BULLETIN №081Last updated · 27 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -20.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 05 Aug 2016 | LinguaphoneLinguaphone was fined 25,000 EUR by the Greek HDPA for sending unsolicited marketing emails without prior recipient consent. The conduct breached Article 11 of Law 3471/2006. | GR | HDPA | ePrivacy | €25,000 | ↗ |
| 21 Jul 2025 | VIVLIOPOLEION TIS ESTIAS, I.D. KOLLAROU & SIA A.E.The company was fined by the HDPA 3,000 EUR for failing to implement appropriate technical and organizational measures to secure personal data. The deficiency resulted in unauthorized disclosure of personal data. | GR | HDPA | GDPR | €3,000 | ↗ |
| 24 Jun 2025 | I ASPIDA TOU DAVIDThe entity failed to provide the required information and to implement adequate data protection measures. HDPA imposed a fine of EUR 3,000 for breach of GDPR principles. | GR | HDPA | GDPR | €3,000 | ↗ |
| 21 Aug 2018 | Eurobank Ergasias A.E.Eurobank Ergasias A.E. was fined by the HDPA in the amount of 5,000 EUR for failing to maintain and process accurate data of its debtors. The authority found that the company’s handling of debtor information breached data protection requirements. | GR | HDPA | GDPR | €5,000 | ↗ |
| 04 May 2015 | CitibankThe HDPA imposed a fine of EUR 8,000 on Citibank for unlawful processing of the complainant’s creditworthiness data. The case concerned a breach of the rules governing lawful processing of personal data. | GR | HDPA | GDPR | €8,000 | ↗ |
| 12 Sept 2017 | Little Kook - K. Tzortzis – I. Thanos I.K.EThe company was fined EUR 7,000 by the HDPA for operating a video surveillance system without proper notification to the authority. It also monitored employee workspaces, which breached privacy requirements. | GR | HDPA | GDPR | €7,000 | ↗ |
| 12 May 2017 | Strategy MentorThe fine was imposed for sending unsolicited marketing emails to a large number of recipients without prior consent. This conduct breached ePrivacy rules governing electronic marketing communications. | GR | HDPA | ePrivacy | €75,000 | ↗ |
| 26 Feb 2015 | Anonymised (HDPA 26/2015)The company was fined for unlawful collection and processing of personal data, and for sending unsolicited marketing emails without recipients’ consent. The case concerns breaches of core data protection principles and the requirement to obtain prior consent for marketing communications. | GR | HDPA | ePrivacy | €1,000 | ↗ |
| 22 Jun 2017 | Bolos & SynergatesThe law firm Bolos & Synergates was fined EUR 1,000 by the HDPA for unlawfully collecting and using personal data for direct marketing. The violation involved unsolicited electronic communications sent without prior consent from the data subjects. | GR | HDPA | ePrivacy | €1,000 | ↗ |
| 06 Sept 2013 | Groupon Greece Monoprosopi Etaireia Periorismenis EfthynisGroupon Greece was fined by the HDPA for failing to inform customers that their credit card data was stored by a third party. The authority found this to be a breach of data protection law. | GR | HDPA | ePrivacy | €1,500 | ↗ |
| 14 Jul 2021 | Anonymised (HDPA 31/2021)The fined individual unlawfully obtained and processed personal data from the complainant's personnel file. The data came from an unauthorized source and were used in a complaint against the complainant, in breach of data protection rules. | GR | HDPA | GDPR | €2,000 | ↗ |
| 11 Jul 2025 | NN HellasNN Hellas was fined EUR 20,000 for failing to satisfy the complainant’s access request concerning recorded telephone conversations. The authority found a violation of Article 15 GDPR. | GR | HDPA | GDPR | €20,000 | ↗ |
| 26 May 2014 | General Hospital PapageorgiouGeneral Hospital Papageorgiou was fined EUR 1,000 by the HDPA for transferring sensitive health data without prior authorization. The hospital also failed to inform the data subject, breaching Greek data protection law. | GR | HDPA | GDPR | €1,000 | ↗ |
| 09 Oct 2018 | Vodafone-PanafonVodafone-Panafon was fined by the HDPA for making unsolicited marketing calls to subscribers who had opted out of such contact. The authority found that the conduct breached privacy and data protection rules. | GR | HDPA | ePrivacy | €12,000 | ↗ |
| 08 Jan 2015 | OTEThe Hellenic Data Protection Authority fined OTE EUR 60,000 for failing to implement adequate security measures. The deficiency led to a data breach involving personal data of a large number of subscribers. | GR | HDPA | ePrivacy | €60,000 | ↗ |
| 07 Jul 2015 | OLYMPION XENODOXEION AEThe company was fined by the HDPA EUR 5,000 for failing to implement appropriate organizational and technical security measures. The deficiency led to a data breach involving credit card information. | GR | HDPA | GDPR | €5,000 | ↗ |
| 07 Apr 2021 | Ignatiadis Nikolaos and SIA E.E.The company was fined for unlawfully using a surveillance camera to monitor employees. The authority found a breach of data protection principles and an absence of a valid legal basis for processing. | GR | HDPA | GDPR | €2,000 | ↗ |
| 08 Aug 2014 | PARAMOUNT A.E.The company was fined EUR 5,000 by the HDPA for processing publicly available personal data without consent. The authority found a breach of the principles of lawful data collection and proportionality. | GR | HDPA | GDPR | €5,000 | ↗ |
| 13 Jun 2025 | Anonymised (HDPA 21/2025)A fine of EUR 1,000 was imposed for violating the data subject’s right of access. The entity did not provide the requested video footage. | GR | HDPA | GDPR | €1,000 | ↗ |
| 11 Jul 2025 | MEDIADENTMEDIADENT was fined for failing to cooperate with the supervisory authority. The case concerned Article 31 GDPR, which requires controllers and processors to cooperate with the authority during its work. | GR | HDPA | GDPR | €2,000 | ↗ |