BULLETIN №084Last updated · 12 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 31 Dec 2024 | SOCIETE DE TRANSPORT AMBULANCIER (procédure simplifiée)The CNIL imposed an administrative fine of EUR 10,000 on SOCIETE DE TRANSPORT AMBULANCIER. The case was handled under a simplified procedure. | FR | CNIL | GDPR | €10,000 | ↗ |
| 31 Dec 2024 | PARTICULIERS (procédure simplifiée)An administrative fine of EUR 5,000 was imposed by the CNIL. The case was handled under a simplified procedure. | FR | CNIL | GDPR | €5,000 | ↗ |
| 31 Dec 2024 | SOCIETE GERANT UN ROBOT CONVERSATIONNEL UTILISANT L'INTELLIGENCE ARTIFICELLE (procédure simplifiée)The CNIL imposed an administrative fine of 5,000 EUR on the company operating an AI-based conversational robot. The case was handled under a simplified procedure. | FR | CNIL | GDPR | €5,000 | ↗ |
| 01 Jan 2025 | MONUMENTAL FORMA SPORT, S.L.MONUMENTAL FORMA SPORT, S.L. was fined by the AEPD EUR 3,000 for requesting excessive personal data, including banking information, in connection with a free gym access promotion. The authority found that the data requested breached the GDPR data minimisation principle under Article 5(1)(c). | ES | AEPD | GDPR | €3,000 | ↗ |
| 01 Jan 2025 | Εθνική Τράπεζα της Ελλάδος Α.Ε.The data protection authority imposed a EUR 220,000 fine on Εθνική Τράπεζα της Ελλάδος Α.Ε. for a GDPR violation. The case concerned deficiencies in personal data protection and compliance with GDPR requirements. | GR | Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα | GDPR | €220,000 | ↗ |
| 01 Jan 2025 | SGKLegalThe Greek data protection authority, ΑΠΔΠΧ, imposed a fine of EUR 22,000 on SGKLegal for a GDPR violation. The case involved recorded conversations and deficiencies in personal data protection compliance. | GR | Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (ΑΠΔΠΧ) | GDPR | €22,000 | ↗ |
| 01 Jan 2025 | B3C CONSULTORÍA DE SERVICIOS 2010 S.L.B3C CONSULTORÍA DE SERVICIOS 2010 S.L. was fined by the AEPD EUR 800 for subcontracting TELCO without authorization from the data controller, AIRE NETWORKS. The company also failed to impose the required contractual obligations on TELCO, breaching GDPR Articles 28.2 and 28.4. | ES | AEPD | GDPR | €800 | ↗ |
| 01 Jan 2025 | STRATESYS TECHNOLOGY SOLUTIONS, S.L.STRATESYS TECHNOLOGY SOLUTIONS, S.L. was fined EUR 100,000 by the AEPD for breaching Article 5(1)(f) of the GDPR. The case concerned a failure to protect the integrity and confidentiality of personal data. | ES | AEPD | GDPR | €100,000 | ↗ |
| 01 Jan 2025 | A.A.A.A.A.A. failed to properly handle a data access request, which constitutes a breach of Article 15 GDPR. The AEPD imposed a fine of EUR 200, reduced to EUR 160 for early payment. | ES | AEPD | GDPR | €200 | ↗ |
| 01 Jan 2025 | TELEROSA SPAIN, S.L.TELEROSA SPAIN, S.L. was fined 450 EUR by the AEPD for sending unsolicited commercial SMS messages without prior express consent. The authority also noted that there was no pre-existing contractual relationship with the recipients. | ES | AEPD | ePrivacy | €450 | ↗ |
| 01 Jan 2025 | FEMXA FORMACIÓN, S.L.FEMXA FORMACIÓN, S.L. was fined by the AEPD 25,000 EUR for requiring a full copy of a student's ID during course enrollment. The authority found the data request unnecessary and inconsistent with data protection principles. | ES | AEPD | GDPR | €25,000 | ↗ |
| 01 Jan 2025 | MALAGASUITE SHOWROOM, S.L.MALAGASUITE SHOWROOM, S.L. was fined by the AEPD 2,000 EUR for failing to inform guests about the processing of their personal data. The authority found a breach of Article 13 GDPR. | ES | AEPD | GDPR | €2,000 | ↗ |
| 01 Jan 2025 | AMADEUSAMADEUS was fined EUR 9,000,000 by the AEPD for breaching GDPR Articles 14 and 6. The authority found that the company failed to inform data subjects about the processing of their personal data. | ES | AEPD | GDPR | €9,000,000 | ↗ |
| 01 Jan 2025 | Sambla GroupThe Finnish Data Protection Authority fined Sambla Group EUR 950,000 after unauthorized parties accessed credit application data by manipulating web addresses. The authority found that the company had not implemented adequate safeguards to prevent the breach. | FI | Tietosuojavaltuutetun toimisto | GDPR | €950,000 | ↗ |
| 01 Jan 2025 | Diskrimineringsombudsmannen (DO)Integritetsskyddsmyndigheten (IMY) imposed a 100,000 SEK administrative sanction on Diskrimineringsombudsmannen (DO). The case concerned insufficient security measures for personal data collected via a web form, which resulted in unintended disclosure to a processor. | SE | Integritetsskyddsmyndigheten (IMY) | GDPR | €8,727 | ↗ |
| 01 Jan 2025 | RaiItaly’s data protection authority fined Rai EUR 150,000 over a Report broadcast on 8 December 2024 that disclosed a private conversation. The case concerns unlawful processing of personal data in a television report. | IT | Garante per la protezione dei dati personali | GDPR | €150,000 | ↗ |
| 01 Jan 2025 | ASESORAMOS TU FORMACIÓN CON CALIDAD S.L.ASESORAMOS TU FORMACIÓN CON CALIDAD S.L. was fined by the AEPD 10,000 EUR for processing personal data without a legal basis. The case also involved the improper inclusion of individuals in credit information systems. | ES | AEPD | GDPR | €10,000 | ↗ |
| 01 Jan 2025 | PROYECTOS VISUALES ZARAGOZA SLPROYECTOS VISUALES ZARAGOZA SL was fined by the AEPD 50,000 EUR for a personal data breach. The authority found that the company failed to ensure data integrity and confidentiality under Article 5(1)(f) GDPR. | ES | AEPD | GDPR | €50,000 | ↗ |
| 01 Jan 2025 | Posti Jakelu OyPosti Jakelu Oy was fined EUR 2,400,000 by the Data Protection Ombudsman for deficiencies in data protection related to the OmaPosti service. The case concerned inadequate safeguards and failures to meet personal data protection requirements. | FI | Tietosuojavaltuutettu | GDPR | €2,400,000 | ↗ |
| 06 Jan 2025 | Anonymisé (CNPD decision-01-fr-2025)The entity failed to comply with the response time requirements for data subject requests, which constitutes a breach of Article 12 GDPR. CNPD imposed a fine of EUR 493,560. | LU | CNPD | GDPR | €493,000 | ↗ |