BULLETIN №081Last updated · 27 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -20.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 16 Jun 2015 | Eurobank Ergasias AEA fine was imposed for failing to maintain appropriate organizational and technical security measures. This led to unauthorized employee access to the complainant's personal data. | GR | HDPA | GDPR | €5,000 | ↗ |
| 08 Aug 2014 | RANNER ETAIREIA SYLLOGIS KAI DIACHEIRISIS PLIROFORION E.P.E.RANNER ETAIREIA SYLLOGIS KAI DIACHEIRISIS PLIROFORION E.P.E. was fined by the HDPA in the amount of EUR 3,000. The authority found processing of personal data without consent and the sending of unsolicited electronic messages for marketing purposes. | GR | HDPA | GDPR | €3,000 | ↗ |
| 23 Nov 2023 | Alpha BankAlpha Bank was fined for failing to satisfy the complainant’s request for access to personal data. The authority found breaches of GDPR Articles 15 and 5. | GR | HDPA | GDPR | €10,000 | ↗ |
| 04 Apr 2022 | Anonymised (HDPA 15/2022)The former mayor disclosed a municipal employee’s personal data without consent or a lawful basis. The authority found this to be a breach of GDPR principles of lawfulness and purpose limitation. | GR | HDPA | GDPR | €5,000 | ↗ |
| 05 Jan 2022 | Egnatia Odos S.A.Egnatia Odos S.A. was fined by the HDPA EUR 1,000 for failing to provide the complainant with access to personal data related to a toll violation. The authority found a breach of the right of access under the GDPR. | GR | HDPA | GDPR | €1,000 | ↗ |
| 13 May 2015 | HellastatHellastat was fined by the HDPA EUR 5,000 for the illegal collection and use of data. The case concerned a breach of data protection laws. | GR | HDPA | GDPR | €5,000 | ↗ |
| 10 Jun 2021 | MARIA & DESPOINA KOUSATHANA O.E.The company was fined by the HDPA 5,000 EUR for operating a video surveillance system without proper notification and for unlawful camera use in kitchen areas. The authority also found that data subjects were not informed about the processing of their personal data. | GR | HDPA | GDPR | €5,000 | ↗ |
| 12 Jun 2023 | Piraeus Bank S.A.Piraeus Bank S.A. was fined by the HDPA in the amount of 100,000 EUR for failing to implement appropriate technical and organizational measures. The authority found that the bank did not ensure data protection by design and by default. | GR | HDPA | GDPR | €100,000 | ↗ |
| 08 Aug 2014 | INFOASSIST A.E.INFOASSIST A.E. was fined by the HDPA 7,500 EUR for processing personal data without consent. The authority found breaches of legality and data minimization principles. | GR | HDPA | GDPR | €7,500 | ↗ |
| 22 May 2012 | Municipal Water and Sewerage Company of RhodesThe Municipal Water and Sewerage Company of Rhodes was fined 5,000 EUR by the HDPA. The authority found that the company failed to satisfy the complainant’s data access rights and did not respond within the mandatory 15-day period. | GR | HDPA | GDPR | €5,000 | ↗ |
| 08 Aug 2014 | Hummingbird EPEHummingbird EPE was fined by the HDPA for processing publicly available personal data without the consent of the data subjects. The authority found a breach of the principles of data relevance and proportionality. | GR | HDPA | GDPR | €7,500 | ↗ |
| 27 Sept 2022 | Anonymised (HDPA 18/2022)A fine was imposed for sending unsolicited political communication via SMS without prior consent. The case concerns a breach of consent requirements for political and marketing communications. | GR | HDPA | ePrivacy | €2,000 | ↗ |
| 27 Jun 2024 | METRO AEBEThe supervisory authority found that the company did not properly investigate and notify a personal data breach. It also failed to comply with data subject requests for access and erasure. | GR | HDPA | GDPR | €20,000 | ↗ |
| 09 May 2018 | Sioufas and Partners Law FirmThe law firm was fined for operating a video surveillance system that covered workspaces without proper justification. It also failed to notify the authority in a timely manner and did not inform individuals about the surveillance, breaching several provisions of Greek data protection law. | GR | HDPA | GDPR | €50,000 | ↗ |
| 24 Jun 2025 | I ASPIDA TOU DAVIDThe entity did not inform data subjects about the processing of their personal data. The authority treated this as a GDPR breach and imposed a monetary fine. | GR | HDPA | GDPR | €3,000 | ↗ |
| 25 Jul 2013 | Fast-typeThe HDPA imposed a fine of EUR 1,000 on Fast-type for the illegal collection and further processing of personal data. The case concerns a breach of core data processing legality requirements. | GR | HDPA | GDPR | €1,000 | ↗ |
| 03 Sept 2014 | Anonymised (HDPA 119/2014)A fine was imposed for the unlawful collection and processing of personal data, including email addresses, and for sending unsolicited marketing emails without subscriber consent. The case concerns breaches of lawful processing requirements and the need for prior consent for marketing communications. | GR | HDPA | ePrivacy | €4,000 | ↗ |
| 09 Oct 2018 | WIND HELLAS TELECOMMUNICATIONS S.A.The fine was imposed for making unsolicited marketing calls to subscribers who had opted out of such contact. This conduct breached privacy and data protection rules. | GR | HDPA | ePrivacy | €150,000 | ↗ |
| 08 Aug 2014 | Anonymised (HDPA 115/2014)The controller was fined for processing personal data without consent and for sending unsolicited marketing messages. The case indicates breaches of core data protection and marketing communication obligations. | GR | HDPA | ePrivacy | €1,500 | ↗ |
| 16 Feb 2024 | Anonymised (HDPA 6/2024)The company was fined 2,000 EUR by the HDPA for unlawful processing of personal data. It used vehicle tracking data outside working hours to locate an employee. | GR | HDPA | GDPR | €2,000 | ↗ |