BULLETIN №081Last updated · 28 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -20.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 23 Oct 2012 | B.B.B. (VELAS TLC)B.B.B. (VELAS TLC) was fined by the AEPD in the amount of EUR 1,200 for sending unsolicited commercial emails. The conduct breached Article 21.1 of the LSSI, which prohibits such communications without prior consent. | ES | AEPD | ePrivacy | €1,200 | ↗ |
| 03 May 2022 | B.B.B.Y OTRO MAS C.B.The entity installed a video surveillance system without providing the required information to data subjects. The conduct breached Article 13 of the GDPR and resulted in a EUR 300 fine imposed by the AEPD. | ES | AEPD | GDPR | €300 | ↗ |
| 13 Jun 2013 | BBJ s.r.l.BBJ s.r.l. was fined by the Garante EUR 64,000 for running SMS and email marketing campaigns without providing the required information to data subjects and without obtaining their consent. The authority found this to be a breach of data protection rules. | IT | Garante | GDPR | €64,000 | ↗ |
| 11 Jan 2023 | BBVABBVA was fined by the AEPD EUR 1,640,000 for multiple data protection violations. The case involved unauthorized payment operations and improper handling of personal data in credit information systems. | ES | AEPD | GDPR | €1,640,000 | ↗ |
| 03 Jun 2013 | BBVA SERVICIOS, S.A.BBVA SERVICIOS, S.A. was fined by the AEPD EUR 30,001 for sending unsolicited commercial emails without prior consent. This conduct breached Article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €30,001 | ↗ |
| 07 Mar 2024 | BdM Banca S.p.a.BdM Banca S.p.a. was fined 10,000 EUR by the Garante for failing to provide an adequate response to a data access request submitted by an heir. The authority found that the response did not meet the requirements of GDPR Article 15. | IT | Garante | GDPR | €10,000 | ↗ |
| 12 Dec 2024 | BDM Banca S.p.A.BDM Banca S.p.A. was fined by the Italian data protection authority, Garante, in the amount of EUR 20,000. The sanction concerned the failure to provide a timely response to a data subject’s access request, which constitutes a breach of GDPR Article 15. | IT | Garante | GDPR | €20,000 | ↗ |
| 04 Jan 2022 | BEAUTY & AESTHETIC BALEARIC, SL.BEAUTY & AESTHETIC BALEARIC, SL. was fined by the AEPD €1,000 for sending marketing emails without an opt-out mechanism. The authority found this to be a breach of Article 21 of the LSSI. | ES | AEPD | ePrivacy | €1,000 | ↗ |
| 01 Jan 2012 | BECERRITA, S.L.BECERRITA, S.L. was fined by the AEPD EUR 600 for sending unsolicited commercial emails without proper consent. The conduct breached Article 21 of the LSSI on electronic marketing communications. | ES | AEPD | ePrivacy | €600 | ↗ |
| 16 Nov 2023 | BEGIN RESTAURANTES, S.L.BEGIN RESTAURANTES, S.L. was fined by the AEPD EUR 2,000 for deficiencies in its cookie policy. The authority found the use of non-essential third-party cookies without proper consent and insufficient information in the main page banner. | ES | AEPD | ePrivacy | €2,000 | ↗ |
| 04 Dec 2020 | BEINNOVA.ESBEINNOVA.ES was fined by the AEPD EUR 2,000 for sending unsolicited marketing emails without the recipient's consent. This conduct breached Article 21 of the LSSI on electronic commercial communications. | ES | AEPD | ePrivacy | €2,000 | ↗ |
| 03 Mar 2025 | BEKO ROMÂNIA SAIn February 2025, ANSPDCP completed an investigation at BEKO ROMÂNIA SA and found violations of GDPR provisions. As a result, the controller was fined EUR 10,000. | RO | ANSPDCP | GDPR | €10,000 | ↗ |
| 23 May 2018 | BELEADER INTERNET MARKETING S.L.BELEADER INTERNET MARKETING S.L. was fined 5,000 EUR by the AEPD. The authority found that the company sent unsolicited emails and did not honor unsubscribe requests. | ES | AEPD | ePrivacy | €5,000 | ↗ |
| 17 Mar 2016 | Belzirossi s.r.l.Belzirossi s.r.l. was fined by the Italian Garante in the amount of EUR 2,400. The case concerned the use of a video surveillance system without providing data subjects with the required information under data protection rules. | IT | Garante | GDPR | €2,400 | ↗ |
| 02 Dec 2025 | Bende IstvánBende István and Berencsi Béla Miklós were fined for processing personal data without a legal basis and for failing to provide required information. The authority found breaches of GDPR principles of fair processing, purpose limitation, and transparency. | HU | NAIH | GDPR | €1,315 | ↗ |
| 27 Apr 2023 | Benetton Group S.r.l.Benetton Group S.r.l. was fined €240,000 by the Italian data protection authority, Garante. The authority found violations in the processing of personal data for marketing and profiling purposes, including the retention of former customers’ data for more than 10 years without proper justification. | IT | Garante | GDPR | €240,000 | ↗ |
| 15 Dec 2022 | BENOTAC, S.L.BENOTAC, S.L. was fined by the AEPD EUR 2,500 for operating a video surveillance system without proper signage and for capturing public areas without authorization. The authority also noted the sharing of recordings without the consent of the data subjects. | ES | AEPD | GDPR | €2,500 | ↗ |
| 23 May 2019 | Bérleti jogviszony során keletkezett dokumentumok másolatban történő kiadásaThe controller did not comply with the data subject's access request for personal data beyond the 2012 lease agreement. The authority treated this as a breach of access-right obligations and imposed a fine. | HU | NAIH | GDPR | €918 | ↗ |
| 19 Jan 2017 | Bertolotto Michele e Azienda Universitaria Ospedaliera Ospedali Riuniti di TriesteThe Garante imposed a 10,000 EUR fine on Bertolotto Michele and Azienda Universitaria Ospedaliera Ospedali Riuniti di Trieste. The case concerned unauthorized access by two doctors to personal health data, including Bertolotto’s data. | IT | Garante | GDPR | €10,000 | ↗ |
| 06 Aug 2024 | BEST ELAN ONLINE SRLBEST ELAN ONLINE SRL was fined €1,000 for GDPR violations. The company was also required to provide the ANSPDCP with all requested information and documents. | RO | ANSPDCP | GDPR | €1,000 | ↗ |