BULLETIN №083Last updated · 09 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.1%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 19 Jul 2012 | Biodiversity S.p.A.Biodiversity S.p.A. was fined by the Garante for failing to timely notify personal data processing activities related to molecular diagnostics. The obligation arose under the Italian Privacy Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 16 Feb 2011 | Bioacqua s.r.l.Bioacqua s.r.l. was fined EUR 9,000 by the Garante for using phone numbers for commercial communications without explicit consent and without providing the required information notice. The conduct breached Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €9,000 | ↗ |
| 02 Apr 2025 | BINBOX GLOBAL SERVICES S.R.L.In March 2025, Romania’s data protection authority ANSPDCP completed an investigation into BINBOX GLOBAL SERVICES S.R.L. The authority found a GDPR violation and imposed a fine of EUR 3,000. | RO | ANSPDCP | GDPR | €3,000 | ↗ |
| 01 Dec 2017 | BILUA E-COMMERCE S.L (CARETHY y BIUKY)BILUA E-COMMERCE S.L. was fined by the AEPD EUR 7,000 for sending unsolicited commercial emails. The messages were sent despite the recipient's request to unsubscribe, which breached Article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €7,000 | ↗ |
| 04 Apr 2019 | Bill Size s.r.l.Bill Size s.r.l. was fined by the Garante in the amount of EUR 16,000 for registering phone cards to individuals without their consent. The authority found this to be a breach of data protection rules. | IT | Garante | GDPR | €16,000 | ↗ |
| 05 Jul 2023 | BILBAO AD INFINITUM, S.L.BILBAO AD INFINITUM, S.L. was fined by the AEPD EUR 500 for installing surveillance cameras directed at a public square without prior administrative authorization. The authority found that this conduct breached GDPR requirements on lawful processing. | ES | AEPD | GDPR | €500 | ↗ |
| 23 Jul 2015 | Bike Service s.n.c.Bike Service s.n.c. was fined by the Garante 2,400 EUR for failing to inform data subjects about the processing of personal data through a video surveillance system. The breach concerned the absence of required notices for individuals subject to the monitoring. | IT | Garante | GDPR | €2,400 | ↗ |
| 20 Jan 2021 | BICLAMEDIA, S.L.BICLAMEDIA, S.L. was fined 1,500 EUR by the AEPD for sending commercial emails without the recipient’s consent. The conduct breached Article 21 of the LSSI governing electronic marketing communications. | ES | AEPD | ePrivacy | €1,500 | ↗ |
| 11 May 2017 | Bianalisi s.p.a.Bianalisi s.p.a. was fined by the Italian data protection authority, Garante, for failing to update its notification concerning the processing of genetic data. The obligation arose under the Italian Privacy Code and was intended to ensure proper disclosure of sensitive data processing. | IT | Garante | GDPR | €20,000 | ↗ |
| 16 Sept 2025 | Bharat Singh ChandBharat Singh Chand, a self-employed lead generator, sent or instigated the sending of 966,449 direct marketing SMS messages between 3 December 2023 and 3 July 2024. The activity breached regulations 22 and 23 of PECR and generated 19,138 complaints to the 7726 spam reporting service. He was fined £200,000 and issued with an enforcement notice. | GB | ICO | ePrivacy | €231,000 | ↗ |
| 12 Dec 2023 | B*** GmbHB*** GmbH was fined by the DSB EUR 5,900 for failing to timely report a data breach to the supervisory authority and for not providing sufficient information required under GDPR. The company also did not cooperate with the authority’s further requests for information. | AT | DSB | GDPR | €5,900 | ↗ |
| 07 Oct 2024 | B*** GmbHB*** GmbH was fined EUR 600 by the Austrian Data Protection Authority (DSB). The penalty concerned a failure to cooperate in a data breach procedure, which breached Article 31 GDPR. | AT | DSB | GDPR | €600 | ↗ |
| 20 Oct 2011 | Betfair Italia srlBetfair Italia srl was fined EUR 40,000 by the Garante for violations related to the omission of information on how data subjects can exercise their rights, as well as other data protection obligations. The case concerned incomplete compliance with information requirements toward users. | IT | Garante | GDPR | €40,000 | ↗ |
| 06 Aug 2024 | BEST ELAN ONLINE SRLBEST ELAN ONLINE SRL was fined €1,000 for GDPR violations. The company was also required to provide the ANSPDCP with all requested information and documents. | RO | ANSPDCP | GDPR | €1,000 | ↗ |
| 19 Jan 2017 | Bertolotto Michele e Azienda Universitaria Ospedaliera Ospedali Riuniti di TriesteThe Garante imposed a 10,000 EUR fine on Bertolotto Michele and Azienda Universitaria Ospedaliera Ospedali Riuniti di Trieste. The case concerned unauthorized access by two doctors to personal health data, including Bertolotto’s data. | IT | Garante | GDPR | €10,000 | ↗ |
| 23 May 2019 | Bérleti jogviszony során keletkezett dokumentumok másolatban történő kiadásaThe controller did not comply with the data subject's access request for personal data beyond the 2012 lease agreement. The authority treated this as a breach of access-right obligations and imposed a fine. | HU | NAIH | GDPR | €918 | ↗ |
| 15 Dec 2022 | BENOTAC, S.L.BENOTAC, S.L. was fined by the AEPD EUR 2,500 for operating a video surveillance system without proper signage and for capturing public areas without authorization. The authority also noted the sharing of recordings without the consent of the data subjects. | ES | AEPD | GDPR | €2,500 | ↗ |
| 27 Apr 2023 | Benetton Group S.r.l.Benetton Group S.r.l. was fined €240,000 by the Italian data protection authority, Garante. The authority found violations in the processing of personal data for marketing and profiling purposes, including the retention of former customers’ data for more than 10 years without proper justification. | IT | Garante | GDPR | €240,000 | ↗ |
| 02 Dec 2025 | Bende IstvánBende István and Berencsi Béla Miklós were fined for processing personal data without a legal basis and for failing to provide required information. The authority found breaches of GDPR principles of fair processing, purpose limitation, and transparency. | HU | NAIH | GDPR | €1,315 | ↗ |
| 17 Mar 2016 | Belzirossi s.r.l.Belzirossi s.r.l. was fined by the Italian Garante in the amount of EUR 2,400. The case concerned the use of a video surveillance system without providing data subjects with the required information under data protection rules. | IT | Garante | GDPR | €2,400 | ↗ |