BULLETIN №083Last updated · 11 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.1%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 01 Aug 2012 | Spazio S s.r.l.Spazio S s.r.l. was fined by the Garante 10,400 EUR for sending unsolicited commercial emails. The authority found that the company failed to provide adequate information and did not obtain valid consent from recipients, breaching privacy rules. | IT | Garante | GDPR | €10,400 | ↗ |
| 31 Jul 2012 | MEDIASTAY SASMEDIASTAY SAS was fined 30,001 EUR by the AEPD for sending commercial emails to a user despite requests to unsubscribe. The authority found a breach of Article 21.1 of the LSSI on unsolicited electronic communications. | ES | AEPD | ePrivacy | €30,001 | ↗ |
| 27 Jul 2012 | VIPVENTA, S.L.VIPVENTA, S.L. was fined EUR 30,001 by the AEPD for sending unsolicited commercial emails to the complainant. The authority found this conduct breached Article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €30,001 | ↗ |
| 26 Jul 2012 | Comune di MilanoThe Garante fined Comune di Milano EUR 20,000 for failing to implement minimum security measures on two computer stations at a primary school. The case concerned non-compliance with data protection requirements. | IT | Garante | GDPR | €20,000 | ↗ |
| 26 Jul 2012 | Meeting s.r.l.Meeting s.r.l. was fined by the Garante in the amount of 6,000 EUR for providing inadequate information to clients. The case concerned a breach of Article 13 of the Italian Data Protection Code, which requires proper notice to data subjects. | IT | Garante | GDPR | €6,000 | ↗ |
| 19 Jul 2012 | Biodiversity S.p.A.Biodiversity S.p.A. was fined by the Garante for failing to timely notify personal data processing activities related to molecular diagnostics. The obligation arose under the Italian Privacy Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 17 Jul 2012 | FARMACIA INTERNACIONALFARMACIA INTERNACIONAL was fined by the AEPD EUR 1,800 for continuing to send electronic newsletters to a customer after the customer had unsubscribed. The authority found a breach of Article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €1,800 | ↗ |
| 13 Jul 2012 | NH HOTELES, S.A.NH HOTELES, S.A. was fined by the AEPD for sending unsolicited commercial emails to a complainant after confirming the cancellation of their personal data. The authority found a breach of Article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €33,001 | ↗ |
| 11 Jul 2012 | SOLUCIONES CORPORATIVAS IP, S.L.U.SOLUCIONES CORPORATIVAS IP, S.L.U. was fined 600 EUR by the AEPD for sending an unsolicited email. The conduct breached Article 21 of the LSSI, which restricts commercial communications without prior consent. | ES | AEPD | ePrivacy | €600 | ↗ |
| 11 Jul 2012 | Control Distribución Marketing, S.L.Control Distribución Marketing, S.L. was fined by the AEPD for sending unsolicited commercial emails. The company also failed to honor requests to stop such communications, breaching Article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €1,200 | ↗ |
| 27 Jun 2012 | OKANAOKANA was fined by the HDPA in the amount of 3,000 EUR for failing to adequately protect special-category personal data. Documents containing patients’ health data were found in trash bins, indicating a breach of data protection rules. | GR | HDPA | GDPR | €3,000 | ↗ |
| 07 Jun 2012 | HOTEL REY DON SANCHO S.A.HOTEL REY DON SANCHO S.A. was fined EUR 30,001 by the AEPD for continuing to send unsolicited commercial emails despite a request for data cancellation. The authority found a breach of Article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €30,001 | ↗ |
| 31 May 2012 | CITIBANK ESPAÑA, S.A.CITIBANK ESPAÑA, S.A. was fined by the AEPD EUR 30,001 for sending unsolicited commercial emails despite a prior request to be removed from its mailing list. The conduct breached Article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €30,001 | ↗ |
| 30 May 2012 | ESCUELA HIPICA OLIMPIA, S.L.ESCUELA HIPICA OLIMPIA, S.L. was fined by the AEPD EUR 1,200 for sending commercial emails after the individual requested deletion of personal data and cessation of advertising communications. The case concerns failure to respect the recipient’s opt-out and data erasure request. | ES | AEPD | ePrivacy | €1,200 | ↗ |
| 22 May 2012 | Municipal Water and Sewerage Company of RhodesThe Municipal Water and Sewerage Company of Rhodes was fined 5,000 EUR by the HDPA. The authority found that the company failed to satisfy the complainant’s data access rights and did not respond within the mandatory 15-day period. | GR | HDPA | GDPR | €5,000 | ↗ |
| 18 May 2012 | INATED S.L.INATED S.L. was fined by the AEPD EUR 600 for sending unsolicited commercial communications by email. This conduct breached Article 21.1 of the LSSI, which prohibits such messages without prior recipient consent. | ES | AEPD | ePrivacy | €600 | ↗ |
| 16 May 2012 | CONFORAMA ESPAÑA S.A.CONFORAMA ESPAÑA S.A. was fined by the AEPD in the amount of 3,000 EUR for sending unsolicited advertising SMS messages to customers. The conduct breached Article 21 of the LSSI on marketing communications without prior consent. | ES | AEPD | ePrivacy | €3,000 | ↗ |
| 11 May 2012 | PLEGADOS IRUÑA S.L.PLEGADOS IRUÑA S.L. was fined by the AEPD 600 EUR for sending unsolicited commercial emails. The conduct breached Article 21.1 of the LSSI, which restricts marketing communications without prior consent. | ES | AEPD | ePrivacy | €600 | ↗ |
| 12 Apr 2012 | Alitalia – Compagnia Aerea Italiana s.p.a.Alitalia was fined by the Garante for inadequate data protection measures and for failing to provide proper information to customers during call center interactions. The authority found that these practices breached Italian data protection law. | IT | Garante | GDPR | €120,000 | ↗ |
| 05 Apr 2012 | XY s.r.l.XY s.r.l. was fined by the Garante 10,400 EUR for sending unsolicited commercial communications by email despite the recipient's repeated objections. The case indicates a breach of data protection rules governing electronic marketing and respect for opt-out requests. | IT | Garante | GDPR | €10,400 | ↗ |