BULLETIN №083Last updated · 11 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.1%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 23 Oct 2024 | SNOW INK SIERRA NEVADA, S.L.SNOW INK SIERRA NEVADA, S.L. was fined by the AEPD 4,000 EUR for using surveillance cameras that captured public areas, which breached data protection principles. Privacy masks were implemented during the sanctioning process. | ES | AEPD | GDPR | €4,000 | ↗ |
| 23 Oct 2024 | ASSOCIATION PARTICIPANT AUX ACTIVITES DES ORGANISATIONS POLITIQUES (procédure simplifiée)CNIL imposed a EUR 4,000 penalty on ASSOCIATION PARTICIPANT AUX ACTIVITES DES ORGANISATIONS POLITIQUES under a simplified procedure. The case concerns liquidation of an astreinte, indicating that a prior obligation was not fulfilled on time. | FR | CNIL | GDPR | €4,000 | ↗ |
| 23 Oct 2024 | Profi Rom Food SrlProfi Rom Food Srl was fined EUR 10,000 by ANSPDCP for violating GDPR provisions. The case concerns non-compliance with personal data protection requirements. | RO | ANSPDCP | GDPR | €10,000 | ↗ |
| 25 Oct 2024 | IA BILET SRLThe operator was fined EUR 1,000 by ANSPDCP for violating GDPR provisions. The case concerns non-compliant processing of personal data. | RO | ANSPDCP | GDPR | €1,000 | ↗ |
| 25 Oct 2024 | IA BILET SRLThe operator was fined EUR 1,000 by ANSPDCP for violating GDPR provisions. The case concerns non-compliance with personal data protection requirements. | RO | ANSPDCP | GDPR | €1,000 | ↗ |
| 28 Oct 2024 | Vodafone România S.A.Vodafone România S.A. was fined by ANSPDCP EUR 5,000 for the unauthorized disclosure of email addresses. The breach resulted from failing to use the “BCC” option, which exposed recipients’ data and violated GDPR obligations. | RO | ANSPDCP | GDPR | €5,000 | ↗ |
| 28 Oct 2024 | HSSERVICE LIZCON SOLUTIONS, S.L.HSSERVICE LIZCON SOLUTIONS, S.L. was fined by the AEPD for failing to comply with data protection rules. The authority cited non-compliance with measures required under Article 58(2) GDPR. | ES | AEPD | GDPR | €15,000 | ↗ |
| 29 Oct 2024 | AUTOMOCIÓN 1972, S.L.AUTOMOCIÓN 1972, S.L. was fined by the AEPD in the amount of 2,000 EUR for failing to comply with a data access request. The authority found a breach of GDPR obligations. | ES | AEPD | GDPR | €2,000 | ↗ |
| 29 Oct 2024 | TELEFÓNICA MÓVILES ESPAÑA, S.A.TELEFÓNICA MÓVILES ESPAÑA, S.A. was fined by the AEPD for allowing a SIM card to be duplicated without the customer's consent. The incident led to fraudulent activity on the customer's bank account, indicating serious weaknesses in identity verification and security controls. | ES | AEPD | GDPR | €200,000 | ↗ |
| 29 Oct 2024 | Grue kommuneGrue kommune was fined 250,000 NOK by Datatilsynet after personal data was made accessible in its public journal. The authority found breaches of confidentiality requirements and GDPR rules on legal basis and security. | NO | Datatilsynet | GDPR | €21,113 | ↗ |
| 30 Oct 2024 | Untold SRLIn September 2024, ANSPDCP completed an investigation at Untold SRL and found violations of GDPR provisions. As a result, the company was fined EUR 10,000. | RO | ANSPDCP | GDPR | €10,000 | ↗ |
| 30 Oct 2024 | Untold SRLUntold SRL was fined EUR 5,000 by ANSPDCP for violations of GDPR provisions. The case concerned non-compliance with personal data protection requirements. | RO | ANSPDCP | GDPR | €5,000 | ↗ |
| 30 Oct 2024 | COLEGIO NOTARIAL DE ARAGÓNCOLEGIO NOTARIAL DE ARAGÓN was fined by the AEPD for implementing a fingerprint-based time control system without carrying out a data protection impact assessment. The authority found breaches of GDPR Articles 9 and 35. | ES | AEPD | GDPR | €10,000 | ↗ |
| 01 Nov 2024 | SIA "North Technology Group"A monetary penalty of 500 EUR was imposed on SIA "North Technology Group" by the DVI. The decision entered into force on 1 November 2024. | LV | DVI | GDPR | €500 | ↗ |
| 02 Nov 2024 | Intesa SanpaoloThe Italian Data Protection Authority fined Intesa Sanpaolo €31.8 million for a data breach involving unauthorized access to banking information of more than 3,500 clients. The authority also found that the bank detected the activity late and filed an incomplete and delayed breach notification. | IT | Garante per la protezione dei dati personali | GDPR | €31,800 | ↗ |
| 04 Nov 2024 | Blackcab Systems SRLANSPDCP completed an investigation at Blackcab Systems SRL in October 2024 and found a breach of GDPR provisions. As a result, a fine of EUR 1,000 was imposed. | RO | ANSPDCP | GDPR | €1,000 | ↗ |
| 08 Nov 2024 | AECORP 005, S.L.AECORP 005, S.L. was fined EUR 6,000 by the AEPD for failing to provide access to information requested during an investigation. The authority found a breach of Article 58.1 GDPR. | ES | AEPD | GDPR | €6,000 | ↗ |
| 08 Nov 2024 | PPC Energie Muntenia S.AThe National Supervisory Authority for Personal Data Processing completed an investigation at PPC Energie Muntenia S.A and found a violation of GDPR provisions. As a result, a fine of EUR 1,000 was imposed. | RO | ANSPDCP | GDPR | €1,000 | ↗ |
| 12 Nov 2024 | Dane anonimowe (A. z siedzibą w W. przy ul.)The Polish DPA (UODO) imposed administrative fines on the controller and the processor for breaches of GDPR obligations. The case concerned, among others, integrity and confidentiality, accountability, data protection by design, processor arrangements, and security measures. | PL | UODO | GDPR | €351,000 | ↗ |
| 12 Nov 2024 | Dane anonimowe (X. w Y.)UODO imposed an administrative fine of PLN 24,555 on Anonymous entity (X. in Y.) for breaches of Articles 24(1), 25(1), and 32(1)-(2) of the GDPR. The authority also ordered the processing operations to be brought into compliance with Regulation (EU) 2016/679. | PL | UODO | GDPR | €5,644 | ↗ |