BULLETIN №081Last updated · 28 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -20.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 22 Aug 2024 | Kaufland România SCSKaufland România SCS was fined EUR 2,000 by ANSPDCP for a data security breach. The case concerns an incident affecting data protection and resulted in an administrative sanction. | RO | ANSPDCP | GDPR | €2,000 | ↗ |
| 06 Sept 2022 | B.B.B.The entity failed to provide the information required under Article 13 GDPR when processing personal data. AEPD imposed a fine of EUR 2,000 for this breach. | ES | AEPD | GDPR | €2,000 | ↗ |
| 27 Apr 2023 | Checcoro di Nigro FrancescoThe company was fined EUR 2,000 by the Italian data protection authority, Garante. The sanction concerned the use of surveillance cameras without appropriate informational signage, in breach of GDPR requirements. | IT | Garante | GDPR | €2,000 | ↗ |
| 06 Jun 2022 | URQUÍA & BAS, CORREDURÍA DE SEGUROS S.L.URQUÍA & BAS, CORREDURÍA DE SEGUROS S.L. was fined by the AEPD 2,000 EUR for failing to notify a personal data breach in time. The case concerns the Article 33 GDPR obligation to report breaches to the supervisory authority. | ES | AEPD | GDPR | €2,000 | ↗ |
| 11 Nov 2011 | Galineio Melathro Private ClinicThe clinic unlawfully disclosed sensitive personal data without the required authorization from the HDPA. The breach involved special-category personal data and resulted in a 2,000 EUR fine. | GR | HDPA | GDPR | €2,000 | ↗ |
| 31 May 2017 | LEAD CONVERSIÓN, S.L.LEAD CONVERSIÓN, S.L. was fined by the AEPD €2,000 for sending unsolicited commercial emails. The conduct breached rules on electronic communications and recipient consent. | ES | AEPD | ePrivacy | €2,000 | ↗ |
| 02 Feb 2022 | TARIFER SERVICIOS, S.L.TARIFER SERVICIOS, S.L. was fined by the AEPD 2,000 EUR for using non-essential cookies without user consent. The authority also found that the website did not provide the required cookie information. | ES | AEPD | ePrivacy | €2,000 | ↗ |
| 19 Feb 2025 | EDA TV CONSULTING, S.L.EDA TV CONSULTING, S.L. was fined by the AEPD EUR 2,000 for failing to comply with cookie policy requirements on its website. The breach concerned obligations under the LSSI. | ES | AEPD | ePrivacy | €2,000 | ↗ |
| 23 Oct 2023 | EDITEUR DE BLOG EN LIGNE DEDIE A LA LUTTE CONTRE LA PEDOCRIMINALITE (procédure simplifiée)The CNIL imposed a fine of 2,000 EUR on EDITEUR DE BLOG EN LIGNE DEDIE A LA LUTTE CONTRE LA PEDOCRIMINALITE (procédure simplifiée). The matter was handled under a simplified procedure. | FR | CNIL | GDPR | €2,000 | ↗ |
| 03 Jun 2022 | Kaufland România SCSKaufland România SCS was fined EUR 2,000 by ANSPDCP for failing to follow internal complaint procedures. This allowed a security guard to improperly access and misuse personal data, resulting in a breach of data confidentiality. | RO | ANSPDCP | GDPR | €2,000 | ↗ |
| 22 Nov 2024 | MAXPOWER FITNESS NUTRITION, S.L.MAXPOWER FITNESS NUTRITION, S.L. was fined by the AEPD in the amount of 2,000 EUR for deficiencies in its cookie policy. The breach concerned the information and consent requirements under the LSSI. | ES | AEPD | ePrivacy | €2,000 | ↗ |
| 12 May 2022 | Singh Market S.r.l.The Garante fined Singh Market S.r.l. 2,000 EUR for operating a video surveillance system without the required informational signage. The authority found a breach of Article 13 GDPR. | IT | Garante | GDPR | €2,000 | ↗ |
| 16 Jun 2022 | Rapido Finance, S.L.Rapido Finance, S.L. was fined 2,000 EUR by the AEPD for unlawfully processing personal data. The company continued to pursue a debt that had already been paid, which breached Article 6(1) GDPR. | ES | AEPD | GDPR | €2,000 | ↗ |
| 19 May 2025 | REAL FEDERACIÓN ESPAÑOLA DE TENIS DE MESAREAL FEDERACIÓN ESPAÑOLA DE TENIS DE MESA was fined by the AEPD 2,000 EUR for publishing personal data of individuals involved in an electoral process on its website. This conduct breached data protection principles. | ES | AEPD | GDPR | €2,000 | ↗ |
| 07 Mar 2024 | Giuliana VinziThe Garante fined Giuliana Vinzi, owner of Rocky Bar, 2,000 EUR for operating video surveillance without the required notices to data subjects. The authority also found that authorization from the Labor Inspectorate was missing, resulting in a GDPR breach. | IT | Garante | GDPR | €2,000 | ↗ |
| 20 Oct 2022 | Comune di Calvi RisortaThe Municipality of Comune di Calvi Risorta was fined 2,000 EUR by the Garante. The sanction resulted from a delayed response to the supervisory authority's request for information, which breached data protection rules. | IT | Garante | GDPR | €2,000 | ↗ |
| 29 Apr 2025 | Versilmagra Immobiliare di Robertelli Davide & C. S.a.s.Versilmagra Immobiliare was fined EUR 2,000 by the Garante. The authority found that the company sent unsolicited communications via WhatsApp without proper consent and did not facilitate the exercise of data subject rights. | IT | Garante | GDPR | €2,000 | ↗ |
| 29 Jan 2025 | SINDICATO DE LA ADMON. PÚBLICA DE LA CGT EN JEREZ Y COSTA NOROESTE DE CÁDIZThe union was fined by the AEPD for failing to comply with data protection principles and for not informing individuals about the processing of their personal data. The case indicates shortcomings in transparency and GDPR compliance obligations. | ES | AEPD | GDPR | €2,000 | ↗ |
| 14 Mar 2023 | DIGIMAN ALICANTE, S.L.DIGIMAN ALICANTE, S.L. was fined 2,000 EUR by the AEPD for failing to remove an ex-employee’s image from its YouTube channel despite repeated requests. The authority found a breach of GDPR Article 6(1) regarding the lawful basis for processing personal data. | ES | AEPD | GDPR | €2,000 | ↗ |
| 09 Sept 2022 | SC Raiffeisen Bank SASC Raiffeisen Bank SA was fined by ANSPDCP in the amount of EUR 2,000 for violating Article 5 of the GDPR. The case concerned non-compliance with the basic principles for processing personal data set out in that provision. | RO | ANSPDCP | GDPR | €2,000 | ↗ |