BULLETIN №084Last updated · 12 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 30 May 2018 | Alpha BankAlpha Bank was fined by the HDPA for failing to respond to a data subject access request within the prescribed timeframe. The case concerned Article 12 of Law 2472/1997 and the bank’s obligations to facilitate data subject rights. | GR | HDPA | GDPR | €10,000 | ↗ |
| 01 Jan 2022 | ALPA 57 PRODUCCIONES, S.L.ALPA 57 PRODUCCIONES, S.L. was fined by the AEPD 10,000 EUR for processing personal data without a legal basis. The company impersonated another energy provider and used personal data without consent. | ES | AEPD | GDPR | €10,000 | ↗ |
| 19 Jan 2023 | ALPA 57 PRODUCCIONES, S.L.ALPA 57 PRODUCCIONES, S.L. was fined by the AEPD 10,000 EUR for processing personal and banking data without consent. The conduct occurred in connection with a contract renewal offer presented as if it came from the complainant's electricity supplier. | ES | AEPD | GDPR | €10,000 | ↗ |
| 28 Jun 2022 | ALPA 57 PRODUCCIONES, S.L.ALPA 57 PRODUCCIONES, S.L. failed to provide the required information to the Spanish Data Protection Agency, which constitutes a breach of Article 58.1 of the GDPR. The AEPD imposed a fine of 3,000 EUR. | ES | AEPD | GDPR | €3,000 | ↗ |
| 12 Feb 2015 | Aloisio AngeloAloisio Angelo was fined EUR 25,000 by the Italian data protection authority, Garante. The case involved activating 15 phone cards in the names of 5 individuals without their knowledge, which breached data protection rules. | IT | Garante | GDPR | €25,000 | ↗ |
| 12 Mar 2026 | Almas SalonThe Garante imposed an EUR 800 fine on Almas Salon for operating a video surveillance system without proper compliance with data protection rules. The case concerns a breach of GDPR Article 5, indicating failure to meet core data processing principles. | IT | Garante | GDPR | €800 | ↗ |
| 18 Mar 2010 | Alma s.r.l.Alma s.r.l. was fined by the Italian data protection authority, Garante, in the amount of 10,000 EUR. The case concerned the processing of personal data without the notification required under the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 19 Jul 2013 | ALL THE WORLD - COSMOS ONLINEThe company was fined for sending unsolicited marketing emails without obtaining prior consent from recipients. This conduct breached ePrivacy rules governing electronic communications. | GR | HDPA | ePrivacy | €8,000 | ↗ |
| 26 Jan 2024 | Allium UPI OÜEstonia’s Data Protection Inspectorate fined Allium UPI OÜ, operator of the Apotheka loyalty program, 3 million euros. The authority found that the company failed to protect customer data and used inadequate security measures, exposing the data of more than 750,000 people. | EE | Andmekaitse Inspektsioon | GDPR | €3,000,000 | ↗ |
| 25 Apr 2024 | ALL IN DIGITAL MARKETING, S.L.ALL IN DIGITAL MARKETING, S.L. was fined by the AEPD EUR 3,000 for sending unsolicited commercial emails without prior consent from recipients. The authority found this conduct to be in breach of Article 21 of the LSSI. | ES | AEPD | ePrivacy | €3,000 | ↗ |
| 14 Feb 2024 | ALL IN DIGITAL MARKETING SLALL IN DIGITAL MARKETING SL was fined by the AEPD €5,000 for continuing to send commercial emails despite repeated requests to unsubscribe. The authority found this conduct breached Article 21 of the LSSI. | ES | AEPD | ePrivacy | €5,000 | ↗ |
| 03 Oct 2024 | ALL IN DIGITAL MARKETING SLALL IN DIGITAL MARKETING SL was fined EUR 5,000 by the AEPD for continuing to send marketing emails despite the recipient's unsubscribe requests. The authority found a breach of Article 21 of the LSSI. | ES | AEPD | ePrivacy | €5,000 | ↗ |
| 01 Jan 2024 | ALLIANZ COMPAÑÍA DE SEGUROS Y REASEGUROS, S.A.ALLIANZ COMPAÑÍA DE SEGUROS Y REASEGUROS, S.A. was fined by the AEPD EUR 140,000 for unauthorized access to personal data. The authority found a breach of GDPR confidentiality and security principles. | ES | AEPD | GDPR | €140,000 | ↗ |
| 24 Mar 2021 | ALLIANZ COMPAÑIA DE SEGUROS Y REASEGUROS, S.A.ALLIANZ COMPAÑIA DE SEGUROS Y REASEGUROS, S.A. was fined EUR 30,000 by the AEPD. The authority found that after a policy was canceled, the company continued processing personal data without a lawful basis, in breach of Article 6 GDPR. | ES | AEPD | GDPR | €30,000 | ↗ |
| 11 Jun 2015 | Allevi BortoloAllevi Bortolo was fined EUR 15,000 by the Garante for activating fourteen phone cards in the names of five individuals without their knowledge. The conduct breached data protection rules and led to supervisory enforcement. | IT | Garante | GDPR | €15,000 | ↗ |
| 01 Jan 2013 | ALLCUPONE ESPAÑA S.L.ALLCUPONE ESPAÑA S.L. was fined by the AEPD in the amount of 600 EUR for sending unsolicited commercial emails. This conduct breached Article 21 of Spain’s LSSI, which restricts marketing communications without prior consent. | ES | AEPD | ePrivacy | €600 | ↗ |
| 15 Jan 2026 | Allay Claims Ltd The ICO issued an MPN and EN to Allay Claims Ltd after a large volume of unsolicited SMS messages promoting PPI tax refund services. The case indicates a breach of direct marketing and electronic communications rules. | GB | ICO | GDPR | €138,000 | ↗ |
| 23 May 2019 | Alkotmányjogi panasz elbírálása a NAIH/2019/1189/11. sz. ügyben (IV/1561/2020.)The controller did not comply with a data subject access request under the GDPR. NAIH imposed a fine of HUF 300,000 for unlawful data processing. | HU | NAIH | GDPR | €918 | ↗ |
| 15 Jan 2018 | Alkis Alqi Zarbala ZarballaA fine was imposed for operating a video surveillance system without the required notification and for monitoring employee workspaces. These actions breached data protection rules. | GR | HDPA | GDPR | €1,000 | ↗ |
| 12 Apr 2012 | Alitalia – Compagnia Aerea Italiana s.p.a.Alitalia was fined by the Garante for inadequate data protection measures and for failing to provide proper information to customers during call center interactions. The authority found that these practices breached Italian data protection law. | IT | Garante | GDPR | €120,000 | ↗ |