BULLETIN №082Last updated · 29 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 10 Oct 2024 | WerepairUK LtdWerepairUK Ltd made 42,688 marketing calls to individuals in breach of regulation 21 of PECR. The ICO fined the company 80,000 GBP and issued an enforcement notice. | GB | ICO | ePrivacy | €95,592 | ↗ |
| 09 Oct 2024 | Pana AB, prowadzącego działalność gospodarczą pod firmą X, ul.The Polish DPA (UODO) imposed a fine of PLN 353,589 on Pana AB, operating under the name X, for breaches of the GDPR. The authority also ordered the company to bring its processing operations into compliance with Regulation (EU) 2016/679. | PL | UODO | GDPR | €82,273 | ↗ |
| 08 Oct 2024 | SEAT, S.A.SEAT, S.A. was fined by the AEPD €20,000 for using cookies on its website without obtaining user consent. The authority found this conduct to be in breach of the LSSI. | ES | AEPD | ePrivacy | €20,000 | ↗ |
| 07 Oct 2024 | B*** GmbHB*** GmbH was fined EUR 600 by the Austrian Data Protection Authority (DSB). The penalty concerned a failure to cooperate in a data breach procedure, which breached Article 31 GDPR. | AT | DSB | GDPR | €600 | ↗ |
| 07 Oct 2024 | BANCO BILBAO VIZCAYA ARGENTARIA, S.A.The bank was fined for unauthorized remote management of a former employee's personal device. The authority found that the conduct breached the principles of lawful personal data processing. | ES | AEPD | GDPR | €200,000 | ↗ |
| 04 Oct 2024 | DIAMOND FERVA, S.L.DIAMOND FERVA, S.L. was fined by the AEPD 1,000 EUR for installing a surveillance camera without properly informing data subjects and without the required authorization. The authority treated this as a breach of the information obligations under GDPR Article 13. | ES | AEPD | GDPR | €1,000 | ↗ |
| 03 Oct 2024 | ALL IN DIGITAL MARKETING SLALL IN DIGITAL MARKETING SL was fined EUR 5,000 by the AEPD for continuing to send marketing emails despite the recipient's unsubscribe requests. The authority found a breach of Article 21 of the LSSI. | ES | AEPD | ePrivacy | €5,000 | ↗ |
| 03 Oct 2024 | Police Service of Northern IrelandThe Police Service of Northern Ireland was fined £750,000 by the ICO for breaches of Articles 5(1)(f), 32(1) and (2) of the UK GDPR between 25 May 2018 and 14 June 2024. The case concerned insufficient protection of personal data and inadequate security of processing. The decision indicates a failure to implement appropriate technical and organisational safeguards. | GB | ICO | GDPR | €890,000 | ↗ |
| 02 Oct 2024 | Global Ports’s Services S.R.L.The company was fined for processing personal data without a legal basis, which breaches Article 6 of the GDPR. The case concerned unlawful processing by the controller. | RO | ANSPDCP | GDPR | €2,000 | ↗ |
| 01 Oct 2024 | TRIVE CREDIT SPAIN, S.L.TRIVE CREDIT SPAIN, S.L. failed to properly handle a data subject access request, which constitutes a breach of Article 15 GDPR. The AEPD imposed a fine for non-compliance with a prior resolution. | ES | AEPD | GDPR | €450,000 | ↗ |
| 01 Oct 2024 | IBERCAJA BANCO, S.A.Ibercaja Banco, S.A. accessed personal data in the BADEXCUG EXPERIAN file 47 times without consent after the contractual relationship ended. The AEPD found this to be a breach of data protection rules and imposed a 300,000 EUR fine. | ES | AEPD | GDPR | €300,000 | ↗ |
| 01 Oct 2024 | SERVACE, S.L.SERVACE, S.L. was fined by the AEPD EUR 1,400 for using an employee’s personal email address for work purposes without consent. The authority found this breached GDPR Articles 6(1) and 5(1)(f). | ES | AEPD | GDPR | €1,400 | ↗ |
| 01 Oct 2024 | CONSULTORIA INTEGRAL DE ENERGÍA ECOLÓGICA, S.L.The company was fined by the AEPD in the amount of 5,000 EUR for sending unsolicited advertising messages to a complainant. The authority found this conduct breached Article 21 of the LSSI. | ES | AEPD | ePrivacy | €5,000 | ↗ |
| 30 Sept 2024 | ASSOCIATION AYANT POUR OBJET LA CREATION D'UN RESEAU DE SANTE PSYCHIATRIQUE (procédure simplifiée)CNIL imposed an administrative fine of EUR 3,000 on ASSOCIATION AYANT POUR OBJET LA CREATION D'UN RESEAU DE SANTE PSYCHIATRIQUE. The case concerns a breach of personal data protection rules under a simplified procedure. | FR | CNIL | GDPR | €3,000 | ↗ |
| 26 Sept 2024 | SOCIETE PROPOSANT DES SERVICES DE CONSEIL EN SYSTÈMES ET LOGICIELS INFORMATIQUES, L'EDITION ET LA REALISATION DE LOGICIELS (procédure simplifiée)CNIL imposed an administrative fine of 15,000 EUR and issued an injunction. The case was handled under a simplified procedure. | FR | CNIL | GDPR | €15,000 | ↗ |
| 26 Sept 2024 | Azienda Sanitaria Territoriale di Ascoli PicenoThe Garante fined Azienda Sanitaria Territoriale di Ascoli Piceno EUR 17,000 for failing to implement procedures that would prevent unauthorized linkage between individuals and health departments. The issue could reveal information about a person's health status. | IT | Garante | GDPR | €17,000 | ↗ |
| 26 Sept 2024 | Città metropolitana di TorinoCittà metropolitana di Torino was fined by the Garante 50,000 EUR for publishing personal data on its institutional website about individuals fined by voluntary ecological guards. The disclosure included names and contact details, breaching data protection rules. | IT | Garante | GDPR | €50,000 | ↗ |
| 26 Sept 2024 | Meta Platforms Ireland Limited (MPIL)The Irish DPC imposed a fine of 91,000,000 EUR on Meta Platforms Ireland Limited. The case relates to an inquiry and is currently pending appeal. | IE | DPC | GDPR | €91,000,000 | ↗ |
| 26 Sept 2024 | SOCIETE DE MARKETING (procédure simplifiée)CNIL imposed a EUR 3,000 penalty on SOCIETE DE MARKETING under a simplified procedure. The case concerns liquidation astreinte, meaning enforcement of a previously imposed monetary obligation. | FR | CNIL | GDPR | €3,000 | ↗ |
| 26 Sept 2024 | ORGANISME DE FORMATION DESTINE AUX PROFESSIONNELS DE SANTE (procédure simplifiée)CNIL imposed an administrative fine of 15,000 EUR on ORGANISME DE FORMATION DESTINE AUX PROFESSIONNELS DE SANTE and issued an injunction. The case was handled under a simplified procedure. | FR | CNIL | GDPR | €15,000 | ↗ |