BULLETIN №081Last updated · 28 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -20.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 05 Nov 2020 | B.B.B.The entity was fined by the AEPD EUR 2,000 for using security cameras that recorded public spaces extensively without justification. The authority found that this breached data protection principles. | ES | AEPD | GDPR | €2,000 | ↗ |
| 18 Jun 2021 | DESPACHO TEJEDOR INFANTES CONSULTORES ASESORES, S.L.The entity unlawfully disclosed personal data to a third party, breaching the confidentiality principle under GDPR. The AEPD imposed a fine of 2,000 EUR. | ES | AEPD | GDPR | €2,000 | ↗ |
| 07 Dec 2023 | Mushtaq RubinaThe Garante fined Mushtaq Rubina 2,000 EUR for operating a video surveillance system without adequate informational signage. The authority found a breach of GDPR transparency requirements toward recorded individuals. | IT | Garante | GDPR | €2,000 | ↗ |
| 17 Mar 2021 | BODY TONIC SHOP, S.L.BODY TONIC SHOP, S.L. was fined by the AEPD EUR 2,000 for processing personal data without proper consent. The authority found a breach of Article 6 of the GDPR. | ES | AEPD | GDPR | €2,000 | ↗ |
| 03 Mar 2021 | COMUNIDAD DE PROPIETARIOS R.R.R.COMUNIDAD DE PROPIETARIOS R.R.R. was fined by the AEPD EUR 2,000 for installing a surveillance camera system without the required authorization. The cameras recorded private areas, which breached privacy rules. | ES | AEPD | GDPR | €2,000 | ↗ |
| 21 Jul 2022 | Global Service s.r.l.Global Service s.r.l. was fined by the Garante EUR 2,000 for installing a video surveillance system without the required informational signage. The case concerned a breach of data protection rules and the duty to properly inform individuals under surveillance. | IT | Garante | GDPR | €2,000 | ↗ |
| 15 Jul 2022 | URBANO DIVERTIA, S.L.URBANO DIVERTIA, S.L. was fined by the AEPD 2,000 EUR for sending clients documents that contained personal data of third parties. The company also failed to include a reference to its privacy policy in corporate emails, which breached data protection requirements. | ES | AEPD | GDPR | €2,000 | ↗ |
| 10 Jun 2024 | KAFFA KOFFEE ORGANISATION, S.L.KAFFA KOFFEE ORGANISATION, S.L. was fined by the AEPD EUR 2,000 for sending an email to more than 400 recipients without using BCC. This exposed other recipients’ email addresses and breached GDPR Articles 5(1)(f) and 32. | ES | AEPD | GDPR | €2,000 | ↗ |
| 11 Jan 2021 | RIPOBRUNA 2007, S.L.RIPOBRUNA 2007, S.L. was fined by the AEPD 2,000 EUR for installing surveillance cameras directed toward public spaces without justified cause. The authority found this processing to be contrary to data protection principles. | ES | AEPD | GDPR | €2,000 | ↗ |
| 01 Jan 2021 | INMARÁN ASESORES, S.L.INMARÁN ASESORES, S.L. was fined 2,000 EUR by the AEPD for recording telephone conversations without informing the data subject or obtaining consent. The authority found this to be a breach of the GDPR information obligations. | ES | AEPD | GDPR | €2,000 | ↗ |
| 22 Jun 2023 | Futuro Molise S.r.l.Futuro Molise S.r.l. was fined EUR 2,000 by the Garante for publishing an article that contained personal data without demonstrating a public interest basis. The authority found a breach of data protection rules. | IT | Garante | GDPR | €2,000 | ↗ |
| 03 Apr 2023 | Banca Transilvania SABanca Transilvania SA was fined EUR 2,000 by ANSPDCP for a GDPR breach. The case concerned improperly restricting access to an account in the mobile banking application despite the client's explicit request. | RO | ANSPDCP | GDPR | €2,000 | ↗ |
| 17 Apr 2026 | Pak StorePak Store was fined EUR 2,000 by the Garante for using a CCTV camera without the required signage and without the necessary authorization from the Labour Inspectorate. The authority found a breach of the information obligations under GDPR Article 13. | IT | Garante | GDPR | €2,000 | ↗ |
| 12 Feb 2026 | Provvedimento del 12 febbraio 2026 [10225084]The Garante fined a retail business for failing to provide adequate informational signage for its video surveillance system. The authority found a breach of data protection rules because individuals on the premises were not properly informed about the processing of their personal data. | IT | Garante | GDPR | €2,000 | ↗ |
| 06 Aug 2025 | GOHIPOTECA, S.L.GOHIPOTECA, S.L. processed personal data without consent, using an individual's data to apply for a mortgage without authorization. The AEPD imposed a fine of EUR 2,000 for this violation. | ES | AEPD | GDPR | €2,000 | ↗ |
| 06 Mar 2025 | SHOPBAG GROUP ONLINE SRLSHOPBAG GROUP ONLINE SRL was fined EUR 2,000 by ANSPDCP. The authority found that the company failed to provide information requested for the performance of its supervisory tasks. | RO | ANSPDCP | GDPR | €2,000 | ↗ |
| 09 Jul 2020 | Istituto Comprensivo Statale Crucoli TorrettaIstituto Comprensivo Statale Crucoli Torretta was fined EUR 2,000 by the Garante for unlawfully publishing a list of students on its institutional website. The authority found breaches of lawfulness, fairness, transparency, and data minimization. | IT | Garante | GDPR | €2,000 | ↗ |
| 07 Jul 2023 | THE COMAKING SPACE, S.L.U.THE COMAKING SPACE, S.L.U. was fined by the AEPD EUR 2,000 for sending unsolicited commercial emails without recipient consent. The conduct breached the LSSI rules on electronic marketing communications. | ES | AEPD | ePrivacy | €2,000 | ↗ |
| 26 Mar 2026 | Provvedimento del 26 marzo 2026 [10246060]The entity was fined for operating a video surveillance system without providing adequate informational signage. The authority found this to be a breach of GDPR Article 13 on the duty to inform data subjects. | IT | Garante | GDPR | €2,000 | ↗ |
| 04 Aug 2017 | STAPLES PRODUCTOS DE OFICINA S.L.U.STAPLES PRODUCTOS DE OFICINA S.L.U. was fined EUR 2,000 by the AEPD for sending unsolicited commercial emails. The breach involved continuing to contact recipients despite requests to cancel consent. | ES | AEPD | ePrivacy | €2,000 | ↗ |