BULLETIN №081Last updated · 27 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -20.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 05 Feb 2026 | MÉDECIN (procédure simplifiée)The CNIL imposed EUR 1,000 on MÉDECIN (simplified procedure) as a liquidation of an astreinte. The case concerns compliance with a prior obligation set by the supervisory authority. | FR | CNIL | GDPR | €1,000 | ↗ |
| 02 Feb 2023 | TRACTAMENT D'AIGUES TEIA, S.L.TRACTAMENT D'AIGUES TEIA, S.L. was fined by the AEPD EUR 1,000 for failing to comply with a data subject's request to delete personal data. The case indicates non-compliance with GDPR obligations regarding the exercise of individual rights. | ES | AEPD | GDPR | €1,000 | ↗ |
| 16 Dec 2021 | 1000 Luci Round a BarThe establishment 1000 Luci Round a Bar was fined EUR 1,000 by the Italian authority Garante. The sanction concerned a video surveillance system that did not meet the information requirements of Article 13 GDPR. | IT | Garante | GDPR | €1,000 | ↗ |
| 17 Jan 2019 | Учебно заведениеThe school was fined 1,000 BGN by the CPDP for unlawfully processing students' personal data. It shared the data with a financial institution without proper consent, which breached GDPR requirements. | BG | CPDP | GDPR | €511 | ↗ |
| 08 Aug 2014 | Anonymised (HDPA 112/2014)The controller sent unsolicited marketing SMS messages without recipients' consent, breaching data protection rules. The case concerned the use of contact data for marketing without a valid legal basis. | GR | HDPA | ePrivacy | €1,000 | ↗ |
| 25 Mar 2025 | B.B.B.B.B.B. was fined EUR 1,000 by the AEPD for lacking an adequate data processing protocol. The authority also found that individuals were not properly informed about the processing of their personal data, in breach of GDPR Articles 5(1)(c) and 13. | ES | AEPD | GDPR | €1,000 | ↗ |
| 15 Sept 2022 | HOTEL VILLA SORO, S.L.The company was fined by the AEPD EUR 1,000 for installing surveillance cameras that could capture public areas without proper signage. The authority considered this a breach of data protection rules. | ES | AEPD | GDPR | €1,000 | ↗ |
| 21 Feb 2017 | MILI CAFEMILI CAFE was fined EUR 1,000 for unlawful video surveillance practices. The violations included recording audio without proper security measures and retaining footage for more than 15 days. | GR | HDPA | GDPR | €1,000 | ↗ |
| 02 Jul 2020 | CENTRO INTERNACIONAL DE CRECIMIENTO LABORAL Y PROFESIONAL, S.L.The entity sent unsolicited commercial emails without the recipients’ consent. It also failed to provide a valid unsubscribe option, which breached the LSSI. | ES | AEPD | ePrivacy | €1,000 | ↗ |
| 03 May 2016 | REAL AUTOMOVIL CLUB DE ESPAÑAREAL AUTOMOVIL CLUB DE ESPAÑA was fined by the AEPD EUR 1,000 for sending unsolicited commercial emails despite the recipient's requests to unsubscribe. The authority found a breach of Article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €1,000 | ↗ |
| 01 Jan 2015 | WERBUNG INTERNET S.L.WERBUNG INTERNET S.L. was fined by the AEPD €1,000 for sending unsolicited commercial emails without prior consent. The conduct breached Article 21.1 of the LSSI on electronic marketing communications. | ES | AEPD | ePrivacy | €1,000 | ↗ |
| 05 Aug 2022 | Colosseo S.r.l.Colosseo S.r.l. was fined EUR 1,000 by the Garante for sending unsolicited promotional emails without prior recipient consent. The authority found this breached GDPR rules on lawful processing and consent. | IT | Garante | GDPR | €1,000 | ↗ |
| 15 Sept 2022 | EDITORIAL RIBADEO S.L.EDITORIAL RIBADEO S.L. was fined EUR 1,000 by the AEPD for failing to meet the information obligations under Articles 12 and 13 of the GDPR. The authority also noted non-compliance with previous data protection decisions. | ES | AEPD | GDPR | €1,000 | ↗ |
| 10 Sept 2014 | SAMPLE GESTION S.L.U.SAMPLE GESTION S.L.U. was fined by the AEPD in the amount of 1,100 EUR for sending unsolicited commercial SMS messages despite the recipient's request to opt out. This constituted a breach of Article 21.1 of the LSSI on unsolicited marketing communications. | ES | AEPD | ePrivacy | €1,100 | ↗ |
| 29 Apr 2016 | CRUZ ROJA ESPAÑOLACRUZ ROJA ESPAÑOLA was fined by the AEPD EUR 1,100 for sending unsolicited commercial emails to a recipient who had previously requested data cancellation. The authority found a breach of Article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €1,100 | ↗ |
| 01 Nov 2015 | OLYMPIA METROPOLITANA S.A.OLYMPIA METROPOLITANA S.A. was fined 1,100 EUR by the AEPD for sending commercial emails to a recipient who had already requested to unsubscribe. The authority found this conduct breached the LSSI rules on marketing communications. | ES | AEPD | ePrivacy | €1,100 | ↗ |
| 31 Mar 2015 | GRAMMATA, S.L.GRAMMATA, S.L. was fined by the AEPD 1,100 EUR for sending unsolicited advertising emails. The authority also found that the company failed to provide a functional opt-out mechanism, in breach of Article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €1,100 | ↗ |
| 14 Apr 2010 | Espectáculos InterfaceEspectáculos Interface was fined EUR 1,200 by the AEPD for sending commercial emails without prior consent from recipients. The case concerned Article 21 of the LSSI, which governs unsolicited commercial communications. | ES | AEPD | ePrivacy | €1,200 | ↗ |
| 01 Jan 2013 | IBERIA LÍNEAS AÉREAS DE ESPAÑA, SOCIEDAD ANÓNIMA OPERADORA, Sociedad UnipersonalIberia was fined by the AEPD EUR 1,200 for sending commercial emails without providing recipients with a simple and free way to opt out of further messages. The authority found a breach of Article 21.2 of the LSSI. | ES | AEPD | ePrivacy | €1,200 | ↗ |
| 29 Apr 2025 | Comune di San Francesco al CampoThe Garante imposed a fine of 1,200 EUR on Comune di San Francesco al Campo for violations related to the publication of personal data on its institutional website. The data were subsequently removed. | IT | Garante | GDPR | €1,200 | ↗ |