BULLETIN №081Last updated · 28 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -20.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 20 Oct 2011 | Betfair Italia srlBetfair Italia srl was fined EUR 40,000 by the Garante for violations related to the omission of information on how data subjects can exercise their rights, as well as other data protection obligations. The case concerned incomplete compliance with information requirements toward users. | IT | Garante | GDPR | €40,000 | ↗ |
| 12 Dec 2023 | B*** GmbHB*** GmbH was fined by the DSB EUR 5,900 for failing to timely report a data breach to the supervisory authority and for not providing sufficient information required under GDPR. The company also did not cooperate with the authority’s further requests for information. | AT | DSB | GDPR | €5,900 | ↗ |
| 07 Oct 2024 | B*** GmbHB*** GmbH was fined EUR 600 by the Austrian Data Protection Authority (DSB). The penalty concerned a failure to cooperate in a data breach procedure, which breached Article 31 GDPR. | AT | DSB | GDPR | €600 | ↗ |
| 16 Sept 2025 | Bharat Singh ChandBharat Singh Chand, a self-employed lead generator, sent or instigated the sending of 966,449 direct marketing SMS messages between 3 December 2023 and 3 July 2024. The activity breached regulations 22 and 23 of PECR and generated 19,138 complaints to the 7726 spam reporting service. He was fined £200,000 and issued with an enforcement notice. | GB | ICO | ePrivacy | €231,000 | ↗ |
| 11 May 2017 | Bianalisi s.p.a.Bianalisi s.p.a. was fined by the Italian data protection authority, Garante, for failing to update its notification concerning the processing of genetic data. The obligation arose under the Italian Privacy Code and was intended to ensure proper disclosure of sensitive data processing. | IT | Garante | GDPR | €20,000 | ↗ |
| 20 Jan 2021 | BICLAMEDIA, S.L.BICLAMEDIA, S.L. was fined 1,500 EUR by the AEPD for sending commercial emails without the recipient’s consent. The conduct breached Article 21 of the LSSI governing electronic marketing communications. | ES | AEPD | ePrivacy | €1,500 | ↗ |
| 23 Jul 2015 | Bike Service s.n.c.Bike Service s.n.c. was fined by the Garante 2,400 EUR for failing to inform data subjects about the processing of personal data through a video surveillance system. The breach concerned the absence of required notices for individuals subject to the monitoring. | IT | Garante | GDPR | €2,400 | ↗ |
| 05 Jul 2023 | BILBAO AD INFINITUM, S.L.BILBAO AD INFINITUM, S.L. was fined by the AEPD EUR 500 for installing surveillance cameras directed at a public square without prior administrative authorization. The authority found that this conduct breached GDPR requirements on lawful processing. | ES | AEPD | GDPR | €500 | ↗ |
| 04 Apr 2019 | Bill Size s.r.l.Bill Size s.r.l. was fined by the Garante in the amount of EUR 16,000 for registering phone cards to individuals without their consent. The authority found this to be a breach of data protection rules. | IT | Garante | GDPR | €16,000 | ↗ |
| 01 Dec 2017 | BILUA E-COMMERCE S.L (CARETHY y BIUKY)BILUA E-COMMERCE S.L. was fined by the AEPD EUR 7,000 for sending unsolicited commercial emails. The messages were sent despite the recipient's request to unsubscribe, which breached Article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €7,000 | ↗ |
| 02 Apr 2025 | BINBOX GLOBAL SERVICES S.R.L.In March 2025, Romania’s data protection authority ANSPDCP completed an investigation into BINBOX GLOBAL SERVICES S.R.L. The authority found a GDPR violation and imposed a fine of EUR 3,000. | RO | ANSPDCP | GDPR | €3,000 | ↗ |
| 16 Feb 2011 | Bioacqua s.r.l.Bioacqua s.r.l. was fined EUR 9,000 by the Garante for using phone numbers for commercial communications without explicit consent and without providing the required information notice. The conduct breached Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €9,000 | ↗ |
| 19 Jul 2012 | Biodiversity S.p.A.Biodiversity S.p.A. was fined by the Garante for failing to timely notify personal data processing activities related to molecular diagnostics. The obligation arose under the Italian Privacy Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 16 Jan 2014 | Bios Marx s.r.l.Bios Marx s.r.l. was fined by the Italian Garante in the amount of EUR 16,000 for providing an inadequate privacy notice during a medical initiative. The authority also found that personal data were shared with third parties without obtaining specific consent. | IT | Garante | GDPR | €16,000 | ↗ |
| 09 Dec 2010 | Bios s.p.a.Bios s.p.a. was fined by the Italian Garante for failing to provide adequate and timely information about the processing of personal data through a video surveillance system. The conduct breached Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €6,000 | ↗ |
| 17 Jul 2019 | Bírák érdek-képviseleti egyesületi tagságra vonatkozó adatának jogellenes kezeléseBudapest Környéki Törvényszék unlawfully processed personal data by listing and sharing association membership information without a proper purpose or legal basis. The authority found a breach of the GDPR principles of purpose limitation and lawful processing. | HU | NAIH | GDPR | €9,180 | ↗ |
| 10 Apr 2023 | BIROU GAS, S.L.BIROU GAS, S.L. was fined EUR 60,000 by the AEPD for breaching Article 58(1) of the GDPR. The company did not respond to information requests from the supervisory authority. | ES | AEPD | GDPR | €60,000 | ↗ |
| 08 Oct 2015 | Birrificio Torino srlBirrificio Torino srl was fined EUR 2,400 by the Garante for providing inadequate information in the data collection form on its website. The authority found a breach of Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 24 Jun 2025 | BirthlinkThe UK Information Commissioner’s Office (ICO) fined Scottish charity Birthlink GBP 18,000. The case involved the destruction of about 4,800 personal records, up to 10% of which may have been irreplaceable. | GB | ICO | GDPR | €21,109 | ↗ |
| 01 Feb 2026 | Biržų ligoninėVDAI imposed a EUR 6,000 fine on Biržų ligoninė for improper processing of personal data. The case concerns a breach of data protection requirements and indicates non-compliance with GDPR obligations. | LT | VDAI | GDPR | €6,000 | ↗ |