BULLETIN №084Last updated · 12 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 19 Nov 2024 | CLUB ESPORTIU VILA OLÍMPICAThe club pressured a parent to obtain consent for collecting images of a minor child. AEPD found this to be a breach of data protection rules. | ES | AEPD | GDPR | €1,000 | ↗ |
| 20 Nov 2024 | Anonymisé (CNPD decision-03-fr-2024)The company was fined for installing surveillance cameras without a legal basis. The authority found breaches of GDPR principles of lawfulness, transparency, and security. | LU | CNPD | GDPR | €14,288 | ↗ |
| 20 Nov 2024 | Raiffeisen Bank S.A.Raiffeisen Bank S.A. was fined EUR 20,000 by ANSPDCP for violations of GDPR provisions. The case concerns non-compliance with personal data protection requirements. | RO | ANSPDCP | GDPR | €20,000 | ↗ |
| 20 Nov 2024 | B.B.B.B.B.B. was fined by the AEPD EUR 300 for sending a marketing email to multiple recipients without using BCC. This exposed recipients’ email addresses to each other and breached data protection principles. | ES | AEPD | GDPR | €300 | ↗ |
| 22 Nov 2024 | CLUB BALONCESTO TELDEClub Baloncesto Telde was fined for publishing images of a minor on social media without obtaining the required consent. The authority found a breach of Article 6(1) of the GDPR. | ES | AEPD | GDPR | €1,000 | ↗ |
| 22 Nov 2024 | MAXPOWER FITNESS NUTRITION, S.L.MAXPOWER FITNESS NUTRITION, S.L. was fined by the AEPD in the amount of 2,000 EUR for deficiencies in its cookie policy. The breach concerned the information and consent requirements under the LSSI. | ES | AEPD | ePrivacy | €2,000 | ↗ |
| 22 Nov 2024 | Maynooth UniversityThe Irish DPC imposed a fine of EUR 40,000 on Maynooth University in inquiry IN-19-9-3. The penalty has been collected. | IE | DPC | GDPR | €40,000 | ↗ |
| 25 Nov 2024 | XFERA CONSUMER FINANCE ESTABLECIMIENTO FINANCIERO DE CRÉDITO, S.A.The AEPD fined XFERA Consumer Finance 5,000 EUR for sending a customer unsolicited advertising SMS messages. The messages were sent after the customer had asked to stop receiving such communications, indicating a breach of marketing communication rules. | ES | AEPD | ePrivacy | €5,000 | ↗ |
| 26 Nov 2024 | ASSOCIATION AYANT POUR ACTIVITE L'ACTION SOCIALE SANS HEBERGEMENT ET LA GESTION D'ETABLISSEMENTS MEDICO-SOCIAUX ET SANITAIRES (procédure simplifiée)CNIL imposed an administrative fine of 10,000 EUR on ASSOCIATION AYANT POUR ACTIVITE L'ACTION SOCIALE SANS HEBERGEMENT ET LA GESTION D'ETABLISSEMENTS MEDICO-SOCIAUX ET SANITAIRES. The case was handled under a simplified procedure. | FR | CNIL | GDPR | €10,000 | ↗ |
| 26 Nov 2024 | AD735 DATA MEDIA ADVERTISING, S.L.AD735 DATA MEDIA ADVERTISING, S.L. was fined by the AEPD EUR 10,000 for sending unsolicited advertising emails. The messages were sent despite the recipient's unsubscribe request and inclusion on the Robinson list, breaching the LSSI. | ES | AEPD | ePrivacy | €10,000 | ↗ |
| 26 Nov 2024 | Dane anonimowe (X. ul.)UODO imposed an administrative fine of PLN 29,684.04 on Dane anonimowe (X. ul.) for breaching Article 33(1) and Article 34(1) and (2) of the GDPR. The authority also ordered the controller to notify the affected data subject about the personal data breach. | PL | UODO | GDPR | €6,886 | ↗ |
| 26 Nov 2024 | SOCIETE DE GESTION D'INSTALLATIONS INFORMATIQUES (procédure simplifiée)CNIL imposed an administrative fine of EUR 15,000 on SOCIETE DE GESTION D'INSTALLATIONS INFORMATIQUES. The case was handled under a simplified procedure. | FR | CNIL | GDPR | €15,000 | ↗ |
| 26 Nov 2024 | NetflixThe Autoriteit Persoonsgegevens fined Netflix 4.75 million euros for privacy and GDPR transparency failures. The 26 November 2024 decision concerned inadequate explanations in Netflix’s privacy notice and insufficiently clear responses to data access requests. | NL | Autoriteit Persoonsgegevens | GDPR | €4,750,000 | ↗ |
| 27 Nov 2024 | Lyngby-Taarbæk KommuneThe Danish DPA reported Lyngby-Taarbæk Municipality to the police for failing to implement adequate security measures. This led to unauthorized access to personal data of about 30,000 citizens, and a fine of 350,000–400,000 DKK was recommended. | DK | Datatilsynet | GDPR | €53,632 | ↗ |
| 27 Nov 2024 | Comune di TorrenovaThe Garante fined Comune di Torrenova 4,000 EUR for breaches of GDPR principles, including lawfulness, fairness, and transparency in data processing. The case indicates failures to meet basic data protection requirements in the public authority's processing activities. | IT | Garante | GDPR | €4,000 | ↗ |
| 27 Nov 2024 | E.ON Energia S.p.A.E.ON Energia S.p.A. was fined EUR 892,738 by the Garante for telemarketing-related violations. The authority cited repeated contact attempts and numerous communications sent without proper consent. | IT | Garante | GDPR | €892,000 | ↗ |
| 27 Nov 2024 | Faro di RomaFaro di Roma was fined 15,000 EUR by the Garante for failing to comply with data protection rules. The case concerned the failure to honor requests for erasure and rectification of personal data linked to a judicial matter. | IT | Garante | GDPR | €15,000 | ↗ |
| 27 Nov 2024 | Istituto Comprensivo Statale "Corso Matteotti" di AlfonsineIstituto Comprensivo Statale “Corso Matteotti” di Alfonsine was fined by the Garante EUR 1,000 for violations related to the processing of personal data. The authority cited non-compliance with the principles of lawfulness, fairness, and transparency. | IT | Garante | GDPR | €1,000 | ↗ |
| 27 Nov 2024 | Engineering Ingegneria Informatica S.p.A.The Garante imposed a fine of EUR 10,000 on Engineering Ingegneria Informatica S.p.A. for a data breach involving the Molise regional health portal. A system vulnerability allowed unauthorized access to personal data. | IT | Garante | GDPR | €10,000 | ↗ |
| 27 Nov 2024 | Comune di Motta Sant'AnastasiaThe Garante imposed a EUR 10,000 fine on Comune di Motta Sant'Anastasia for breaches of GDPR Articles 5 and 6 and Article 2-ter of the Italian Privacy Code. The case concerned improper processing of personal data. | IT | Garante | GDPR | €10,000 | ↗ |