BULLETIN №081Last updated · 28 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -20.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 03 Nov 2021 | B.B.B.The entity processed personal data without consent by using the complainant's data to make a purchase on Amazon. The authority found a breach of GDPR Article 6. | ES | AEPD | GDPR | €2,000 | ↗ |
| 11 Jul 2025 | MEDIADENTMEDIADENT was fined for failing to cooperate with the supervisory authority. The case concerned Article 31 GDPR, which requires controllers and processors to cooperate with the authority during its work. | GR | HDPA | GDPR | €2,000 | ↗ |
| 13 Dec 2022 | CONSULTORÍA PERITACIONES ALMERIENSES, S.L.The company did not respond to a data access request and failed to publish information on data processing or the data controller on its website. AEPD treated this as a breach of the information obligations under Article 13 GDPR. | ES | AEPD | GDPR | €2,000 | ↗ |
| 01 Jan 2024 | WAGESTREAM SPAIN S.L.U.WAGESTREAM SPAIN S.L.U. was fined by the AEPD for processing employees’ personal data without proper consent. The case involved names, personal email addresses, bank account numbers, and salary details, in breach of Article 6(1) GDPR. | ES | AEPD | GDPR | €2,000 | ↗ |
| 17 Apr 2026 | Io e te s.r.l.s.Io e te s.r.l.s. was fined EUR 2,000 by the Italian Garante. The case concerned improper use of a surveillance camera that enabled remote viewing through a mobile application without proper authorization. | IT | Garante | GDPR | €2,000 | ↗ |
| 18 Dec 2025 | SOCIETE EXERCANT UNE ACTIVITE D'AGENCE DE VOYAGE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 2,000 on SOCIETE EXERCANT UNE ACTIVITE D'AGENCE DE VOYAGE and issued an injunction. The case concerns a breach of rules supervised by the CNIL. | FR | CNIL | GDPR | €2,000 | ↗ |
| 13 May 2021 | Brico Rida s.r.l.Brico Rida s.r.l. was fined by the Garante in the amount of 2,000 EUR for operating a video surveillance system without the required information notice to data subjects. The authority found a breach of Article 13 GDPR. | IT | Garante | GDPR | €2,000 | ↗ |
| 23 Mar 2023 | Paolo MeloniThe condominium administrator, Paolo Meloni, was fined for disclosing to all residents that a family had tested positive for COVID-19. The authority found this to be a breach of data protection rules. | IT | Garante | GDPR | €2,000 | ↗ |
| 16 Feb 2023 | CONCENTRA CENTRAL DE COMPRAS Y SERVICIOS S.L.The entity was fined for making misleading advertising calls without explicit consent from recipients. The authority cited breaches of GDPR Articles 14 and 21(4). | ES | AEPD | GDPR | €2,000 | ↗ |
| 15 Apr 2025 | United Business Solutions SRLANSPDCP completed an investigation at United Business Solutions SRL and found a violation of GDPR provisions. As a result, a fine of EUR 2,000 was imposed. | RO | ANSPDCP | GDPR | €2,000 | ↗ |
| 19 May 2011 | Anonymised (HDPA 59/2011)The company was fined for sending unsolicited electronic messages and faxes without subscriber consent. This conduct breached e-privacy rules governing direct electronic communications. | GR | HDPA | ePrivacy | €2,000 | ↗ |
| 07 Feb 2024 | Account Exchange SRLAccount Exchange SRL was fined EUR 2,000 by ANSPDCP for violating GDPR provisions related to data processing. The case concerned non-compliant processing of personal data. | RO | ANSPDCP | GDPR | €2,000 | ↗ |
| 20 Mar 2026 | Domeniul Public și Privat SADomeniul Public și Privat SA was fined 2,000 EUR by ANSPDCP for GDPR violations. The case concerned non-compliance with personal data protection requirements. | RO | ANSPDCP | GDPR | €2,000 | ↗ |
| 13 Mar 2023 | Modaone SRLModaone SRL was fined by ANSPDCP EUR 2,000 for sending commercial emails to a data subject after the person had objected. The authority found a breach of the GDPR right to object. | RO | ANSPDCP | GDPR | €2,000 | ↗ |
| 01 Jan 2025 | MALAGASUITE SHOWROOM, S.L.MALAGASUITE SHOWROOM, S.L. was fined by the AEPD 2,000 EUR for failing to inform guests about the processing of their personal data. The authority found a breach of Article 13 GDPR. | ES | AEPD | GDPR | €2,000 | ↗ |
| 15 Apr 2021 | Società triveneta di chirurgiaSocietà triveneta di chirurgia was fined EUR 2,000 by the Garante for processing personal data without meeting the requirements of lawfulness, fairness, and transparency. The authority also found a breach of the data minimization principle. | IT | Garante | GDPR | €2,000 | ↗ |
| 16 Apr 2022 | ORI, S.l.ORI, S.l. was fined by the AEPD 2,000 EUR for failing to provide a privacy policy on its website. Personal data was collected through multiple forms, which constituted a breach of data protection rules. | ES | AEPD | GDPR | €2,000 | ↗ |
| 22 Feb 2024 | Camera di Commercio Industria Artigianato e Agricoltura di XXCamera di Commercio was fined for violating data protection principles by improperly disclosing personal data. The disclosure could have allowed third parties to learn the content of a judicial decision and infringed the privacy of the individual concerned. | IT | Garante | GDPR | €2,000 | ↗ |
| 20 Jun 2022 | Anonymised (HDPA 23/2022)A fine was imposed for failing to respond to a data access request within the required timeframe. The case concerns a breach of the controller’s obligations to facilitate data subject rights. | GR | HDPA | GDPR | €2,000 | ↗ |
| 23 Apr 2023 | COYARE SLUCOYARE SLU was fined by the AEPD EUR 2,000 for a data protection breach linked to mass email sending. Using CC instead of BCC exposed recipients’ email addresses and could have compromised their identities. | ES | AEPD | GDPR | €2,000 | ↗ |