BULLETIN №081Last updated · 28 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -20.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 05 Apr 2019 | Budapesti Műszaki és Gazdaságtudományi EgyetemBudapest University of Technology and Economics was fined 600,000 HUF by NAIH. The authority found that the university failed to comply with a data subject's request for access to personal data. | HU | NAIH | GDPR | €1,872 | ↗ |
| 25 Jun 2019 | Budapesti Rendőr-főkapitányságBudapesti Rendőr-főkapitányság was fined by NAIH 5,000,000 HUF for failing to report a personal data breach within the 72-hour deadline. The incident involved the loss of a pendrive containing personal data, in breach of GDPR Article 33. | HU | NAIH | GDPR | €15,400 | ↗ |
| 21 Mar 2024 | Budapesti Rendőr-főkapitányság XI. kerületi RendőrkapitányságBudapesti Rendőr-főkapitányság XI. kerületi Rendőrkapitányság was fined by NAIH 300,000 HUF for violations related to the closed handling of personal data. The authority found breaches of several provisions of the Hungarian Information Act (Infotv.). | HU | NAIH | GDPR | €762 | ↗ |
| 11 Jan 2024 | Build Lenders S.r.l.Build Lenders S.r.l. was fined EUR 10,000 by the Garante for unlawfully publishing personal data and failing to respond to a data deletion request. The authority found that the company breached GDPR rules on data protection and data subject rights. | IT | Garante | GDPR | €10,000 | ↗ |
| 03 Dec 2021 | Bűnügyi személyes adatok kezelése magánvádló általThe controller unlawfully transferred the complainant's criminal personal data, breaching the principles of lawful and fair processing and purpose limitation. The authority also found no legal basis for processing under the GDPR. | HU | NAIH | GDPR | €825 | ↗ |
| 19 Oct 2010 | BUONGIORNO MARKETING SERVICES ESPAÑA S.L.U.BUONGIORNO MARKETING SERVICES ESPAÑA S.L.U. was fined by the AEPD for sending unsolicited commercial SMS messages. The conduct breached Article 21 of the LSSI, which governs marketing communications without prior consent. | ES | AEPD | ePrivacy | €1,200 | ↗ |
| 06 Jul 2020 | Bureau Krediet Registratie (BKR)Bureau Krediet Registratie (BKR) was fined EUR 830,000 by the AP for not providing free electronic access to personal data. The authority found this practice breached the GDPR right of access. | NL | AP | GDPR | €830,000 | ↗ |
| 07 May 2015 | Burger Joint/Maria Galioni I.K.E.The company was fined for unlawfully operating a video surveillance system in the workplace. The authority found a privacy violation because employees and customers were monitored without proper justification. | GR | HDPA | GDPR | €3,000 | ↗ |
| 09 Jul 2020 | Burgo Group S.p.A.Burgo Group S.p.A. was fined EUR 20,000 by the Garante for violating GDPR principles. The case concerned improper restriction of access to an employee’s corporate email account, which was accessible to other staff members without the employee’s consent. | IT | Garante | GDPR | €20,000 | ↗ |
| 01 Jan 2015 | BUSCANDO SUERTE S.L.BUSCANDO SUERTE S.L. was fined by the AEPD €2,300 for sending unsolicited SMS messages. The messages misled recipients into replying and caused charges without any legitimate purpose. | ES | AEPD | ePrivacy | €2,300 | ↗ |
| 08 May 2013 | Business Services s.r.lBusiness Services s.r.l was fined EUR 6,400 by the Garante. The case concerned the sending of promotional faxes without the required information and without obtaining explicit consent from recipients. | IT | Garante | GDPR | €6,400 | ↗ |
| 11 Jul 2018 | BUSITALIA VENETO S.p.A.BUSITALIA VENETO S.p.A. was fined by the Garante for unlawful processing of personal data through the installation of a geolocation system on its public transport vehicles. The measure infringed employee privacy and data protection rules. | IT | Garante | GDPR | €10,000 | ↗ |
| 19 Jul 2018 | BUTALI S.P.A.BUTALI S.P.A. was fined €16,000 by the Garante for activating a SIM card without providing the required privacy information and obtaining the customer’s specific consent. The authority found this to be a breach of data protection rules. | IT | Garante | GDPR | €16,000 | ↗ |
| 23 Mar 2023 | CAAF CGIL Lombardia s.r.l.CAAF CGIL Lombardia s.r.l. was fined EUR 30,000 by the Garante for unlawful processing of personal data. The company sent promotional emails despite a prior request to delete the data. | IT | Garante | GDPR | €30,000 | ↗ |
| 17 Dec 2015 | Caaf Cgil Sardegna srlCaaf Cgil Sardegna srl was fined by the Garante 12,000 EUR for failing to provide the required privacy notice on its website. The authority found this to be a breach of Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €12,000 | ↗ |
| 17 Mar 2016 | Caaf Consulenti del lavoro srlCaaf Consulenti del lavoro srl was fined EUR 4,800 by the Garante. The authority found that the company failed to provide the required privacy notice for data collected through its website contact form and video surveillance system, in breach of Article 13 of the Italian Privacy Code. | IT | Garante | GDPR | €4,800 | ↗ |
| 11 Jul 2018 | CAA Liberi professionisti s.r.l.CAA Liberi professionisti s.r.l. was fined by the Garante in the amount of 12,400 EUR for failing to properly designate and instruct personnel involved in data processing. The authority found this to be a breach of data protection rules. | IT | Garante | GDPR | €12,400 | ↗ |
| 05 Nov 2025 | CABINET D'AVOCATS (procédure simplifiée)The CNIL imposed an administrative fine of EUR 5,000 on CABINET D'AVOCATS (procédure simplifiée). The case was handled under a simplified administrative procedure by the French data protection authority. | FR | CNIL | GDPR | €5,000 | ↗ |
| 01 Jan 2015 | CABLEUROPA SAUCABLEUROPA SAU was fined EUR 5,000 by the AEPD for sending unsolicited commercial emails and SMS messages to a customer. The recipient had previously exercised the right to cancel and opted out of receiving such communications. | ES | AEPD | ePrivacy | €5,000 | ↗ |
| 30 May 2011 | CABLEUROPA, S.A.U.CABLEUROPA, S.A.U. was fined EUR 600 by the AEPD for continuing to send advertising communications to an individual after repeated requests for data cancellation. The authority found a breach of Article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €600 | ↗ |