BULLETIN №084Last updated · 12 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 27 Nov 2024 | Molise dati S.p.A.Molise dati S.p.A. was fined EUR 10,000 by the Garante for a data breach involving the regional health portal. A system vulnerability allowed unauthorized access to personal data of citizens in the Molise Regional Registry. | IT | Garante | GDPR | €10,000 | ↗ |
| 27 Nov 2024 | Maximum International Corp. S.r.l.Maximum International Corp. S.r.l. was fined by the Garante 10,000 EUR for persistent promotional calls despite objections and for failing to respond to data subject requests. The authority found breaches of GDPR rules on consent and information obligations. | IT | Garante | GDPR | €10,000 | ↗ |
| 27 Nov 2024 | Azienda Sanitaria provinciale di EnnaAzienda Sanitaria provinciale di Enna was fined by the Garante 20,000 EUR for publishing employees’ personal data without a legal basis. The disclosure included details on additional payments, sickness absences, and union rights, breaching the GDPR and the national privacy code. | IT | Garante | GDPR | €20,000 | ↗ |
| 28 Nov 2024 | COMUNIDAD DE PROPIETARIOS A.A.A.The community of property owners was fined by the AEPD for publicly displaying personal data, including names and debt information. The authority found a breach of the confidentiality principle under GDPR. | ES | AEPD | GDPR | €1,000 | ↗ |
| 01 Dec 2024 | Orange România SAThe Romanian data protection authority completed an investigation in December 2024 into Orange România SA and found a breach of Article 12(3) GDPR. The case concerned failure to meet the deadline for responding to a data subject access request, resulting in a EUR 40,000 fine. | RO | Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal | GDPR | €40,000 | ↗ |
| 03 Dec 2024 | VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD 20,000 EUR for sending commercial electronic communications to a customer who had opted out. The authority also found that there was no effective mechanism to revoke consent. | ES | AEPD | ePrivacy | €20,000 | ↗ |
| 03 Dec 2024 | BANCO BILBAO VIZCAYA ARGENTARIA, S.A.The AEPD imposed a EUR 200,000 fine on Banco Bilbao Vizcaya Argentaria, S.A. for processing personal data without a legal basis. The conduct included signing documents without consent and marking consent checkboxes for commercial purposes without authorization. | ES | AEPD | GDPR | €200,000 | ↗ |
| 03 Dec 2024 | Fiziska personaA fine of EUR 500 was imposed by the DVI. The decision has entered into force. | LV | DVI | GDPR | €500 | ↗ |
| 05 Dec 2024 | ESL Consultancy Services Ltd Between 15 September 2022 and 5 December 2023, 37,977 complaints were received about direct marketing messages sent at the instigation of ESL Consultancy Services Ltd. The ICO fined the company GBP 200,000 and issued an enforcement notice. | GB | ICO | GDPR | €241,000 | ↗ |
| 05 Dec 2024 | SOCIETE VENDANT DES PRODUITS COSMETIQUES (procédure simplifiée)The CNIL imposed an administrative fine of EUR 3,000 on SOCIETE VENDANT DES PRODUITS COSMETIQUES. The case was handled under a simplified procedure. | FR | CNIL | GDPR | €3,000 | ↗ |
| 05 Dec 2024 | CLINIQUE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 15,000 on CLINIQUE (procédure simplifiée). The case concerns a regulatory breach that resulted in an administrative sanction. | FR | CNIL | GDPR | €15,000 | ↗ |
| 05 Dec 2024 | SOCIETE DEVELOPPANT ET COMMERCIALISANT UNE EXTENSION POUR NAVIGATEURThe CNIL imposed an administrative fine of EUR 240,000 on SOCIETE DEVELOPPANT ET COMMERCIALISANT UNE EXTENSION POUR NAVIGATEUR and issued an injunction. The case concerns identified regulatory breaches. | FR | CNIL | GDPR | €240,000 | ↗ |
| 05 Dec 2024 | SOCIETE OFFRANT DES PRESTATIONS DE SECURITE PRIVE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 20,000 on SOCIETE OFFRANT DES PRESTATIONS DE SECURITE PRIVE and issued an injunction. The case was handled under a simplified procedure. | FR | CNIL | GDPR | €20,000 | ↗ |
| 05 Dec 2024 | TMETME was fined EUR 200,000 by the AEPD for changing the ownership of a mobile line without consent and for issuing a duplicate SIM card without a valid legal basis. The authority found that these actions failed to meet the requirements for lawful processing and proper authorization of subscriber account changes. | ES | AEPD | GDPR | €200,000 | ↗ |
| 05 Dec 2024 | KASPRThe CNIL imposed an administrative fine of EUR 200,000 on KASPR on 5 December 2024. The authority found GDPR breaches relating to lawful basis, retention, transparency, information, and access rights in connection with KASPR's data scraping activities. | FR | CNIL | GDPR | €200,000 | ↗ |
| 05 Dec 2024 | SOCIETE SPECIALISEE DANS L'ELABORATION ET ORGANISATION DE CAMPAGNES PUBLICITAIRES (procédure simplifiée)The CNIL imposed an administrative fine of EUR 20,000 on SOCIETE SPECIALISEE DANS L'ELABORATION ET ORGANISATION DE CAMPAGNES PUBLICITAIRES under a simplified procedure. The case concerns a data protection breach identified by the authority. | FR | CNIL | GDPR | €20,000 | ↗ |
| 05 Dec 2024 | KASPRThe CNIL imposed an administrative fine of €240,000 on KASPR on 5 December 2024. The case concerned data scraping and multiple GDPR breaches, including lack of lawful basis, poor transparency, excessive retention, and failure to respect access rights. | FR | CNIL | GDPR | €240,000 | ↗ |
| 09 Dec 2024 | SOBLADA RESTAURACIÓN, S.L.SOBLADA RESTAURACIÓN, S.L. was fined by the AEPD EUR 4,500 for installing a video surveillance system without proper signage. The company also failed to inform employees about the system and its purposes, breaching GDPR Articles 5(1)(c) and 13. | ES | AEPD | GDPR | €4,500 | ↗ |
| 10 Dec 2024 | un operatorANSPDCP imposed a fine of 10,000 RON on un operator for non-compliance with the law. A warning was also issued. | RO | ANSPDCP | GDPR | €2,012 | ↗ |
| 11 Dec 2024 | INSTITUTO RAIMON GAJA, S.L.INSTITUTO RAIMON GAJA, S.L. was fined by the AEPD 2,000 EUR for sending unsolicited commercial communications by email. The conduct breached Article 21.1 of the LSSI, despite the recipient’s request to stop receiving such messages. | ES | AEPD | ePrivacy | €2,000 | ↗ |