BULLETIN №081Last updated · 27 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -20.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 01 Jan 2023 | CARSO TRADING, S.L.CARSO TRADING, S.L. was fined by the AEPD in the amount of 1,000 EUR for sending unsolicited commercial emails. The company also failed to respond to a data access request, which constitutes a breach of Article 15 GDPR. | ES | AEPD | GDPR | €1,000 | ↗ |
| 30 Nov 2022 | INMARAN ASESORES S.L.INMARAN ASESORES S.L. was fined by the AEPD 1,000 EUR for failing to comply with data protection authority resolutions. The breach concerned the obligation to inform data subjects under Article 13 of the GDPR. | ES | AEPD | GDPR | €1,000 | ↗ |
| 01 May 2026 | Anonymised (IDPC 0583_001)The Commissioner found that the insurance company continued to process the complainant’s personal data for direct marketing despite his objection. The authority also identified inadequate safeguards, weak accountability measures, and non-compliant arrangements with third-party processors. A reprimand was issued, corrective measures were ordered within 20 days, and administrative fines totalling EUR 1,000 were imposed. | MT | IDPC | GDPR | €1,000 | ↗ |
| 04 Dec 2023 | CARSO TRADING, S.L.CARSO TRADING, S.L. was fined by the AEPD for sending unsolicited commercial emails without prior consent from recipients. The company also failed to respond to a request to stop such communications, which constitutes a breach of the LSSI. | ES | AEPD | ePrivacy | €1,000 | ↗ |
| 26 Jun 2025 | SC Piramida Trade Invest SRLSC Piramida Trade Invest SRL received a fine of EUR 1,000 from ANSPDCP. The sanction concerns a breach of Article 6 GDPR, meaning personal data were processed without a valid legal basis. | RO | ANSPDCP | GDPR | €1,000 | ↗ |
| 16 Jun 2023 | Anonymisiert (DSB 2023-0.404.421)An individual processed personal data without a legal basis by storing contact details on a private phone for political advertising. The DSB imposed a EUR 1,000 fine for breaching GDPR lawfulness requirements. | AT | DSB | GDPR | €1,000 | ↗ |
| 31 Jan 2023 | Dent Estet Clinic SADent Estet Clinic SA was fined EUR 1,000 by ANSPDCP for failing to notify the supervisory authority within 72 hours of becoming aware of a personal data breach. The incident involved unauthorized disclosure of health data, which required prompt reporting under GDPR rules. | RO | ANSPDCP | GDPR | €1,000 | ↗ |
| 01 Jan 2021 | ASOCIACIÓN JEREZ CAPITALThe entity was fined by the AEPD for failing to comply with data protection rules in relation to its website cookie policy. Non-essential cookies were placed on the site without prior user consent. | ES | AEPD | GDPR | €1,000 | ↗ |
| 19 Dec 2024 | CLUB RÁPIDO DE BOUZASThe club was fined by the AEPD for leaving documents containing players’ personal data, including minors’ data, in a public trash container. The authority found this breached data protection principles, especially confidentiality and security. | ES | AEPD | GDPR | €1,000 | ↗ |
| 16 Sept 2024 | SC Class IT Outsourcing SRLSC Class IT Outsourcing SRL was fined EUR 1,000 by ANSPDCP for GDPR violations. The case concerned non-compliance with personal data protection requirements. | RO | ANSPDCP | GDPR | €1,000 | ↗ |
| 26 Feb 2015 | Anonymised (HDPA 26/2015)The company was fined for unlawful collection and processing of personal data, and for sending unsolicited marketing emails without recipients’ consent. The case concerns breaches of core data protection principles and the requirement to obtain prior consent for marketing communications. | GR | HDPA | ePrivacy | €1,000 | ↗ |
| 07 Jun 2021 | EFS MANTENIMIENTO Y SERVICIOS TÉCNICOS, S.L.EFS MANTENIMIENTO Y SERVICIOS TÉCNICOS, S.L. was fined EUR 1,000 by the AEPD for improperly sharing an employee’s personal data with the company committee. The authority found a breach of data protection rules. | ES | AEPD | GDPR | €1,000 | ↗ |
| 22 Jun 2017 | Bolos & SynergatesThe law firm Bolos & Synergates was fined EUR 1,000 by the HDPA for unlawfully collecting and using personal data for direct marketing. The violation involved unsolicited electronic communications sent without prior consent from the data subjects. | GR | HDPA | ePrivacy | €1,000 | ↗ |
| 05 Aug 2025 | Ordinul Biochimiștilor, Biologilor și Chimiștilor în Sistemul Sanitar din RomâniaANSPDCP imposed a EUR 1,000 fine on the Order of Biochemists, Biologists and Chemists in the Romanian Healthcare System for breaching Article 15 of the GDPR. The case concerned improper handling of a data subject access request. | RO | ANSPDCP | GDPR | €1,000 | ↗ |
| 10 Jul 2020 | COMUNIDAD.1The entity was fined for installing surveillance cameras with audio in common areas without proper notice to affected persons. The authority found this to be a breach of data protection rules. | ES | AEPD | GDPR | €1,000 | ↗ |
| 05 Mar 2021 | APARTAMENTOS PLAYA DE COVACHOS, S.L.The company was fined by the AEPD in the amount of 1,000 EUR for operating video surveillance without the required information for recorded individuals. It did not identify the data controller, explain how rights could be exercised, or state the purpose of the surveillance, which breaches Article 13 GDPR. | ES | AEPD | GDPR | €1,000 | ↗ |
| 26 May 2014 | General Hospital PapageorgiouGeneral Hospital Papageorgiou was fined EUR 1,000 by the HDPA for transferring sensitive health data without prior authorization. The hospital also failed to inform the data subject, breaching Greek data protection law. | GR | HDPA | GDPR | €1,000 | ↗ |
| 01 Jan 2014 | EL CORTE INGLES, S.A.EL CORTE INGLES, S.A. was fined by the AEPD 1,000 EUR for sending unsolicited commercial emails. The conduct breached Article 21.1 of Spain’s LSSI, which restricts marketing communications without recipient consent. | ES | AEPD | ePrivacy | €1,000 | ↗ |
| 01 Aug 2025 | Dr. Max SRLANSPDCP fined Dr. Max SRL EUR 1,000 after an investigation concluded in August 2025. The authority found breaches of GDPR Articles 12 and 17, including failure to respond to a deletion request and unlawful retention of an identity card copy without consent. | RO | Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal | GDPR | €1,000 | ↗ |
| 24 Nov 2022 | STS Di Prisinzano s.r.l.STS Di Prisinzano s.r.l. was fined EUR 1,000 by the Garante for failing to provide a data subject with an adequate privacy notice during roadside assistance. The authority found a breach of Article 13 GDPR. | IT | Garante | GDPR | €1,000 | ↗ |