BULLETIN №084Last updated · 12 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 28 May 2026 | Action Fit di MilanoThe Garante fined Action Fit di Milano EUR 3,930 for sending unsolicited commercial emails to a customer without consent. The authority found this to be a breach of data protection rules. | IT | Garante | GDPR | €3,930 | ↗ |
| 29 Apr 2016 | ACROSS SRLACROSS SRL was fined by the AEPD in the amount of 1,500 EUR for sending unsolicited commercial emails without proper consent. The case concerned Article 21.1 of the LSSI and indicates a lack of a valid legal basis for direct marketing. | ES | AEPD | ePrivacy | €1,500 | ↗ |
| 24 Sept 2015 | Acquapark di Milillo Rosa & C. s.a.s.Acquapark di Milillo Rosa & C. s.a.s. was fined EUR 6,400 by the Garante for collecting personal data without providing the required information notice and for publishing user photos without consent. The case concerns failures to meet transparency obligations and lawful processing requirements. | IT | Garante | GDPR | €6,400 | ↗ |
| 21 Jul 2022 | Acqua Novara.VCO S.p.a.Acqua Novara.VCO S.p.a. was fined EUR 20,000 by the Garante for breaches related to the processing of personal data. The case concerned confidentiality and the risks arising from handling sensitive data in a workplace context. | IT | Garante | GDPR | €20,000 | ↗ |
| 09 Aug 2021 | ACONCAGUA JUEGOS S.A.ACONCAGUA JUEGOS S.A. was fined by the AEPD 10,000 EUR for failing to appoint a Data Protection Officer. The authority also found that the company did not address a data subject’s erasure request within the legal deadline. | ES | AEPD | GDPR | €10,000 | ↗ |
| 01 Jan 2022 | ACKERMANN & SCHWARTZ ATTORNEYS AT LAW SLP.The company was fined by the AEPD EUR 10,000 for processing personal data without consent. The authority also found that its website privacy information was insufficient, including missing contact details and information on data subject rights. | ES | AEPD | GDPR | €10,000 | ↗ |
| 26 Oct 2023 | A.C. Group S.r.l.s.A.C. Group S.r.l.s. was fined by the Garante 10,000 EUR for making an unsolicited marketing call to a number listed in the Public Register of Objections without prior informed consent. The authority also found that the company failed to adequately respond to a data subject rights request. | IT | Garante | GDPR | €10,000 | ↗ |
| 21 Jun 2018 | Acentro s.r.l.Acentro s.r.l. was fined EUR 10,000 by the Garante for failing to appoint data processors and provide them with the necessary instructions. The case concerns non-compliance with data protection obligations. | IT | Garante | GDPR | €10,000 | ↗ |
| 06 Jul 2023 | AcegasApsAmga S.p.A.AcegasApsAmga S.p.A. was fined €10,000 by the Italian supervisory authority, Garante. The sanction concerned the company’s failure to respond to a data subject’s request for access to personal data, in breach of GDPR Article 15. | IT | Garante | GDPR | €10,000 | ↗ |
| 12 Feb 2026 | Acea Energia S.p.A.Acea Energia S.p.A. was fined by the Garante 2,000,000 EUR for processing inaccurate and outdated personal data of customers. This led to the activation of unsolicited energy supply contracts, indicating significant deficiencies in data quality controls. | IT | Garante | GDPR | €2,000,000 | ↗ |
| 10 Apr 2025 | Acea EnergiaAcea Energia was fined EUR 3,000,000 by the Garante. The authority found unauthorized telemarketing activities and insufficient protection of databases against access by unauthorized agents. | IT | Garante | GDPR | €3,000,000 | ↗ |
| 21 Oct 2014 | ACDACD was fined by the HDPA 1,000 EUR for sending unsolicited marketing emails without the recipients’ consent. This breached Article 11 of Law 3471/2006. | GR | HDPA | ePrivacy | €1,000 | ↗ |
| 10 Jun 2025 | Accounting Audit SRLAccounting Audit SRL was fined by ANSPDCP for a data security breach caused by a cyber attack. The incident led to unauthorized disclosure of personal data, including identification data and financial documents, affecting a large number of data subjects, mainly employees of the company’s clients. | RO | ANSPDCP | GDPR | €10,000 | ↗ |
| 16 May 2025 | ACCOUNTING & AUDIT CONSULTING SRLACCOUNTING & AUDIT CONSULTING SRL was fined by ANSPDCP €5,000 for GDPR violations. The investigation was completed in April 2025, and the decision was issued on 16 May 2025. | RO | ANSPDCP | GDPR | €5,000 | ↗ |
| 07 Feb 2024 | Account Exchange SRLAccount Exchange SRL was fined EUR 2,000 by ANSPDCP for violating GDPR provisions related to data processing. The case concerned non-compliant processing of personal data. | RO | ANSPDCP | GDPR | €2,000 | ↗ |
| 19 Dec 2024 | ACCES AUX SOINS (procédure simplifiée)The CNIL imposed an administrative fine of EUR 5,000 on ACCES AUX SOINS under a simplified procedure. The case concerns a breach of rules supervised by the CNIL. | FR | CNIL | GDPR | €5,000 | ↗ |
| 16 Sept 2021 | Accademia di Belle Arti di RomaAccademia di Belle Arti di Roma was fined EUR 5,000 by the Garante for breaching data protection principles. The case involved improper handling of personal data in a disciplinary procedure and the dissemination of sensitive information. | IT | Garante | GDPR | €5,000 | ↗ |
| 18 May 2016 | Accademia Dante Alighieri s.r.l.Accademia Dante Alighieri s.r.l. was fined by the Garante 2,400 EUR for collecting personal data from users through its websites without providing the required information or obtaining consent. The conduct breached Articles 13 and 23 of the Italian Data Protection Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 30 Mar 2017 | Acantho s.p.a.Acantho s.p.a. was fined by the Garante in the amount of EUR 30,000 for retaining telephone and telematic traffic data longer than legally permitted. The authority found this to be a breach of data protection rules. | IT | Garante | GDPR | €30,000 | ↗ |
| 05 May 2022 | ABUNTIA SERVICES, S.L.ABUNTIA SERVICES, S.L. was fined by the AEPD EUR 1,500 for sending commercial SMS messages without prior consent from recipients. The authority found this breached Article 21 of the LSSI on unsolicited commercial communications. | ES | AEPD | ePrivacy | €1,500 | ↗ |