BULLETIN №081Last updated · 28 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -20.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 28 Oct 2021 | OTTO s.r.l.OTTO s.r.l. was fined by the Italian data protection authority, Garante, in the amount of 2,000 EUR. The case concerned a video surveillance system operated without the required privacy notice, which constitutes a breach of Article 13 GDPR. | IT | Garante | GDPR | €2,000 | ↗ |
| 23 Oct 2025 | Comune di AvolaThe Garante fined Comune di Avola 2,000 EUR for failing to provide the Authority with the Data Protection Officer’s contact details. The breach concerned the obligation under Article 37(7) GDPR. | IT | Garante | GDPR | €2,000 | ↗ |
| 23 Feb 2023 | TECH TALENTS, S.L.TECH TALENTS, S.L. was fined EUR 2,000 by the AEPD for sending unsolicited commercial emails. The conduct breached Article 21 of the LSSI, which governs marketing communications sent without prior consent. | ES | AEPD | ePrivacy | €2,000 | ↗ |
| 11 Mar 2021 | COMUNIDAD DE PROPIETARIOS B.B.B.COMUNIDAD DE PROPIETARIOS B.B.B. was fined by the AEPD in the amount of 2,000 EUR for irregularities in its video surveillance system. The authority found that the cameras captured public spaces, which breached the data minimization principle under Article 5(1)(c) GDPR. | ES | AEPD | GDPR | €2,000 | ↗ |
| 03 Dec 2021 | MEDIOS DE PREVENCIÓN EXTERNOS, S.L.The entity was fined for sending unsolicited advertising emails despite requests to cancel the subscription. This conduct breached rules on electronic commercial communications. | ES | AEPD | ePrivacy | €2,000 | ↗ |
| 27 Jan 2021 | Comune di Cesano BosconeThe Municipality of Cesano Boscone was fined EUR 2,000 by the Garante for publishing personal data related to a disciplinary sanction on its website. The authority found a breach of the principles of lawfulness, fairness, and transparency. | IT | Garante | GDPR | €2,000 | ↗ |
| 01 Jan 2023 | CIUDAD RESIDENCIAL H.H.H.CIUDAD RESIDENCIAL H.H.H. was fined by the AEPD EUR 2,000 for breaching the data minimization principle. The case concerned capturing and storing photographs of residents collecting packages without informing them about this processing. | ES | AEPD | GDPR | €2,000 | ↗ |
| 26 Nov 2025 | Cucina di Fabio S.R.L.ANSPDCP imposed a fine of EUR 2,000 on Cucina di Fabio S.R.L. for a GDPR violation. The case concerned non-compliance with personal data protection requirements. | RO | ANSPDCP | GDPR | €2,000 | ↗ |
| 26 Mar 2026 | Provvedimento del 26 marzo 2026 [10241477]A doctor did not comply with a request to delete data and provided patients with incomplete information, which constituted a breach of GDPR Article 13. The Garante imposed a fine of EUR 2,000. | IT | Garante | GDPR | €2,000 | ↗ |
| 03 Feb 2022 | Κοινοτικό Συμβούλιο ΒορόκληνηςThe Community Council of Voroklini was fined by the CyDPC for failing to exercise due diligence in the processing of personal data. This led to unauthorized changes to mailing addresses without proper consent. | CY | CyDPC | GDPR | €2,000 | ↗ |
| 12 Mar 2026 | Domiziana GiorgianniThe Garante imposed a EUR 2,000 fine on Domiziana Giorgianni for failing to implement adequate technical and organizational measures to support data subject rights. The authority also found that requests were not handled without undue delay. | IT | Garante | GDPR | €2,000 | ↗ |
| 22 Nov 2021 | B.B.B.The entity installed a surveillance camera in a shared stairway without the consent of the affected persons. The camera captured an excessive area, including private spaces, which breached data protection principles. | ES | AEPD | GDPR | €2,000 | ↗ |
| 17 Dec 2019 | B.B.B.A private individual was fined by the AEPD for installing a camera aimed at a public space and a building entrance without justification. The authority found a breach of data protection principles. | ES | AEPD | GDPR | €2,000 | ↗ |
| 07 Oct 2014 | BANCO SANTANDER, S.A.Banco Santander was fined by the AEPD EUR 2,000 for sending commercial emails despite the recipient's objection. The authority found this breached Article 21 of the LSSI on unsolicited electronic communications. | ES | AEPD | ePrivacy | €2,000 | ↗ |
| 22 Aug 2024 | Kaufland România SCSKaufland România SCS was fined by ANSPDCP €2,000 for a data security breach. The case concerned an incident affecting data protection and required supervisory authority action. | RO | ANSPDCP | GDPR | €2,000 | ↗ |
| 01 Jan 2024 | COMUNIDAD DE PROPIETARIOS L.L.L.COMUNIDAD DE PROPIETARIOS L.L.L. was fined by the AEPD 2,000 EUR for posting a list of debtor co-owners in a publicly accessible area and for sending erroneous debtor lists by email without justification. The authority found that these actions breached data protection principles. | ES | AEPD | GDPR | €2,000 | ↗ |
| 27 Nov 2025 | PFA Nițu A. Cleopatra – Expert contabilThe National Supervisory Authority for Personal Data Processing fined PFA Nițu A. Cleopatra – Expert contabil EUR 2,000 for GDPR violations. The case concerned non-compliant processing of personal data. | RO | ANSPDCP | GDPR | €2,000 | ↗ |
| 09 Sept 2021 | PACKLINK SHIPPING S.L.PACKLINK SHIPPING S.L. was fined by the AEPD €2,000 for using non-essential cookies on its website without providing the required information or obtaining explicit user consent. The authority treated this as a breach of data protection rules. | ES | AEPD | ePrivacy | €2,000 | ↗ |
| 14 Jul 2021 | Anonymised (HDPA 31/2021)The fined individual unlawfully obtained and processed personal data from the complainant's personnel file. The data came from an unauthorized source and were used in a complaint against the complainant, in breach of data protection rules. | GR | HDPA | GDPR | €2,000 | ↗ |
| 15 Oct 2020 | Comune di CollegnoComune di Collegno was fined by the Garante for failing to respond in time to a data subject’s request for access to personal data. The authority found a breach of GDPR Article 15. | IT | Garante | GDPR | €2,000 | ↗ |