BULLETIN №082Last updated · 29 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 05 Dec 2024 | SOCIETE OFFRANT DES PRESTATIONS DE SECURITE PRIVE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 20,000 on SOCIETE OFFRANT DES PRESTATIONS DE SECURITE PRIVE and issued an injunction. The case was handled under a simplified procedure. | FR | CNIL | GDPR | €20,000 | ↗ |
| 05 Dec 2024 | TMETME was fined EUR 200,000 by the AEPD for changing the ownership of a mobile line without consent and for issuing a duplicate SIM card without a valid legal basis. The authority found that these actions failed to meet the requirements for lawful processing and proper authorization of subscriber account changes. | ES | AEPD | GDPR | €200,000 | ↗ |
| 05 Dec 2024 | KASPRThe CNIL imposed an administrative fine of EUR 200,000 on KASPR on 5 December 2024. The authority found GDPR breaches relating to lawful basis, retention, transparency, information, and access rights in connection with KASPR's data scraping activities. | FR | CNIL | GDPR | €200,000 | ↗ |
| 05 Dec 2024 | SOCIETE SPECIALISEE DANS L'ELABORATION ET ORGANISATION DE CAMPAGNES PUBLICITAIRES (procédure simplifiée)The CNIL imposed an administrative fine of EUR 20,000 on SOCIETE SPECIALISEE DANS L'ELABORATION ET ORGANISATION DE CAMPAGNES PUBLICITAIRES under a simplified procedure. The case concerns a data protection breach identified by the authority. | FR | CNIL | GDPR | €20,000 | ↗ |
| 05 Dec 2024 | KASPRThe CNIL imposed an administrative fine of €240,000 on KASPR on 5 December 2024. The case concerned data scraping and multiple GDPR breaches, including lack of lawful basis, poor transparency, excessive retention, and failure to respect access rights. | FR | CNIL | GDPR | €240,000 | ↗ |
| 03 Dec 2024 | VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD 20,000 EUR for sending commercial electronic communications to a customer who had opted out. The authority also found that there was no effective mechanism to revoke consent. | ES | AEPD | ePrivacy | €20,000 | ↗ |
| 03 Dec 2024 | BANCO BILBAO VIZCAYA ARGENTARIA, S.A.The AEPD imposed a EUR 200,000 fine on Banco Bilbao Vizcaya Argentaria, S.A. for processing personal data without a legal basis. The conduct included signing documents without consent and marking consent checkboxes for commercial purposes without authorization. | ES | AEPD | GDPR | €200,000 | ↗ |
| 03 Dec 2024 | Fiziska personaA fine of EUR 500 was imposed by the DVI. The decision has entered into force. | LV | DVI | GDPR | €500 | ↗ |
| 01 Dec 2024 | Orange România SAThe Romanian data protection authority completed an investigation in December 2024 into Orange România SA and found a breach of Article 12(3) GDPR. The case concerned failure to meet the deadline for responding to a data subject access request, resulting in a EUR 40,000 fine. | RO | Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal | GDPR | €40,000 | ↗ |
| 28 Nov 2024 | COMUNIDAD DE PROPIETARIOS A.A.A.The community of property owners was fined by the AEPD for publicly displaying personal data, including names and debt information. The authority found a breach of the confidentiality principle under GDPR. | ES | AEPD | GDPR | €1,000 | ↗ |
| 27 Nov 2024 | Lyngby-Taarbæk KommuneThe Danish DPA reported Lyngby-Taarbæk Municipality to the police for failing to implement adequate security measures. This led to unauthorized access to personal data of about 30,000 citizens, and a fine of 350,000–400,000 DKK was recommended. | DK | Datatilsynet | GDPR | €53,632 | ↗ |
| 27 Nov 2024 | Comune di TorrenovaThe Garante fined Comune di Torrenova 4,000 EUR for breaches of GDPR principles, including lawfulness, fairness, and transparency in data processing. The case indicates failures to meet basic data protection requirements in the public authority's processing activities. | IT | Garante | GDPR | €4,000 | ↗ |
| 27 Nov 2024 | E.ON Energia S.p.A.E.ON Energia S.p.A. was fined EUR 892,738 by the Garante for telemarketing-related violations. The authority cited repeated contact attempts and numerous communications sent without proper consent. | IT | Garante | GDPR | €892,000 | ↗ |
| 27 Nov 2024 | Faro di RomaFaro di Roma was fined 15,000 EUR by the Garante for failing to comply with data protection rules. The case concerned the failure to honor requests for erasure and rectification of personal data linked to a judicial matter. | IT | Garante | GDPR | €15,000 | ↗ |
| 27 Nov 2024 | Istituto Comprensivo Statale "Corso Matteotti" di AlfonsineIstituto Comprensivo Statale “Corso Matteotti” di Alfonsine was fined by the Garante EUR 1,000 for violations related to the processing of personal data. The authority cited non-compliance with the principles of lawfulness, fairness, and transparency. | IT | Garante | GDPR | €1,000 | ↗ |
| 27 Nov 2024 | Engineering Ingegneria Informatica S.p.A.The Garante imposed a fine of EUR 10,000 on Engineering Ingegneria Informatica S.p.A. for a data breach involving the Molise regional health portal. A system vulnerability allowed unauthorized access to personal data. | IT | Garante | GDPR | €10,000 | ↗ |
| 27 Nov 2024 | Comune di Motta Sant'AnastasiaThe Garante imposed a EUR 10,000 fine on Comune di Motta Sant'Anastasia for breaches of GDPR Articles 5 and 6 and Article 2-ter of the Italian Privacy Code. The case concerned improper processing of personal data. | IT | Garante | GDPR | €10,000 | ↗ |
| 27 Nov 2024 | Molise dati S.p.A.Molise dati S.p.A. was fined EUR 10,000 by the Garante for a data breach involving the regional health portal. A system vulnerability allowed unauthorized access to personal data of citizens in the Molise Regional Registry. | IT | Garante | GDPR | €10,000 | ↗ |
| 27 Nov 2024 | Maximum International Corp. S.r.l.Maximum International Corp. S.r.l. was fined by the Garante 10,000 EUR for persistent promotional calls despite objections and for failing to respond to data subject requests. The authority found breaches of GDPR rules on consent and information obligations. | IT | Garante | GDPR | €10,000 | ↗ |
| 27 Nov 2024 | Azienda Sanitaria provinciale di EnnaAzienda Sanitaria provinciale di Enna was fined by the Garante 20,000 EUR for publishing employees’ personal data without a legal basis. The disclosure included details on additional payments, sickness absences, and union rights, breaching the GDPR and the national privacy code. | IT | Garante | GDPR | €20,000 | ↗ |