BULLETIN №083Last updated · 11 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.1%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 17 Jan 2019 | Учебно заведениеThe school was fined 1,000 BGN by the CPDP for unlawfully processing students' personal data. It shared the data with a financial institution without proper consent, which breached GDPR requirements. | BG | CPDP | GDPR | €511 | ↗ |
| 08 Aug 2014 | Anonymised (HDPA 112/2014)The controller sent unsolicited marketing SMS messages without recipients' consent, breaching data protection rules. The case concerned the use of contact data for marketing without a valid legal basis. | GR | HDPA | ePrivacy | €1,000 | ↗ |
| 25 Mar 2025 | B.B.B.B.B.B. was fined EUR 1,000 by the AEPD for lacking an adequate data processing protocol. The authority also found that individuals were not properly informed about the processing of their personal data, in breach of GDPR Articles 5(1)(c) and 13. | ES | AEPD | GDPR | €1,000 | ↗ |
| 15 Sept 2022 | HOTEL VILLA SORO, S.L.The company was fined by the AEPD EUR 1,000 for installing surveillance cameras that could capture public areas without proper signage. The authority considered this a breach of data protection rules. | ES | AEPD | GDPR | €1,000 | ↗ |
| 21 Feb 2017 | MILI CAFEMILI CAFE was fined EUR 1,000 for unlawful video surveillance practices. The violations included recording audio without proper security measures and retaining footage for more than 15 days. | GR | HDPA | GDPR | €1,000 | ↗ |
| 02 Jul 2020 | CENTRO INTERNACIONAL DE CRECIMIENTO LABORAL Y PROFESIONAL, S.L.The entity sent unsolicited commercial emails without the recipients’ consent. It also failed to provide a valid unsubscribe option, which breached the LSSI. | ES | AEPD | ePrivacy | €1,000 | ↗ |
| 03 May 2016 | REAL AUTOMOVIL CLUB DE ESPAÑAREAL AUTOMOVIL CLUB DE ESPAÑA was fined by the AEPD EUR 1,000 for sending unsolicited commercial emails despite the recipient's requests to unsubscribe. The authority found a breach of Article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €1,000 | ↗ |
| 01 Jan 2015 | WERBUNG INTERNET S.L.WERBUNG INTERNET S.L. was fined by the AEPD €1,000 for sending unsolicited commercial emails without prior consent. The conduct breached Article 21.1 of the LSSI on electronic marketing communications. | ES | AEPD | ePrivacy | €1,000 | ↗ |
| 05 Aug 2022 | Colosseo S.r.l.Colosseo S.r.l. was fined EUR 1,000 by the Garante for sending unsolicited promotional emails without prior recipient consent. The authority found this breached GDPR rules on lawful processing and consent. | IT | Garante | GDPR | €1,000 | ↗ |
| 15 Sept 2022 | EDITORIAL RIBADEO S.L.EDITORIAL RIBADEO S.L. was fined EUR 1,000 by the AEPD for failing to meet the information obligations under Articles 12 and 13 of the GDPR. The authority also noted non-compliance with previous data protection decisions. | ES | AEPD | GDPR | €1,000 | ↗ |
| 27 Feb 2026 | T., za naruszenie art. 5 ust. 1 lit. f), art. 5 ust. 2 oraz art. 32 ust. 1 i 2 rozporządzenia 2016/679,The Polish DPA (UODO) imposed an administrative fine of PLN 975 on T. for failing to implement appropriate technical and organizational measures and for lacking a proper, accountable data protection policy tailored to its processing activities. The authority also noted deficiencies in transparency notices, processor agreements, access authorizations, and the record of processing activities. | PL | UODO | GDPR | €231 | ↗ |
| 10 Jan 2025 | Stowarzyszenie „Maraton” z GorlicThe President of the Personal Data Protection Office imposed an administrative fine of PLN 916.71 on Stowarzyszenie „Maraton” z Gorlic. The penalty concerned failure to notify a personal data breach within the required 72-hour deadline, together with related compliance shortcomings. | PL | Prezes Urzędu Ochrony Danych Osobowych | GDPR | €215 | ↗ |
| 30 Apr 2024 | Dane anonimowe (Stowarzyszenie F. z siedzibą w X. przy ul.)UODO imposed an administrative fine on Association F. for failing to notify the supervisory authority of a personal data breach without undue delay, and no later than 72 hours after becoming aware of it. The case concerns the obligation to report data security incidents within the required timeframe. | PL | UODO | GDPR | €212 | ↗ |
| 09 Jul 2025 | KAFFA KOFFEE ORGANISATION, S.L.KAFFA KOFFEE ORGANISATION, S.L. was fined EUR 900 by the AEPD for failing to implement appropriate technical and organizational measures. The deficiency led to email addresses being visible to multiple recipients, in breach of GDPR requirements. | ES | AEPD | GDPR | €900 | ↗ |
| 06 Mar 2025 | CUBILLO GALLEGO, S.L.CUBILLO GALLEGO, S.L. was fined by the AEPD in the amount of 900 EUR for failing to comply with data protection authority resolutions. The breach concerned the absence of required privacy information on the company website and in contracts. | ES | AEPD | GDPR | €900 | ↗ |
| 01 Jan 2023 | ISA MADRID SERVICIOS, S.L.ISA MADRID SERVICIOS, S.L. was fined EUR 900 by the AEPD for improperly positioning a surveillance camera that captured public areas. The authority also found that adequate signage informing individuals about the surveillance was not provided, in breach of data protection rules. | ES | AEPD | GDPR | €900 | ↗ |
| 07 Jan 2020 | CHENMING YE (BAZAR REAL)CHENMING YE (BAZAR REAL) was fined EUR 900 by the AEPD. The authority found that the required visible notice identifying the data controller was missing, which breached data protection rules. | ES | AEPD | GDPR | €900 | ↗ |
| 20 Oct 2022 | Istituto di Istruzione Superiore “G. Renda” di Polistena, Reggio CalabriaIstituto di Istruzione Superiore “G. Renda” was fined EUR 900 by the Garante for unlawfully processing personal data. The school published sensitive information about an employee’s contract termination without a legal basis, breaching GDPR principles of lawfulness, fairness, and transparency. | IT | Garante | GDPR | €900 | ↗ |
| 25 Jun 2024 | RIVENDELL TECHNOLOGY, S.L.RIVENDELL TECHNOLOGY, S.L. failed to properly handle a data subject access request, which constitutes a breach of Article 15 GDPR. The company was fined for not complying with the data protection authority's resolution. | ES | AEPD | GDPR | €900 | ↗ |
| 06 Mar 2025 | AVENTURA EN TRAMPOLINES S.L.AVENTURA EN TRAMPOLINES S.L. was fined 900 EUR by the AEPD for failing to comply with data protection authority resolutions. The case concerned Article 58(2) GDPR, which requires cooperation with the supervisory authority. | ES | AEPD | GDPR | €900 | ↗ |