BULLETIN №081Last updated · 28 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -20.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 06 Feb 2024 | GESTIÓN DE PATRIMONIOS ANFIPOLIS SOCIEDAD DE RESPONSABILIDAD LIMITADAThe AEPD fined GESTIÓN DE PATRIMONIOS ANFIPOLIS SOCIEDAD DE RESPONSABILIDAD LIMITADA EUR 2,000 for sending unsolicited commercial communications without the recipient's consent. The authority noted that the messages were sent despite the recipient's opposition. | ES | AEPD | ePrivacy | €2,000 | ↗ |
| 13 Jun 2025 | Anonymised (HDPA 21/2025)A fine was imposed for breaching the principles of lawfulness, fairness, and transparency in data processing in connection with a video surveillance system. The case concerned improper processing of personal data through video monitoring. | GR | HDPA | GDPR | €2,000 | ↗ |
| 22 Jul 2025 | Anonimizirano (IP-RS 0609-101/2024/5)A legal entity was fined by IP-RS for a GDPR breach involving the unauthorized disclosure of personal data, including hospital treatment details, via email. The case concerned processing that failed to meet confidentiality and access-control requirements. | SI | IP-RS | GDPR | €2,000 | ↗ |
| 17 Dec 2020 | Ordine degli Assistenti Sociali della Regione LazioOrdine degli Assistenti Sociali della Regione Lazio was fined EUR 2,000 by the Garante. The authority found that the entity failed to respond to a request for access to personal data, which is a breach of GDPR Article 15. | IT | Garante | GDPR | €2,000 | ↗ |
| 29 Apr 2025 | Tirrenia Hospital S.r.l.Tirrenia Hospital S.r.l. was fined by the Garante EUR 2,000 for breaching the data processing principles set out in GDPR Article 5. The case concerned processing in the healthcare sector, where a particularly high level of compliance is required. | IT | Garante | GDPR | €2,000 | ↗ |
| 29 May 2026 | Unicredit Bank SAUnicredit Bank SA was fined EUR 2,000 by ANSPDCP. The authority found that the bank failed to notify a personal data breach within the required 72-hour deadline. | RO | ANSPDCP | GDPR | €2,000 | ↗ |
| 17 Apr 2026 | Sicra PressThe Garante imposed a 2,000 EUR fine on Sicra Press for using non-anonymized data in articles related to judicial matters. The authority found a breach of data protection rules. | IT | Garante | GDPR | €2,000 | ↗ |
| 22 Feb 2024 | BLU MANAGEMENT SPAIN, S.L.BLU MANAGEMENT SPAIN, S.L. was fined €2,000 by the AEPD for sharing a job applicant’s contact details without consent. The authority treated this as a breach of data protection rules. | ES | AEPD | GDPR | €2,000 | ↗ |
| 01 Jan 2020 | VOLTIMUM, S.A.VOLTIMUM, S.A. was fined EUR 2,000 by the AEPD for sending commercial emails after the recipient had opted out. The authority found this to be a breach of Article 21 of the LSSI on marketing communications. | ES | AEPD | ePrivacy | €2,000 | ↗ |
| 04 Sept 2024 | Agrotikos Elaiourgikos Synetairismos StylidasAgrotikos Elaiourgikos Synetairismos Stylidas was fined EUR 2,000 by the HDPA. The authority found breaches of data minimization and transparency principles, as well as inadequate technical and organizational measures in its video surveillance system. | GR | HDPA | GDPR | €2,000 | ↗ |
| 15 Apr 2021 | Ordine degli Avvocati di RomaOrdine degli Avvocati di Roma was fined €2,000 by the Garante for a significant delay in responding to a data subject access request. The case highlights a failure to meet the required timelines for handling access requests under data protection rules. | IT | Garante | GDPR | €2,000 | ↗ |
| 01 Sept 2025 | Osnovna škola XAZOP imposed a fine of EUR 2,000 on Osnovna škola X for breaching GDPR rules on personal data processing. The case involved unlawful processing of personal data, indicating a compliance failure under data protection requirements. | HR | AZOP | GDPR | €2,000 | ↗ |
| 09 Mar 2023 | Consorzio Concessioni Reti Gas S.c.a.r.l.The Garante fined Consorzio Concessioni Reti Gas S.c.a.r.l. EUR 2,000 for GDPR breaches linked to the improper handling of email accounts and the failure to provide data processing information after an internship ended. The case highlights deficiencies in information duties and access control over personal data. | IT | Garante | GDPR | €2,000 | ↗ |
| 21 Jul 2025 | VIVLIOPOLEION TIS ESTIAS, I.D. KOLLAROU & SIA A.E.The company was fined by the HDPA in the amount of €2,000 for failing to build data protection into the design of its processing and for not applying privacy by default. The authority treated this as a breach of GDPR requirements on privacy by design and by default. | GR | HDPA | GDPR | €2,000 | ↗ |
| 17 Feb 2025 | Meedea Construct Prest SRLThe company was fined for violating the principles and lawfulness of personal data processing, specifically Articles 6 and 9 of the GDPR. A corrective measure was also imposed to ensure GDPR compliance in data collection and processing and to reduce the risk of unauthorized access and disclosure. | RO | ANSPDCP | GDPR | €2,000 | ↗ |
| 10 Jun 2020 | Istituto autonomo per le case popolari della provincia di IserniaIstituto autonomo per le case popolari della provincia di Isernia was fined EUR 2,000 by the Garante. The authority found that personal data, including health information, had been published on the institutional website without a proper legal basis. | IT | Garante | GDPR | €2,000 | ↗ |
| 09 May 2024 | IRIDEX GROUP SALUBRIZARE SRLIRIDEX GROUP SALUBRIZARE SRL was fined by ANSPDCP 2,000 EUR for sending a collective email to clients with recipients' email addresses visible. The incident resulted in unauthorized disclosure of personal data. | RO | ANSPDCP | GDPR | €2,000 | ↗ |
| 21 May 2021 | COOPERA RC SERVICES, S.L.COOPERA RC SERVICES, S.L. was fined by the AEPD 2,000 EUR for failing to provide the contact details needed to exercise data protection rights. The authority found a breach of the information obligations under Article 13 GDPR. | ES | AEPD | GDPR | €2,000 | ↗ |
| 23 Jun 2020 | COMUNIDAD DE PROPIETAROS R.R.R.The entity was fined for installing video surveillance cameras without the required informational signage. The case concerned a breach of data protection rules and the obligation to properly inform individuals subject to monitoring. | ES | AEPD | GDPR | €2,000 | ↗ |
| 18 Jan 2021 | MEJORFRESCO TIENDA ONLINE, S.L.MEJORFRESCO TIENDA ONLINE, S.L. was fined by the AEPD EUR 2,000 for sending advertising emails without the recipient's consent. The case concerned Article 21 of the LSSI and reflects unlawful direct marketing practices. | ES | AEPD | ePrivacy | €2,000 | ↗ |