BULLETIN №081Last updated · 28 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -20.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 23 Mar 2023 | B.B.B.B.B.B. was fined by the AEPD in the amount of 2,000 EUR for sending unsolicited commercial emails after a request for data deletion. The conduct breached Article 21 of the LSSI on marketing communications without consent. | ES | AEPD | ePrivacy | €2,000 | ↗ |
| 17 Jan 2025 | DELIVERY SOLUTIONS S.A.The company was fined for failing to implement adequate technical and organizational measures to ensure a level of security appropriate to the risk. The authority also found insufficient safeguards to ensure data confidentiality. | RO | ANSPDCP | GDPR | €2,000 | ↗ |
| 21 May 2024 | B.B.B.B.B.B. was fined 2,000 EUR by the AEPD for unlawfully processing personal data. The case concerned the inclusion of data in the ASNEF credit information system without meeting the legal requirements under GDPR. | ES | AEPD | GDPR | €2,000 | ↗ |
| 29 Dec 2017 | Anonymised (HDPA 151/2017)The controller of the blog dexiextrem.blogspot.gr was fined EUR 2,000 for failing to comply with the data subject’s right to object to the processing of personal data. The authority found a breach of Article 13 of Law 2472/1997 in connection with the publication of personal data. | GR | HDPA | GDPR | €2,000 | ↗ |
| 01 Jan 2024 | INCIBEINCIBE was fined EUR 2,000 by the AEPD for failing to implement data protection by design and by default, in breach of Article 25 GDPR. The procedure concerning the alleged breach of Article 5(1)(f) was dismissed because no serious threat to rights and freedoms was found. | ES | AEPD | GDPR | €2,000 | ↗ |
| 01 Sept 2021 | COMUNIDAD DE PROPIETARIOS C/ ***DIRECCIÓN.1The community of property owners was fined by the AEPD 2,000 EUR for publishing personal data on a public notice board. This conduct breached data protection rules. | ES | AEPD | GDPR | €2,000 | ↗ |
| 27 Nov 2025 | Istituto Comprensivo “G. Falcone” Rende-Quattromiglia (CS)The Garante fined Istituto Comprensivo “G. Falcone” EUR 2,000 for breaches of data processing principles, including lawfulness, fairness, and transparency. The authority also found non-compliance with data processing agreements. | IT | Garante | GDPR | €2,000 | ↗ |
| 16 Jan 2025 | Comune di CoriThe Garante fined Comune di Cori EUR 2,000 for violations related to the processing of personal data in connection with the issuance of the “Dedicata a te” card. The case involved electronic payment cards provided by Poste Italiane. | IT | Garante | GDPR | €2,000 | ↗ |
| 08 Jan 2026 | Amendă pentru încălcarea Legii nr. 506/2004 și a RGPDA fine of EUR 2,000 was imposed for violations of certain provisions of Law No. 506/2004 and the GDPR. The case concerns non-compliant personal data processing and privacy protection obligations. | RO | ANSPDCP | GDPR | €2,000 | ↗ |
| 10 Feb 2022 | Comune di GuidizzoloComune di Guidizzolo was fined for publishing a complainant’s personal data, including name and professional qualification, in a public document without proper justification. The authority found a breach of the principles of lawfulness, fairness, and transparency. | IT | Garante | GDPR | €2,000 | ↗ |
| 13 May 2025 | Romoffice Construct Holding Ag SRLThe company was fined by ANSPDCP €2,000 for processing personal data without a legal basis. The breach concerned the principles of lawfulness, fairness, and transparency. | RO | ANSPDCP | GDPR | €2,000 | ↗ |
| 01 Jan 2023 | UNIQUE HOTEL APARTMENT. S.LThe hotel improperly managed guest registration records, breaching data protection principles. It failed to maintain numerical order and did not communicate the records to the competent security forces. | ES | AEPD | GDPR | €2,000 | ↗ |
| 17 Oct 2023 | MOBILITY AUTOCENTRO, S.L.MOBILITY AUTOCENTRO, S.L. was fined by the AEPD in the amount of 2,000 EUR for sending unsolicited commercial SMS messages. The authority found that recipients were not given an opt-out option, which breached the Spanish LSSI. | ES | AEPD | ePrivacy | €2,000 | ↗ |
| 10 Feb 2021 | CEYLLE SOLUTIONS & DEVELOPMENT S.L.CEYLLE SOLUTIONS & DEVELOPMENT S.L. was fined by the AEPD in the amount of 2,000 EUR for disclosing personal data in emails sent to commercial partners. The authority found a breach of data protection rules. | ES | AEPD | GDPR | €2,000 | ↗ |
| 14 Nov 2024 | Comune di Torre AnnunziataThe Garante imposed a EUR 2,000 fine on Comune di Torre Annunziata for failing to communicate the contact details of its Data Protection Officer. This obligation arises under Article 37(7) GDPR and is intended to ensure the supervisory authority can reach the DPO. | IT | Garante | GDPR | €2,000 | ↗ |
| 23 Dec 2024 | Fan Courier Express S.R.L.Fan Courier Express S.R.L. was fined €2,000 by ANSPDCP for breaching Article 3 of the GDPR. The case concerned non-compliance with the rules on the regulation’s scope of application. | RO | ANSPDCP | GDPR | €2,000 | ↗ |
| 13 Mar 2025 | Comune di RoccarasoThe Garante fined Comune di Roccaraso EUR 2,000 for publishing personal data on a public notice board. The authority found breaches of GDPR Articles 5, 6 and 12, as well as Article 2-ter of the Italian Privacy Code. | IT | Garante | GDPR | €2,000 | ↗ |
| 01 Jan 2023 | INMARAN ASESORES S.L.INMARAN ASESORES S.L. was fined by the AEPD in the amount of 2,000 EUR for failing to comply with a data protection authority resolution. The company did not implement the required measures to inform data subjects under Article 13 GDPR. | ES | AEPD | GDPR | €2,000 | ↗ |
| 16 Apr 2024 | ARRENDAMIENTOS DEUDORES, S.L.ARRENDAMIENTOS DEUDORES, S.L. accessed personal data in the ASNEF file without proper authorization. The AEPD found a breach of Article 6(1) GDPR and imposed a fine of EUR 2,000. | ES | AEPD | GDPR | €2,000 | ↗ |
| 24 Jun 2021 | Istituto Professionale per i servizi commerciali e turistici “G. Ravizza” di NovaraThe Istituto Professionale per i servizi commerciali e turistici “G. Ravizza” in Novara was fined by the Garante EUR 2,000. The authority found breaches of data protection principles, including lawfulness, fairness, transparency, and data minimization. | IT | Garante | GDPR | €2,000 | ↗ |