BULLETIN №084Last updated · 12 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 04 Aug 2017 | VodafoneVodafone was fined 5,000 EUR by the HDPA for failing to satisfy the complainant’s request to access their personal data. The case concerns a breach of the data subject’s access rights under the controller’s obligations. | GR | HDPA | GDPR | €5,000 | ↗ |
| 04 May 2015 | CitibankThe HDPA imposed a fine of EUR 8,000 on Citibank. The case concerned the bank’s failure to satisfy the complainant’s right of access to personal data. | GR | HDPA | GDPR | €8,000 | ↗ |
| 24 Feb 2017 | Geoanalysis S.A.Geoanalysis S.A. was fined EUR 10,000 by the HDPA for improper installation and operation of a video surveillance system. The authority found data protection breaches, including failure to notify the authority and inadequate employee information. | GR | HDPA | GDPR | €10,000 | ↗ |
| 12 May 2021 | A. EPILOGI IDIOTIKI KEFALAIOUCHIKI ETAIREIAThe company was fined by the HDPA 5,000 EUR for sending unsolicited promotional emails without consent. The authority also found that it failed to respond to data subject access requests and did not provide a valid opt-out address for communications. | GR | HDPA | GDPR | €5,000 | ↗ |
| 25 Jun 2025 | Vodafone-PanafonVodafone-Panafon was fined EUR 150,000 by the HDPA for inadequate technical and organizational security measures. The authority found a violation of Article 12 of Law 3471/2006. | GR | HDPA | ePrivacy | €150,000 | ↗ |
| 07 May 2015 | Burger Joint/Maria Galioni I.K.E.The company was fined for unlawfully operating a video surveillance system in the workplace. The authority found a privacy violation because employees and customers were monitored without proper justification. | GR | HDPA | GDPR | €3,000 | ↗ |
| 27 Jun 2012 | OKANAOKANA was fined by the HDPA in the amount of 3,000 EUR for failing to adequately protect special-category personal data. Documents containing patients’ health data were found in trash bins, indicating a breach of data protection rules. | GR | HDPA | GDPR | €3,000 | ↗ |
| 12 Jun 2015 | ALPHA BANKThe HDPA imposed a fine of EUR 100,000 on ALPHA BANK for the unlawful provision of data from the TIRESIAS databases. The case concerned a breach of rules on the processing and disclosure of personal data. | GR | HDPA | GDPR | €100,000 | ↗ |
| 25 Jul 2013 | Anonymised (HDPA 90/2013)The HDPA imposed a EUR 500 fine on the anonymised entity for sending unsolicited marketing emails. The conduct breached the requirement to obtain subscriber consent before sending such communications. | GR | HDPA | ePrivacy | €500 | ↗ |
| 16 Jun 2010 | Anonymised (HDPA 29/2010)The company was fined EUR 3,000 by the HDPA for sending unsolicited marketing emails and faxes without subscriber consent. This conduct breached ePrivacy rules on electronic marketing communications. | GR | HDPA | ePrivacy | €3,000 | ↗ |
| 31 Oct 2022 | B OEThe company was fined for violations related to the operation of a video surveillance system. The authority found non-compliance with data processing principles and insufficient data minimization. | GR | HDPA | GDPR | €10,000 | ↗ |
| 30 Mar 2023 | Vodafone-PanafonVodafone-Panafon was fined by the HDPA for processing personal data for direct marketing without proper consent and transparency. The authority found breaches of lawfulness, fairness, and purpose limitation. | GR | HDPA | GDPR | €10,000 | ↗ |
| 27 Dec 2012 | Euro-Catering O.E.The company installed a CCTV system without notifying the supervisory authority, failed to display required informational signs, and collected excessive data. These actions breached privacy protection rules. | GR | HDPA | GDPR | €20,000 | ↗ |
| 25 Jun 2025 | Vodafone-PanafonVodafone-Panafon was fined by the HDPA for failing to notify a data breach in a timely manner. The authority cited a violation of Article 12 of Law L.3471/2006. | GR | HDPA | ePrivacy | €100,000 | ↗ |
| 04 Apr 2022 | Piraeus Bank S.A.Piraeus Bank S.A. was fined by the HDPA 10,000 EUR for breaching the principle of data confidentiality. The bank sent debit card transaction notifications to incorrect email addresses, failed to notify the authority of the breach, and did not take timely corrective action. | GR | HDPA | GDPR | €10,000 | ↗ |
| 16 Jun 2015 | Eurobank Ergasias AEA fine was imposed for failing to maintain appropriate organizational and technical security measures. This led to unauthorized employee access to the complainant's personal data. | GR | HDPA | GDPR | €5,000 | ↗ |
| 08 Aug 2014 | RANNER ETAIREIA SYLLOGIS KAI DIACHEIRISIS PLIROFORION E.P.E.RANNER ETAIREIA SYLLOGIS KAI DIACHEIRISIS PLIROFORION E.P.E. was fined by the HDPA in the amount of EUR 3,000. The authority found processing of personal data without consent and the sending of unsolicited electronic messages for marketing purposes. | GR | HDPA | GDPR | €3,000 | ↗ |
| 23 Nov 2023 | Alpha BankAlpha Bank was fined for failing to satisfy the complainant’s request for access to personal data. The authority found breaches of GDPR Articles 15 and 5. | GR | HDPA | GDPR | €10,000 | ↗ |
| 04 Apr 2022 | Anonymised (HDPA 15/2022)The former mayor disclosed a municipal employee’s personal data without consent or a lawful basis. The authority found this to be a breach of GDPR principles of lawfulness and purpose limitation. | GR | HDPA | GDPR | €5,000 | ↗ |
| 05 Jan 2022 | Egnatia Odos S.A.Egnatia Odos S.A. was fined by the HDPA EUR 1,000 for failing to provide the complainant with access to personal data related to a toll violation. The authority found a breach of the right of access under the GDPR. | GR | HDPA | GDPR | €1,000 | ↗ |