BULLETIN №083Last updated · 09 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.1%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 24 Sept 2020 | BRONSON BAR, S.L.BRONSON BAR, S.L. was fined 2,000 EUR by the AEPD. The company used the reverse side of a contract to create an inventory, which was then publicly displayed, breaching data integrity and confidentiality principles. | ES | AEPD | GDPR | €2,000 | ↗ |
| 05 Apr 2018 | Broker & Broker s.r.l.Broker & Broker s.r.l. was fined EUR 340,000 by the Italian authority Garante. The case concerned the registration of numerous phone cards to third parties without their knowledge or consent, which breached data protection rules. | IT | Garante | GDPR | €340,000 | ↗ |
| 10 Mar 2022 | Briza Land S.R.L.The National Supervisory Authority completed an investigation on 24.02.2022 at Briza Land S.R.L. and found a violation of GDPR provisions. As a result, a fine of EUR 2,000 was imposed. | RO | ANSPDCP | GDPR | €2,000 | ↗ |
| 12 Jan 2023 | BRISTOL LOGISTICS SABRISTOL LOGISTICS SA was fined EUR 2,000 by ANSPDCP for violating GDPR provisions. The case concerns non-compliant processing of personal data. | RO | ANSPDCP | GDPR | €2,000 | ↗ |
| 13 May 2021 | Brico Rida s.r.l.Brico Rida s.r.l. was fined by the Garante in the amount of 2,000 EUR for operating a video surveillance system without the required information notice to data subjects. The authority found a breach of Article 13 GDPR. | IT | Garante | GDPR | €2,000 | ↗ |
| 12 Feb 2026 | Bressanelli Galli Gelpi Porta & C. S.r.l.The company was fined EUR 15,000 by the Garante for sending promotional emails without prior consent from recipients. The authority found this to be a breach of GDPR principles, including Article 5. | IT | Garante | GDPR | €15,000 | ↗ |
| 12 Dec 2024 | BREOGAN AUTOLUX, S.L.BREOGAN AUTOLUX, S.L. was fined EUR 10,000 by the AEPD for sending unsolicited SMS advertisements without prior consent from recipients. The authority also found that the messages did not provide an opt-out mechanism, in breach of the LSSI. | ES | AEPD | ePrivacy | €10,000 | ↗ |
| 18 May 2017 | Brennercom s.p.a.Brennercom s.p.a. was fined 10,000 EUR by the Garante for inadequate password security measures. The authority found that the company's practices breached data protection rules. | IT | Garante | GDPR | €10,000 | ↗ |
| 17 May 2023 | Breikot Management LtdBreikot Management Ltd was fined EUR 3,000 by the CyDPC for publishing personal data, including names and photos. The authority found a breach of the data minimization principle under the GDPR. | CY | CyDPC | GDPR | €3,000 | ↗ |
| 12 Dec 2024 | Breathe Services LtdBreathe Services Ltd, a debt advice company based in Bolton, was investigated by the ICO following complaints about unsolicited calls to potentially vulnerable individuals. The ICO found that the company spoofed outbound numbers and made 4,376,037 unsolicited direct marketing calls to numbers registered with the Telephone Preference Service, generating multiple complaints. | GB | ICO | GDPR | €206,000 | ↗ |
| 24 Mar 2022 | Brav s.r.l.Brav s.r.l. was fined by the Garante 10,000 EUR for failing to implement adequate technical and organizational security measures. The issue concerned data processing linked to the management of contraventions by the local police of the Municipality of Genoa. | IT | Garante | GDPR | €10,000 | ↗ |
| 11 Jun 2021 | BRAbank ASABRAbank ASA was fined NOK 400,000 by Datatilsynet for failing to perform risk assessments and testing before launching a customer portal. The deficiency led to a data breach in which customers could view other customers’ loan information. | NO | Datatilsynet | GDPR | €39,672 | ↗ |
| 15 Sept 2022 | Bper Banca S.p.A.Bper Banca S.p.A. was fined by the Garante for a delayed and inadequate response to requests for deletion of personal data. The authority found breaches of GDPR Articles 12 and 17. | IT | Garante | GDPR | €10,000 | ↗ |
| 03 Jun 2025 | B*** Parkraumbewirtschaftung Ges.m.b.H.The company was fined by the Austrian Data Protection Authority (DSB) for failing to cooperate during the investigation. It did not respond to multiple requests for statements or to a summons for an oral hearing, which constitutes a breach of Article 31 GDPR. | AT | DSB | GDPR | €16,000 | ↗ |
| 16 Feb 2023 | BOX 24 2050 S.L.BOX 24 2050 S.L. was fined by the AEPD 2,000 EUR for making misleading advertising calls without prior explicit consent. The conduct breached data protection rules and the requirement for lawful processing. | ES | AEPD | GDPR | €2,000 | ↗ |
| 10 Jun 2024 | BOULANGERIE (procédure simplifiée)CNIL imposed an administrative fine of EUR 5,000 on BOULANGERIE under a simplified procedure. The record does not provide further details on the underlying infringement. | FR | CNIL | GDPR | €5,000 | ↗ |
| 15 Jun 2020 | Bostadsrättsförening HalmstadBRF Gårdsbjörken was fined by IMY for unlawful video and audio surveillance in common areas. The authority found breaches of GDPR principles, including data minimization and transparency. | SE | IMY | GDPR | €1,898 | ↗ |
| 16 Jun 2023 | BORSA MEDIC, S.L.BORSA MEDIC, S.L. was fined 10,000 EUR by the AEPD for failing to comply with a data deletion request and for sending unsolicited advertising emails after the recipient objected. The case concerns breaches of data protection and electronic commerce rules. | ES | AEPD | ePrivacy | €10,000 | ↗ |
| 16 Jan 2026 | Born S.r.l.Born S.r.l. was fined by the Garante 15,000 EUR for making unsolicited promotional calls to numbers listed in the Public Register of Oppositions. The conduct breached data protection rules governing telephone marketing and the right to object. | IT | Garante | GDPR | €15,000 | ↗ |
| 04 Dec 2020 | BORJAMOTOR, S.A.BORJAMOTOR, S.A. was fined by the AEPD €8,000 for sending commercial SMS messages without explicit consent from recipients. The authority also identified improper consent practices for personal data processing on the company’s website. | ES | AEPD | ePrivacy | €8,000 | ↗ |