budapest Bank Zrt. was fined by NAIH for improper personal data processing related to the analysis of recorded phone conversations. The authority found violations of several GDPR provisions. | HU | NAIH | GDPR | €707,000 | ↗ |
| 21 Mar 2025 | Bucharest Down Town Hotel SRLThe National Supervisory Authority for Personal Data Processing fined Bucharest Down Town Hotel SRL for GDPR violations following a complaint. The case concerned non-compliant processing of personal data. | RO | ANSPDCP | GDPR | €1,000 | ↗ |
| 05 Jun 2020 | BUBO MEDIA, S.L.BUBO MEDIA, S.L. was fined by the AEPD in the amount of 1,500 EUR for sending unsolicited SMS messages to individuals without their consent. The conduct breached data protection and electronic communications rules. | ES | AEPD | ePrivacy | €1,500 | ↗ |
| 06 Sept 2012 | BT Italia s.p.a.BT Italia s.p.a. was fined by the Garante EUR 75,000 for sending unsolicited promotional faxes without recipient consent. The conduct breached data protection and direct marketing rules. | IT | Garante | GDPR | €75,000 | ↗ |