BULLETIN №083Last updated · 10 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.1%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 31 Mar 2022 | Anonymised (CyDPC Απόφαση για λειτουργία ΚΚΒΠ.pd)The case concerned the unlawful installation and operation of a CCTV system in a shared waiting area of a pediatric and dental clinic. A fine of EUR 1,500 was imposed for failure to cooperate with the supervisory authority under GDPR Article 31. | CY | CyDPC | GDPR | €1,500 | ↗ |
| 03 Feb 2022 | Κοινοτικό Συμβούλιο ΒορόκληνηςThe Community Council of Voroklini was fined by the CyDPC for failing to exercise due diligence in the processing of personal data. This led to unauthorized changes to mailing addresses without proper consent. | CY | CyDPC | GDPR | €2,000 | ↗ |
| 07 Dec 2023 | Anonymised (CyDPC ΑΠΟΦΑΣΗ ΓεΣΥ 77.pdf)A doctor accessed a patient's health records in the General Health System (GHS) without proper authorization or referral. The authority found this breached GDPR principles of lawful and transparent processing of personal data. | CY | CyDPC | GDPR | €1,500 | ↗ |
| 03 Feb 2023 | Epic LtdEpic Ltd was fined by the CyDPC in the amount of 3,250 EUR for making unsolicited calls to former customers without a legal basis. The authority also found insufficient technical and organizational measures to ensure compliant data processing and inadequate data security controls. | CY | CyDPC | GDPR | €3,250 | ↗ |
| 17 Sept 2021 | Mediterranean Hospital of CyprusMediterranean Hospital of Cyprus was fined 10,000 EUR by the CyDPC for failing to comply with a data access request. The authority also found a lack of cooperation with the supervisory authority, constituting a breach of Article 31 GDPR. | CY | CyDPC | GDPR | €10,000 | ↗ |
| 16 Jan 2023 | Εκδόσεις Αρκτίνος ΛτδThe decision concerns the unlawful publication of names and photos of police investigators by the newspaper “Politis”. The authority found a breach of the data minimization principle under the GDPR. | CY | CyDPC | GDPR | €10,000 | ↗ |
| 06 Sept 2019 | Anonymised (CyDPC ΑΝΟΝΥΜΟΠΟΙΗΜΕΝΗ ΑΠΟΦΑΣΗ δημοσί)A medical practice was fined EUR 14,000 for posting a patient's pre- and post-surgery images on Instagram without consent. The authority found a breach of GDPR rules on personal data processing and the protection of special-category data. | CY | CyDPC | GDPR | €14,000 | ↗ |
| 16 Jun 2025 | Υφυπουργείο Κοινωνικής ΠρόνοιαςThe Cypriot Data Protection Commissioner imposed an administrative fine of EUR 5,000 on Υφυπουργείο Κοινωνικής Πρόνοιας on 16 June 2025. The case concerned CCTV cameras at the ministry’s headquarters, including three cameras that recorded audio without a legal basis and without the required GDPR safeguards. | CY | Επίτροπος Προστασίας Δεδομένων Προσωπικού Χαρακτήρα | GDPR | €5,000 | ↗ |
| 17 May 2023 | Breikot Management LtdBreikot Management Ltd was fined EUR 3,000 by the CyDPC for publishing personal data, including names and photos. The authority found a breach of the data minimization principle under the GDPR. | CY | CyDPC | GDPR | €3,000 | ↗ |
| 06 Apr 2023 | К. Л. НK. L. N was fined for unlawfully processing voters' personal data. The case involved forwarding an email containing scanned voting lists to a personal email address, in breach of GDPR Article 6. | BG | CPDP | GDPR | €767 | ↗ |
| 26 Feb 2019 | телекомуникационен операторThe telecommunications operator was fined BGN 53,000 by the CPDP for processing personal data without consent. The case involved changing a subscription plan to a prepaid service without the data subject's knowledge or agreement. | BG | CPDP | GDPR | €27,099 | ↗ |
| 18 Oct 2019 | National Revenue Agency (Bulgaria)The Commission for Personal Data Protection imposed a fine of 5,100,000 BGN on Bulgaria’s National Revenue Agency. The sanction concerned the unauthorized disclosure and dissemination of personal data following a major security breach. | BG | Commission for Personal Data Protection | GDPR | €2,607,000 | ↗ |
| 26 Mar 2019 | А.Р. ЕООДThe CPDP imposed a 10,000 BGN fine on А.Р. ЕООД for processing personal data without consent. The case also involved registering an employment contract for an imprisoned individual, which breached Article 6 GDPR. | BG | CPDP | GDPR | €5,113 | ↗ |
| 24 Jul 2019 | НОИThe National Social Security Institute (НОИ) was fined for failing to implement adequate technical and organizational measures to prevent employees from accessing personal data without authorization. The authority found this to be a breach of GDPR Article 25. | BG | CPDP | GDPR | €2,557 | ↗ |
| 26 Jan 2023 | Политическа партия ******The political party unlawfully processed personal data by including individuals in a list supporting its election registration without their consent. The authority found breaches of GDPR Articles 5, 6, and 24. | BG | CPDP | GDPR | €7,823 | ↗ |
| 06 Jan 2020 | дружество за комунални услугиThe utility company processed the complainant’s personal data without a lawful basis by sharing it with a private bailiff for enforcement proceedings. CPDP imposed a fine of 10,000 BGN for breaching Article 6 GDPR. | BG | CPDP | GDPR | €5,113 | ↗ |
| 12 Feb 2018 | Анонимизирано (CPDP решение-по-жалба-с-рег-№-ж-453-05-10-201)The Commission fined an individual for unlawfully processing personal data by including it in a list supporting registration for a referendum campaign without consent. The case concerned a breach of the legal basis requirements for personal data processing. | BG | CPDP | GDPR | €5,113 | ↗ |
| 26 Oct 2021 | ЧСИ2The Commission fined the private bailiff ЧСИ2 for unlawfully processing personal data by accessing bank account information after the enforcement proceeding had ended. The authority found a breach of the purpose limitation principle under Article 5 GDPR. | BG | CPDP | GDPR | €383 | ↗ |
| 08 Oct 2019 | Министър на вътрешните работиThe Ministry of Interior was fined for unlawfully processing and sharing the personal data of a Finnish citizen with Togo authorities without a legal basis. The authority found a breach of GDPR principles on lawful processing and data disclosure. | BG | CPDP | GDPR | €5,113 | ↗ |
| 07 Oct 2019 | Анонимизирано (CPDP решение-по-жалба-с-рег-№-ппн-01-657-08-0)The Bulgarian data protection authority, CPDP, fined an individual, V.M., BGN 1,000. The sanction concerned failure to provide access to information requested by the authority in connection with a complaint about unlawful dissemination of personal data. | BG | CPDP | GDPR | €511 | ↗ |