BULLETIN №081Last updated · 27 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -20.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 19 Mar 2015 | Trust Center A.E.The company was fined for failing to adequately inform data subjects about the processing of their creditworthiness data. The authority found a breach of Article 11 of the Greek data protection law. | GR | HDPA | GDPR | €3,000 | ↗ |
| 20 Mar 2017 | Eurobank Ergasias A.E.Eurobank Ergasias A.E. was fined EUR 10,000 by the HDPA. The authority found that the bank did not adequately satisfy the complainant’s right of access to recorded telephone conversations. The case concerned the legal obligation to provide access to such recordings. | GR | HDPA | GDPR | €10,000 | ↗ |
| 12 Jun 2023 | Piraeus Bank S.A.Piraeus Bank S.A. was fined by the HDPA EUR 100,000 for processing personal data without a legal basis. The breach affected a large number of data subjects, which increases its compliance significance. | GR | HDPA | GDPR | €100,000 | ↗ |
| 19 Jul 2013 | ALL THE WORLD - COSMOS ONLINEThe company was fined for sending unsolicited marketing emails without obtaining prior consent from recipients. This conduct breached ePrivacy rules governing electronic communications. | GR | HDPA | ePrivacy | €8,000 | ↗ |
| 25 Jul 2013 | Fast-typeFast-type was fined EUR 500 by the HDPA for sending unsolicited marketing emails without subscriber consent. The case concerns a failure to obtain prior consent for marketing communications. | GR | HDPA | ePrivacy | €500 | ↗ |
| 23 Jun 2025 | Piraeus Bank S.A.Piraeus Bank S.A. was fined by the HDPA 50,000 EUR for unlawfully transferring personal data to third parties without the data subject's consent. The authority found breaches of GDPR principles of lawfulness and accuracy. | GR | HDPA | GDPR | €50,000 | ↗ |
| 16 Jun 2010 | Anonymised (HDPA 29/2010)The company was fined 3,000 EUR by the HDPA for unlawfully processing email addresses without prior consent. This conduct breached Greek data protection law. | GR | HDPA | GDPR | €3,000 | ↗ |
| 08 Aug 2014 | Anonymised (HDPA 112/2014)The controller sent unsolicited marketing SMS messages without recipients' consent, breaching data protection rules. The case concerned the use of contact data for marketing without a valid legal basis. | GR | HDPA | ePrivacy | €1,000 | ↗ |
| 09 Jan 2025 | National Bank of GreeceNational Bank of Greece was fined €20,000 by the HDPA. The authority found that the bank failed to provide data subjects with timely access to their personal data, breaching GDPR Articles 15 and 12. | GR | HDPA | GDPR | €20,000 | ↗ |
| 09 Oct 2018 | CosmoteCosmote was fined EUR 150,000 by the HDPA for making unsolicited promotional calls to subscribers who had opted out of such contact. The authority found that this conduct breached privacy and personal data protection rules. | GR | HDPA | ePrivacy | €150,000 | ↗ |
| 21 Feb 2017 | MILI CAFEMILI CAFE was fined EUR 1,000 for unlawful video surveillance practices. The violations included recording audio without proper security measures and retaining footage for more than 15 days. | GR | HDPA | GDPR | €1,000 | ↗ |
| 15 Feb 2022 | Organismos Limenos Irakleiou A.E.Organismos Limenos Irakleiou A.E. was fined 30,000 EUR by the HDPA for breaching the data subject’s right of access. The company failed to provide requested video footage and incorrectly claimed that the data had been deleted. | GR | HDPA | GDPR | €30,000 | ↗ |
| 22 Sept 2022 | Anonymised (HDPA 51/2022)The fined entity did not comply with a data subject access request and did not provide any justification for failing to act on it. It also failed to inform the data subject about further processing and the transfer of their data to the police. | GR | HDPA | GDPR | €3,000 | ↗ |
| 12 Jun 2015 | ALPHA BANKALPHA BANK was fined 30,000 EUR by the HDPA. The authority found that the bank failed to notify the location and facilities used for ICAP data processing. | GR | HDPA | GDPR | €30,000 | ↗ |
| 12 Jun 2015 | Tiresias AETiresias AE was fined for failing to implement measures to control access to personal data files. This failure led to unauthorized access by ICAP. | GR | HDPA | GDPR | €30,000 | ↗ |
| 30 Mar 2023 | Vodafone-PanafonVodafone-Panafon was fined by the HDPA for failing to respond to a data subject access request concerning recorded calls. The authority also found that the company did not notify a personal data breach to the regulator. | GR | HDPA | GDPR | €40,000 | ↗ |
| 04 Sept 2025 | Owner of the studentenkotenThe Belgian Data Protection Authority (GBA) imposed a total fine of EUR 9,700 on the owner of a student house. The case concerned the unlawful use of surveillance cameras inside and around the property to monitor students. | BE | Gegevensbeschermingsautoriteit (GBA) | GDPR | €9,700 | ↗ |
| 14 May 2025 | IAB EuropeThe Gegevensbeschermingsautoriteit’s decision concerned IAB Europe and the Transparency and Consent Framework. A fine of EUR 250,000 was imposed for GDPR breaches related to the processing of personal data, and the Brussels Market Court confirmed the violations and sanctions while noting procedural grounds for annulling the original decision. | BE | Gegevensbeschermingsautoriteit (GBA) | GDPR | €250,000 | ↗ |
| 19 Jan 2023 | A startup football clubThe Belgian data protection authority, GBA, imposed an EUR 8,000 fine on a startup football club. The case involved failure to respond to a data subject access request, as well as additional GDPR breaches concerning transparency and processor-contract requirements. | BE | Gegevensbeschermingsautoriteit (GBA) | GDPR | €8,000 | ↗ |
| 28 Apr 2026 | vzwDecision on the merits No. 94/2026 of 28 April 2026 was issued by the Belgian Gegevensbeschermingsautoriteit. A Belgian vzw was fined EUR 1,000 for failing to respond to registered letters and failing to appear at the hearing, which was treated as a breach of the GDPR cooperation duty. | BE | Gegevensbeschermingsautoriteit (GBA) | GDPR | €1,000 | ↗ |