BULLETIN №083Last updated · 11 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.1%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 17 Mar 2016 | Aurelia FevolaAurelia Fevola was fined by the Garante for collecting personal data through her website without providing users with the required information notice. This conduct breached the Italian Data Protection Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 07 Jul 2025 | AURThe Romanian data protection authority imposed two fines on AUR totaling EUR 25,000. The sanctions concerned unauthorized access to supporters' personal data in the AUR app and unlawful collection of personal data on campaign platforms. | RO | Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal | GDPR | €25,000 | ↗ |
| 28 Jun 2022 | AUDIO STOCK, S.L.AUDIO STOCK, S.L. was fined €2,000 by the AEPD for sending commercial SMS messages despite the recipient's objection. The authority found this conduct breached Article 21 of the LSSI on unsolicited commercial communications. | ES | AEPD | ePrivacy | €2,000 | ↗ |
| 05 Sept 2025 | AUDIO ÓPTICA EUROPA, S.L.AUDIO ÓPTICA EUROPA, S.L. was fined by the AEPD EUR 1,500 for using a minor’s image without valid consent. The authority found this conduct to be in breach of Article 6 of the GDPR. | ES | AEPD | GDPR | €1,500 | ↗ |
| 23 Nov 2021 | atvinnuvega- og nýsköpunarráðuneytiðThe Icelandic DPA, Persónuvernd, fined atvinnuvega- og nýsköpunarráðuneytið for processing personal data in breach of core GDPR principles, including transparency and security. The case concerned the Ferðagjöf app, where the authority found deficiencies in data protection compliance. | IS | Persónuvernd | GDPR | €50,850 | ↗ |
| 13 May 2021 | ATS di Bergamo, Agenzia di Tutela della saluteATS di Bergamo was fined by the Garante 20,000 EUR for violations involving the improper handling of sensitive health data. The case concerned the use of email to transmit data, which did not provide an adequate level of protection. | IT | Garante | GDPR | €20,000 | ↗ |
| 14 Oct 2024 | ATRESMEDIA CORPORACIÓN DE MEDIOS DE COMUNICACIÓN, S.A.ATRESMEDIA was fined by the AEPD EUR 50,000 for publishing a video containing violent content and the voices of the aggressors and the victim. The authority found a breach of data protection rules. | ES | AEPD | GDPR | €50,000 | ↗ |
| 01 Jan 2023 | ATRESMEDIA CORPORACIÓN DE MEDIOS DE COMUNICACIÓN, S.A.ATRESMEDIA was fined by the AEPD in the amount of 50,000 EUR for publishing excessive personal data. The case concerned an audio recording of a victim's court statement, which was not necessary for the journalistic purpose. | ES | AEPD | GDPR | €50,000 | ↗ |
| 11 Sept 2025 | ATRESMEDIA CORPORACIÓN DE MEDIOS DE COMUNICACIÓN, S.A.ATRESMEDIA was fined by the AEPD for disclosing personal data, including a handwritten signature, in a news broadcast without necessity. The authority found that the disclosure breached data protection principles because it was not proportionate to the purpose of the publication. | ES | AEPD | GDPR | €10,000 | ↗ |
| 30 Jun 2014 | ATRAPALO, S.L.ATRAPALO, S.L. was fined by the AEPD EUR 600 for sending unsolicited commercial emails to a user who had previously requested to unsubscribe. The authority found a breach of Article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €600 | ↗ |
| 21 Jul 2023 | ATLAS ENTERTAINMENT, S.L.ATLAS ENTERTAINMENT, S.L. did not comply with a data subject’s request to delete personal data. The AEPD imposed a fine of EUR 1,000 for the GDPR breach. | ES | AEPD | GDPR | €1,000 | ↗ |
| 16 Feb 2011 | Athena Research s.r.l.Athena Research s.r.l. was fined 6,000 EUR by the Garante for sending unsolicited commercial faxes without the recipients' explicit consent. The authority also found that the required privacy notice was not provided, in breach of the Italian Data Protection Code. | IT | Garante | GDPR | €6,000 | ↗ |
| 25 Jan 2018 | ATAM S.p.A. – Azienda territoriale Arezzo Mobilità S.p.A.ATAM S.p.A. was fined by the Italian data protection authority, Garante, in the amount of €20,000. The case concerned failures to meet notification obligations related to a geolocation system used to track vehicles. | IT | Garante | GDPR | €20,000 | ↗ |
| 22 Jul 2021 | Atac s.p.a.Atac s.p.a. was fined by the Garante 400,000 EUR for processing personal data without a specific legal basis and without adequate security measures. The case concerned users of paid parking services in Rome. | IT | Garante | GDPR | €400,000 | ↗ |
| 02 Nov 2023 | ASYMECO, S.A.ASYMECO, S.A. was fined EUR 5,000 by the AEPD for sending clients’ personal data to an employee’s private WhatsApp without proper authorization. The authority found this breached GDPR Articles 6(1) and 32. | ES | AEPD | GDPR | €5,000 | ↗ |
| 16 Jul 2024 | AS Watson / KruidvatThe Dutch data protection authority, Autoriteit Persoonsgegevens, imposed a fine of EUR 600,000 on AS Watson / Kruidvat. The case concerns a breach of GDPR cookie consent rules. | NL | Autoriteit Persoonsgegevens | GDPR | €600,000 | ↗ |
| 16 Jul 2024 | A.S. Watson Health & Beauty Continental Europe B.V.A.S. Watson Health & Beauty Continental Europe B.V. was fined 600,000 EUR by the Dutch AP. The authority found that the company processed personal data without a lawful basis because it failed to obtain consent for tracking cookies on kruidvat.nl, breaching GDPR Articles 5 and 6. | NL | AP | GDPR | €600,000 | ↗ |
| 19 Jan 2023 | A startup football clubThe Belgian data protection authority, GBA, imposed an EUR 8,000 fine on a startup football club. The case involved failure to respond to a data subject access request, as well as additional GDPR breaches concerning transparency and processor-contract requirements. | BE | Gegevensbeschermingsautoriteit (GBA) | GDPR | €8,000 | ↗ |
| 16 Jan 2026 | Associazione Turistica Pro Loco di CittarealeThe association unlawfully disclosed the personal data of 23 members by publishing it in a public notice and online. The authority found breaches of lawfulness, fairness, transparency, and data minimization. | IT | Garante | GDPR | €600 | ↗ |
| 25 Feb 2016 | Associazione sportivo dilettantistica Feriolo Sporting ClubFeriolo Sporting Club was fined by the Garante 14,400 EUR for failing to provide adequate simplified information about its video surveillance system. The authority also found that recorded images were retained longer than permitted. | IT | Garante | GDPR | €14,400 | ↗ |