BULLETIN №081Last updated · 28 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -20.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 09 Sept 2022 | COMUNIDAD DE PROPIETARIOS R.R.R.COMUNIDAD DE PROPIETARIOS R.R.R. was fined by the AEPD 2,000 EUR for unauthorized access to and dissemination of video surveillance recordings. The case concerns a breach of data protection rules. | ES | AEPD | GDPR | €2,000 | ↗ |
| 20 Feb 2025 | Medstar S.R.L.Medstar S.R.L. was fined by ANSPDCP for failing to notify the data breach to the supervisory authority. The company also did not inform the affected individuals about the unauthorized disclosure of their personal data. | RO | ANSPDCP | GDPR | €2,000 | ↗ |
| 01 Jan 2021 | RECLAMADOR, S.L.RECLAMADOR, S.L. was fined €2,000 by the AEPD for sending a commercial electronic communication after the recipient had exercised the right to erasure. The authority found this conduct breached GDPR and LSSI requirements. | ES | AEPD | GDPR | €2,000 | ↗ |
| 01 Jan 2017 | Happy Social Media LTD.Happy Social Media LTD. was fined by the AEPD EUR 2,000 for sending advertising emails to individuals who had opted out of receiving them. The case concerned Article 21.1 of the LSSI and the obligation to respect objections to marketing communications. | ES | AEPD | ePrivacy | €2,000 | ↗ |
| 29 Jun 2023 | FORKMERGE S.L.FORKMERGE S.L. was fined by the AEPD EUR 2,000 for failing to comply with a data subject’s request to remove personal data from search engine results. The authority found this to be a breach of Article 17 GDPR. | ES | AEPD | GDPR | €2,000 | ↗ |
| 18 Jan 2021 | INDUSTRIAS METÁLICAS ANRO, S.L.INDUSTRIAS METÁLICAS ANRO, S.L. was fined by the AEPD for failing to comply with cookie policy requirements on its website. The breach concerned Article 22.2 of the LSSI. | ES | AEPD | ePrivacy | €2,000 | ↗ |
| 04 Aug 2022 | Sephora Cosmetics România SASephora Cosmetics România SA was fined EUR 2,000 by ANSPDCP for violating GDPR provisions. The case concerned non-compliance with personal data protection requirements. | RO | ANSPDCP | GDPR | €2,000 | ↗ |
| 04 Dec 2020 | BEINNOVA.ESBEINNOVA.ES was fined by the AEPD EUR 2,000 for sending unsolicited marketing emails without the recipient's consent. This conduct breached Article 21 of the LSSI on electronic commercial communications. | ES | AEPD | ePrivacy | €2,000 | ↗ |
| 28 Jun 2021 | ELEGA ENERGÍA, S.L.ELEGA ENERGÍA, S.L. was fined EUR 2,000 by the AEPD for failing to provide information about cookies and for not obtaining user consent before placing them. The authority found a breach of Article 22.2 of the LSSI. | ES | AEPD | ePrivacy | €2,000 | ↗ |
| 27 Sept 2022 | Anonymised (HDPA 18/2022)A fine was imposed for sending unsolicited political communication via SMS without prior consent. The case concerns a breach of consent requirements for political and marketing communications. | GR | HDPA | ePrivacy | €2,000 | ↗ |
| 16 Feb 2022 | FEDERACION CASTELLANO-LEONESA DE SALVAMENTO Y SOCORRISMOThe organization was fined EUR 2,000 by the AEPD for requiring participants to consent to data processing and image rights transfers without any option to refuse. The authority found this incompatible with Article 6(1) GDPR. | ES | AEPD | GDPR | €2,000 | ↗ |
| 13 Dec 2021 | SC Nobiotic Pharma SRLSC Nobiotic Pharma SRL was fined €2,000 by ANSPDCP for failing to respond to information requests. The authority treated this as a breach of GDPR obligations. | RO | ANSPDCP | GDPR | €2,000 | ↗ |
| 14 Feb 2023 | MENZIES AVIATION SPAIN S.L.MENZIES AVIATION SPAIN S.L. was fined by the AEPD 2,000 EUR for sending emails to multiple recipients without using BCC. This exposed employees’ personal data to other recipients. | ES | AEPD | GDPR | €2,000 | ↗ |
| 16 Jan 2026 | Liceo Classico e Scientifico Alessandro VoltaLiceo Classico e Scientifico Alessandro Volta was fined 2,000 EUR by the Garante for publishing personal data on its institutional website without a proper legal basis. The authority found breaches of lawfulness, fairness, and transparency principles. | IT | Garante | GDPR | €2,000 | ↗ |
| 18 Dec 2025 | Elba Catering Distribuzioni s.r.l.s.Elba Catering Distribuzioni s.r.l.s. was fined EUR 2,000 by the Garante for installing a video surveillance system that primarily captured public streets. The authority found that this processing breached data protection rules. | IT | Garante | GDPR | €2,000 | ↗ |
| 25 Nov 2019 | YA candidate in municipal elections was fined for using a customer list to send election propaganda. The authority found a breach of the GDPR purpose limitation principle. | BE | APD | GDPR | €2,000 | ↗ |
| 01 Sept 2020 | Geanonimiseerd (APD 53/2020)A politician was fined for sending an election propaganda email without consent. The authority found unlawful processing of personal data and a failure to implement appropriate technical and organizational measures. | BE | APD | GDPR | €2,000 | ↗ |
| 22 May 2024 | TRADING INTERNATIONAL TOURIST, S.L.TRADING INTERNATIONAL TOURIST, S.L. was fined 2,000 EUR by the AEPD for adding the complainant’s phone number to a WhatsApp group with more than 500 members without consent. The authority found a breach of Article 6(1) GDPR, which requires a lawful basis for processing personal data. | ES | AEPD | GDPR | €2,000 | ↗ |
| 08 Aug 2024 | PUERTO FOGONES SLPUERTO FOGONES SL was fined EUR 2,000 by the AEPD. The authority found a breach for failing to provide access to information as required under Article 58.1 of the GDPR. | ES | AEPD | GDPR | €2,000 | ↗ |
| 02 Oct 2024 | Global Ports’s Services S.R.L.The company was fined for processing personal data without a legal basis, which breaches Article 6 of the GDPR. The case concerned unlawful processing by the controller. | RO | ANSPDCP | GDPR | €2,000 | ↗ |