BULLETIN №081Last updated · 28 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -20.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 21 May 2025 | Data Diggers Market Research SRLData Diggers Market Research SRL was fined EUR 2,000 by ANSPDCP for another violation related to the processing of personal data. The case indicates non-compliance with data protection requirements and calls for a review of processing procedures. | RO | ANSPDCP | GDPR | €2,000 | ↗ |
| 19 Sept 2022 | Banca Comercială Română SAThe supervisory authority completed an investigation into Banca Comercială Română SA and found a breach of data processing security requirements. The issue was caused by a technical error in the operator’s IT application, which led to improper data processing. | RO | ANSPDCP | GDPR | €2,000 | ↗ |
| 11 Jan 2024 | Provincia di SassariThe Garante imposed a fine of 2,000 EUR on Provincia di Sassari for breaches of data protection obligations under Article 37 GDPR. The case concerned failure to comply with requirements related to the designation of a data protection officer. | IT | Garante | GDPR | €2,000 | ↗ |
| 12 Mar 2026 | Comune di SutriComune di Sutri was fined EUR 2,000 by the Garante for publishing personal data on its institutional website. The case concerns a breach of data protection rules in the public online disclosure of information. | IT | Garante | GDPR | €2,000 | ↗ |
| 06 Mar 2025 | SERVICIOS DE INTEGRACIÓN DE ANDALUCÍASERVICIOS DE INTEGRACIÓN DE ANDALUCÍA was fined €2,000 by the AEPD for adding an employee’s personal phone number to a work WhatsApp group without consent. The authority found a breach of the GDPR lawful-basis requirement under Article 6(1). | ES | AEPD | GDPR | €2,000 | ↗ |
| 20 Dec 2021 | B.B.B.A video recording showing an individual being assaulted was shared via WhatsApp without that person's consent. The AEPD found a breach of Article 6(1) GDPR. | ES | AEPD | GDPR | €2,000 | ↗ |
| 29 Sept 2021 | dott.ssa Manuela MazzoliThe Garante imposed a fine of 2,000 EUR on dott.ssa Manuela Mazzoli for breaches of data protection rules. The case concerned the processing of personal data in the healthcare sector, including the principles of lawfulness, fairness, and transparency. | IT | Garante | GDPR | €2,000 | ↗ |
| 26 Sept 2022 | FONTANORTE, S.L.FONTANORTE, S.L. was fined 2,000 EUR by the AEPD for breaching Article 32 GDPR. The company improperly disposed of documents containing personal data in public waste containers, making them accessible to third parties. | ES | AEPD | GDPR | €2,000 | ↗ |
| 01 Sept 2025 | Osnovna škola XThe school unlawfully forwarded personal data of 18 employees to the City of Y, breaching GDPR Articles 5 and 6. AZOP imposed a fine of EUR 2,000. | HR | AZOP | GDPR | €2,000 | ↗ |
| 08 Jan 2024 | VUKMAL TRADE, S.L.VUKMAL TRADE, S.L. was fined by the AEPD €2,000 for requiring an employee to use a personal mobile phone for work purposes without consent. The company also shared the employee’s personal number with other staff, breaching data protection principles. | ES | AEPD | GDPR | €2,000 | ↗ |
| 01 Mar 2022 | PREICO JURÍDICOS, S.L.PREICO JURÍDICOS, S.L. was fined EUR 2,000 by the AEPD for deficiencies in its cookie policy. The authority found that the website did not provide the required information or obtain consent for storing and accessing data, in breach of Article 22.2 of the LSSI. | ES | AEPD | ePrivacy | €2,000 | ↗ |
| 01 Mar 2021 | COMUNIDAD DE PROPIETARIOS ***DIRECCIÓN.1The entity was fined EUR 2,000 by the AEPD for installing cameras without the informed consent of the property owners' association. The conduct may have affected third-party rights and data protection obligations. | ES | AEPD | GDPR | €2,000 | ↗ |
| 20 May 2025 | TRUEBA SPORT S.L.TRUEBA SPORT S.L. was fined by the AEPD 2,000 EUR for sending an email to more than 300 recipients without hiding their email addresses. The authority found this breached data protection principles and failed to properly inform the affected individuals about data processing. | ES | AEPD | GDPR | €2,000 | ↗ |
| 12 Sept 2019 | Anonymised (CyDPC ΑΝΩΝΥΜΟΠΟΙΗΜΕΝΗ ΑΠΟΦΑΣΗ ΔΗΜΟΠΡ)A complaint was filed against an individual for using personal data without consent to contact the complainant about a property sale. The Commissioner found a breach of Article 6 GDPR and imposed a fine of EUR 2,000. | CY | CyDPC | GDPR | €2,000 | ↗ |
| 22 Jun 2023 | MIFARMA TIENDA ON-LINE, S.L.MIFARMA TIENDA ON-LINE, S.L. was fined by the AEPD €2,000 for sending commercial electronic communications after the recipient had requested that they stop. The authority found a breach of Article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €2,000 | ↗ |
| 14 Apr 2021 | ANIVERSALIA NETWORKS, S.L.ANIVERSALIA NETWORKS, S.L. was fined by the AEPD EUR 2,000 for not having a GDPR-compliant privacy policy on its website. In particular, it failed to provide contact details for exercising data subject rights. | ES | AEPD | GDPR | €2,000 | ↗ |
| 23 Apr 2024 | ALPHA BANK ROMANIA SAALPHA BANK ROMANIA SA was fined by ANSPDCP for a data security breach caused by improper management of a record system by an employee. This led to unauthorized disclosure and access to the personal data of certain clients. | RO | ANSPDCP | GDPR | €2,000 | ↗ |
| 30 May 2022 | DIGITECNIA SOLUTIONS, S.L.DIGITECNIA SOLUTIONS, S.L. was fined by the AEPD 2,000 EUR for publishing an image on its website without authorization. The authority found this to be a breach of Article 6 of the GDPR. | ES | AEPD | GDPR | €2,000 | ↗ |
| 01 Jan 2012 | THE LEADER NEWSPAPER, S.L.THE LEADER NEWSPAPER, S.L. was fined by the AEPD EUR 2,000 for sending commercial emails without prior recipient consent. The authority found this conduct breached Article 21 of the LSSI. | ES | AEPD | ePrivacy | €2,000 | ↗ |
| 28 Jul 2022 | Auto Hi-Fi System S.n.cAuto Hi-Fi System S.n.c was fined EUR 2,000 by the Garante. The surveillance camera captured public areas and private property without proper notice, breaching data protection principles. | IT | Garante | GDPR | €2,000 | ↗ |