BULLETIN №083Last updated · 09 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.1%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 22 Feb 2024 | BLU MANAGEMENT SPAIN, S.L.BLU MANAGEMENT SPAIN, S.L. was fined €2,000 by the AEPD for sharing a job applicant’s contact details without consent. The authority treated this as a breach of data protection rules. | ES | AEPD | GDPR | €2,000 | ↗ |
| 22 Feb 2024 | Blue Work s.r.l.Blue Work s.r.l. was fined EUR 6,000 by the Garante for unlawful processing of biometric data using facial recognition for employee attendance tracking. The authority found that the same purpose could have been achieved through less intrusive means. | IT | Garante | GDPR | €6,000 | ↗ |
| 20 Feb 2025 | BLUE TEAM FLIGHT SCHOOL, S.L.BLUE TEAM FLIGHT SCHOOL, S.L. was fined 6,000 EUR by the AEPD. The authority found that the company failed to provide access to personal data and information requested by the data protection authority, in breach of Article 58.1 of the GDPR. | ES | AEPD | GDPR | €6,000 | ↗ |
| 03 Apr 2026 | BLUE PROJECTS S.R.L.In March 2026, the Romanian supervisory authority ANSPDCP completed an investigation into BLUE PROJECTS S.R.L. and found a GDPR violation. The company was fined EUR 2,500. | RO | ANSPDCP | GDPR | €2,500 | ↗ |
| 30 Apr 2026 | BLUE PROJECTS INDUSTRIES S.R.L.ANSPDCP completed an investigation in April 2026 into BLUE PROJECTS INDUSTRIES S.R.L. and found a GDPR violation. A fine of EUR 2,500 was imposed. | RO | ANSPDCP | GDPR | €2,500 | ↗ |
| 18 Sept 2014 | Blue Dream Hotel s.r.l.Blue Dream Hotel s.r.l. was fined EUR 2,400 by the Garante for processing personal data related to job applications without providing the required privacy notice. The authority found a breach of Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 13 Jan 2025 | BLEISOR SOLUTIONS, S.A.S.BLEISOR SOLUTIONS, S.A.S. was fined 600 EUR by the AEPD. The authority found that the company failed to provide access to personal data and information requested by the supervisory authority, in breach of Article 58(1) GDPR. | ES | AEPD | GDPR | €600 | ↗ |
| 04 Nov 2024 | Blackcab Systems SRLANSPDCP completed an investigation at Blackcab Systems SRL in October 2024 and found a breach of GDPR provisions. As a result, a fine of EUR 1,000 was imposed. | RO | ANSPDCP | GDPR | €1,000 | ↗ |
| 23 Jun 2023 | BKM Budapesti Közművek Nonprofit Zrt.NAIH imposed a 16,000,000 HUF fine on BKM Budapesti Közművek Nonprofit Zrt. for failing to implement adequate technical and organizational measures to protect data security. The authority also found deficiencies in the reporting of a personal data breach. | HU | NAIH | GDPR | €43,200 | ↗ |
| 23 Dec 2010 | Bitmovers s.r.l.Bitmovers s.r.l. was fined by the Garante 6,000 EUR for collecting personal data through its website without the required information notice. The case concerned a breach of the Italian Data Protection Code. | IT | Garante | GDPR | €6,000 | ↗ |
| 22 Sept 2022 | Bitfactor SRLBitfactor SRL was fined EUR 2,000 by ANSPDCP after a data security incident caused by a malfunctioning application. The application sent marketing communications, resulting in a breach of personal data confidentiality affecting 1,757 users. | RO | ANSPDCP | GDPR | €2,000 | ↗ |
| 30 Apr 2025 | BITDEFENDER SRLIn April 2025, the Romanian authority ANSPDCP completed an investigation into BITDEFENDER SRL and found a GDPR violation. The company was fined EUR 10,000. | RO | ANSPDCP | GDPR | €10,000 | ↗ |
| 01 Apr 2025 | BitdefenderBitdefender received a GDPR fine of EUR 10,000 from the Romanian data protection authority. The sanction followed an investigation completed in April 2025 after a data breach notification, with the authority citing inadequate technical and organizational security measures. | RO | Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal | — | €10,000 | ↗ |
| 01 Feb 2026 | Biržų ligoninėVDAI imposed a EUR 6,000 fine on Biržų ligoninė for improper processing of personal data. The case concerns a breach of data protection requirements and indicates non-compliance with GDPR obligations. | LT | VDAI | GDPR | €6,000 | ↗ |
| 24 Jun 2025 | BirthlinkThe UK Information Commissioner’s Office (ICO) fined Scottish charity Birthlink GBP 18,000. The case involved the destruction of about 4,800 personal records, up to 10% of which may have been irreplaceable. | GB | ICO | GDPR | €21,109 | ↗ |
| 08 Oct 2015 | Birrificio Torino srlBirrificio Torino srl was fined EUR 2,400 by the Garante for providing inadequate information in the data collection form on its website. The authority found a breach of Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 10 Apr 2023 | BIROU GAS, S.L.BIROU GAS, S.L. was fined EUR 60,000 by the AEPD for breaching Article 58(1) of the GDPR. The company did not respond to information requests from the supervisory authority. | ES | AEPD | GDPR | €60,000 | ↗ |
| 17 Jul 2019 | Bírák érdek-képviseleti egyesületi tagságra vonatkozó adatának jogellenes kezeléseBudapest Környéki Törvényszék unlawfully processed personal data by listing and sharing association membership information without a proper purpose or legal basis. The authority found a breach of the GDPR principles of purpose limitation and lawful processing. | HU | NAIH | GDPR | €9,180 | ↗ |
| 09 Dec 2010 | Bios s.p.a.Bios s.p.a. was fined by the Italian Garante for failing to provide adequate and timely information about the processing of personal data through a video surveillance system. The conduct breached Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €6,000 | ↗ |
| 16 Jan 2014 | Bios Marx s.r.l.Bios Marx s.r.l. was fined by the Italian Garante in the amount of EUR 16,000 for providing an inadequate privacy notice during a medical initiative. The authority also found that personal data were shared with third parties without obtaining specific consent. | IT | Garante | GDPR | €16,000 | ↗ |