BULLETIN №083Last updated · 11 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.1%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 15 Oct 2024 | AFP GESTION DEL COLOR, S.L.AFP GESTION DEL COLOR, S.L. was fined by the AEPD in the amount of €1,000 for sending unsolicited commercial emails. The conduct breached Article 21.1 of the LSSI, which prohibits marketing communications without prior consent. | ES | AEPD | ePrivacy | €1,000 | ↗ |
| 12 Dec 2024 | Istituto Comprensivo Statale CalenzanoIstituto Comprensivo Statale Calenzano was fined EUR 1,000 by the Garante for breaching data protection principles. The case concerned the processing of personal data without meeting the requirements of lawfulness, fairness, and transparency. | IT | Garante | GDPR | €1,000 | ↗ |
| 05 Aug 2022 | Mister Brick S.a.s.Mister Brick S.a.s. was fined EUR 1,000 by the Garante for sending an unsolicited promotional email without obtaining prior consent from the recipient. The authority found this to be a breach of GDPR requirements on lawful processing and consent. | IT | Garante | GDPR | €1,000 | ↗ |
| 24 Nov 2022 | Medicover S.R.L.Medicover S.R.L. was fined EUR 1,000 by ANSPDCP for a data security breach. An email sent to a customer included additional contract documents belonging to other clients, resulting in disclosure of third-party personal data. | RO | ANSPDCP | GDPR | €1,000 | ↗ |
| 11 Sept 2025 | Giada FM S.r.l.Giada FM S.r.l. was fined EUR 1,000 by the Garante for failing to respond to an employee’s request to access personal data. The request covered training certificates and medical visit documentation, which is a breach of the GDPR access rights. | IT | Garante | GDPR | €1,000 | ↗ |
| 21 Oct 2014 | ACDACD was fined by the HDPA 1,000 EUR for sending unsolicited marketing emails without the recipients’ consent. This breached Article 11 of Law 3471/2006. | GR | HDPA | ePrivacy | €1,000 | ↗ |
| 24 Jun 2025 | I ASPIDA TOU DAVIDThe HDPA imposed a EUR 1,000 fine on I ASPIDA TOU DAVID. The authority found that the entity failed to cooperate, which breaches GDPR requirements. | GR | HDPA | GDPR | €1,000 | ↗ |
| 06 Mar 2020 | B.B.B.A private individual was fined by the AEPD €1,000 for installing surveillance cameras without the required informational signage. The case concerned a breach of data protection rules linked to proper notice for video surveillance. | ES | AEPD | GDPR | €1,000 | ↗ |
| 16 Dec 2021 | Università Telematica Internazionale UninettunoUniversità Telematica Internazionale Uninettuno was fined EUR 1,000 by the Italian supervisory authority Garante. The authority found breaches of lawfulness, fairness, transparency, and data minimization principles. | IT | Garante | GDPR | €1,000 | ↗ |
| 25 Jul 2013 | Anonymised (HDPA 90/2013)HDPA imposed a fine of EUR 1,000 on Anonymised (HDPA 90/2013) for the illegal collection and further processing of personal data. The case concerns a breach of the lawful processing requirements. | GR | HDPA | GDPR | €1,000 | ↗ |
| 02 Oct 2023 | Cez Vânzare S.A.Cez Vânzare S.A. was fined by ANSPDCP EUR 1,000 for a data protection breach. The incident resulted in unauthorized disclosure or access to personal data, including names, correspondence addresses, and customer codes of both individuals and legal entities. | RO | ANSPDCP | GDPR | €1,000 | ↗ |
| 26 Oct 2023 | Provvedimento del 26 ottobre 2023 [9960920]The Garante imposed a EUR 1,000 fine on a condominium administrator for installing a video surveillance system without a proper legal basis or assembly resolution. The conduct was found to breach GDPR rules on lawful processing. | IT | Garante | GDPR | €1,000 | ↗ |
| 29 Jan 2024 | JAÉN, SENTIDO Y COMÚNThe entity was fined by the AEPD for failing to comply with a data protection authority resolution. The breach concerned sending emails to multiple recipients without using BCC, contrary to Article 58(2) GDPR. | ES | AEPD | GDPR | €1,000 | ↗ |
| 14 May 2026 | FeGi M&A Services s.r.l.FeGi M&A Services s.r.l. was fined EUR 1,000 by the Garante for making promotional phone calls without the required consent. The authority found this conduct breached GDPR principles of fairness and transparency. | IT | Garante | GDPR | €1,000 | ↗ |
| 08 Nov 2024 | PPC Energie Muntenia S.AThe National Supervisory Authority for Personal Data Processing completed an investigation at PPC Energie Muntenia S.A and found a violation of GDPR provisions. As a result, a fine of EUR 1,000 was imposed. | RO | ANSPDCP | GDPR | €1,000 | ↗ |
| 27 Apr 2023 | B.B.B.The entity was fined by the AEPD in the amount of EUR 1,000 for installing surveillance cameras without proper signage and justification. The authority treated this as a breach of data protection rules. | ES | AEPD | GDPR | €1,000 | ↗ |
| 14 Dec 2021 | MALAGATROM, S.L.UMALAGATROM, S.L.U was fined by the AEPD in the amount of EUR 1,000 for failing to comply with a prior decision. That decision required the removal of comments containing personal data from its Amazon page and the implementation of measures to prevent similar incidents in the future. | ES | AEPD | GDPR | €1,000 | ↗ |
| 05 Feb 2026 | MÉDECIN (procédure simplifiée)The CNIL imposed EUR 1,000 on MÉDECIN (simplified procedure) as a liquidation of an astreinte. The case concerns compliance with a prior obligation set by the supervisory authority. | FR | CNIL | GDPR | €1,000 | ↗ |
| 02 Feb 2023 | TRACTAMENT D'AIGUES TEIA, S.L.TRACTAMENT D'AIGUES TEIA, S.L. was fined by the AEPD EUR 1,000 for failing to comply with a data subject's request to delete personal data. The case indicates non-compliance with GDPR obligations regarding the exercise of individual rights. | ES | AEPD | GDPR | €1,000 | ↗ |
| 16 Dec 2021 | 1000 Luci Round a BarThe establishment 1000 Luci Round a Bar was fined EUR 1,000 by the Italian authority Garante. The sanction concerned a video surveillance system that did not meet the information requirements of Article 13 GDPR. | IT | Garante | GDPR | €1,000 | ↗ |