BULLETIN №081Last updated · 27 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -20.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 30 Jan 2026 | un operator persoană fizicăA 1,000 EUR fine was imposed on an individual operator for GDPR violations. The case concerned non-compliance with personal data protection requirements. | RO | ANSPDCP | GDPR | €1,000 | ↗ |
| 04 Apr 2022 | B.B.B.B.B.B. was fined 1,000 EUR by the AEPD for failing to comply with Article 13 of the GDPR. The authority found that the privacy policy did not provide adequate information on data retention periods and transfers to third parties. | ES | AEPD | GDPR | €1,000 | ↗ |
| 13 Dec 2022 | Anonymisé (CNPD decision-19-fr-2022)The company failed to meet GDPR transparency obligations by not providing the required information in a concise, transparent, and easily accessible manner. CNPD imposed a fine of 1,000 EUR. | LU | CNPD | GDPR | €1,000 | ↗ |
| 28 Jun 2023 | FESTINA LOTUS S.A.FESTINA LOTUS S.A. did not respond to requests to delete a user's account and personal data. The authority found a breach of Article 17 GDPR and imposed a fine of EUR 1,000. | ES | AEPD | GDPR | €1,000 | ↗ |
| 23 Nov 2022 | Linee Stampalibera Società Cooperativa S.r.l.Linee Stampalibera Società Cooperativa S.r.l. was fined 1,000 EUR by the Garante for publishing personal data on its website without consent. The case also involved the full text of a property purchase contract, which breached data protection rules. | IT | Garante | GDPR | €1,000 | ↗ |
| 22 Jun 2023 | Spaziani FabrizioThe Garante fined Spaziani Fabrizio EUR 1,000 for non-compliant video surveillance practices. The case involved cameras that were not properly signposted and may have captured public areas. | IT | Garante | GDPR | €1,000 | ↗ |
| 10 Sept 2024 | Fundația Pro Economica – Pro Economica AlapítványThe foundation was fined EUR 1,000 by ANSPDCP after a data security incident caused by a cyberattack. The attack led to the deletion of personal data from its server, affecting data availability. | RO | ANSPDCP | GDPR | €1,000 | ↗ |
| 30 Jul 2018 | А.С.К. УМБАЛ ЕООДThe CPDP found that “А.С.К. УМБАЛ ЕООD” unlawfully processed personal data by providing it to “МБАЛ-В. ЕООD” without consent. This breached data protection rules and resulted in a fine of BGN 1,000. | BG | CPDP | GDPR | €511 | ↗ |
| 18 Dec 2025 | Provvedimento del 18 dicembre 2025 [10210431]A professional sent a communication containing personal data to an institutional email address, which breached data protection rules. The Garante imposed a fine of EUR 1,000. | IT | Garante | GDPR | €1,000 | ↗ |
| 07 Sept 2022 | LEGAL TRAINING GROUP, S.L.LEGAL TRAINING GROUP, S.L. was fined by the AEPD €1,000 for sending unsolicited commercial communications. The conduct occurred after the complainant had exercised the right to data deletion. | ES | AEPD | ePrivacy | €1,000 | ↗ |
| 01 Jan 2018 | ZARA LIBRO S.L. (DIFUSIÓN DEL LIBRO)ZARA LIBRO S.L. was fined by the AEPD in the amount of 1,000 EUR for sending a commercial email without a prior commercial relationship. The authority found a breach of Article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €1,000 | ↗ |
| 05 Feb 2021 | NEXTSTEPAGENCY, S.L.NEXTSTEPAGENCY, S.L. was fined by the AEPD in the amount of 1,000 EUR for failing to provide reliable ownership information and details about data transfers to China on its website. The authority found a breach of the information obligations under Article 13 GDPR. | ES | AEPD | GDPR | €1,000 | ↗ |
| 09 May 2024 | MEDICOVER SRLMEDICOVER SRL was fined EUR 1,000 by ANSPDCP for the unauthorized disclosure of personal data from a medical consultation report to an unintended patient. The case concerns a breach of confidentiality involving special-category data and indicates a need to strengthen access controls and recipient verification procedures. | RO | ANSPDCP | GDPR | €1,000 | ↗ |
| 22 Feb 2022 | Societatea Civilă Profesională de Avocați „Sabou, Burz & Cuc”The law firm Societatea Civilă Profesională de Avocați „Sabou, Burz & Cuc” was fined by ANSPDCP for violating GDPR provisions. The penalty amounted to EUR 1,000. | RO | ANSPDCP | GDPR | €1,000 | ↗ |
| 26 Feb 2026 | Ciemme S.r.l.sThe Italian Data Protection Authority fined Ciemme S.r.l.s EUR 1,000 for failing to respond to a data subject request to exercise rights of access, erasure, and objection. The case arose after unsolicited marketing calls. | IT | Garante | GDPR | €1,000 | ↗ |
| 07 Jun 2024 | Club Balonmano GijónClub Balonmano Gijón was fined EUR 1,000 by the AEPD for unlawfully processing personal data by publishing images of minors on its website without a legal basis. The case indicates a breach of the lawfulness principle and the protection of children's image rights. | ES | AEPD | GDPR | €1,000 | ↗ |
| 18 Sept 2025 | Dr.Max SRLIn August of the current year, ANSPDCP completed an investigation at Dr.Max SRL and found a breach of GDPR provisions. As a result, the operator was fined EUR 1,000. | RO | ANSPDCP | GDPR | €1,000 | ↗ |
| 25 Oct 2024 | IA BILET SRLThe operator was fined EUR 1,000 by ANSPDCP for violating GDPR provisions. The case concerns non-compliant processing of personal data. | RO | ANSPDCP | GDPR | €1,000 | ↗ |
| 20 May 2022 | THUNDER HUNTER ENERGY ADVISORS, S.L.THUNDER HUNTER ENERGY ADVISORS, S.L. was fined by the AEPD 1,000 EUR for sending unsolicited commercial emails without prior consent. The authority found this conduct breached Article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €1,000 | ↗ |
| 20 Mar 2026 | Domeniul Public și Privat SADomeniul Public și Privat SA was fined EUR 1,000 for breaching Article 15 of the GDPR. The case concerned improper handling of data subject access rights. | RO | ANSPDCP | GDPR | €1,000 | ↗ |