BULLETIN №082Last updated · 29 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 29 May 2023 | SERVICIOS E INTERVENCIONES EN EDIFICACION DEL MEDITERRÁNEO, S.L.The company published an image on its website without the individual's express consent. The authority treated the case as a repeat infringement because the company had previously been sanctioned for the same conduct. | ES | AEPD | GDPR | €2,000 | ↗ |
| 06 Mar 2025 | SERVICIOS DE INTEGRACIÓN DE ANDALUCÍASERVICIOS DE INTEGRACIÓN DE ANDALUCÍA was fined €2,000 by the AEPD for adding an employee’s personal phone number to a work WhatsApp group without consent. The authority found a breach of the GDPR lawful-basis requirement under Article 6(1). | ES | AEPD | GDPR | €2,000 | ↗ |
| 01 Jan 2017 | SERVICIOS DE INFORMACIÓN SOBRE LOS FICHEROS DE MOROSOS S.L.The entity sent commercial emails and SMS without proper consent and did not honor recipients’ objections. These actions breached data protection rules. | ES | AEPD | ePrivacy | €1,000 | ↗ |
| 04 Aug 2014 | SERVICIOS DE DEPILACION BLOC, S.L.SERVICIOS DE DEPILACION BLOC, S.L. was fined by the AEPD EUR 3,000 for sending unsolicited commercial SMS messages to a former client. The authority found that this conduct breached Article 21 of the LSSI on marketing communications. | ES | AEPD | ePrivacy | €3,000 | ↗ |
| 04 Aug 2014 | SERVICIOS DE DEPILACION BLOC, S.L.SERVICIOS DE DEPILACION BLOC, S.L. was fined by the AEPD 4,000 EUR for sending unsolicited commercial SMS messages to a former client. The conduct breached Article 21 of the LSSI on marketing communications without prior consent. | ES | AEPD | ePrivacy | €4,000 | ↗ |
| 08 Oct 2020 | Servicio de Alojamientos Responsables, S.L.The entity was fined by the AEPD 6,000 EUR for processing personal data without a legal basis. The breach involved signing a contract on behalf of an individual without authorization. | ES | AEPD | GDPR | €6,000 | ↗ |
| 10 Oct 2024 | Service Box Group LimitedService Box Group Limited made 5,361 marketing calls to individuals in breach of regulation 21 of PECR. The ICO imposed a fine of GBP 40,000 and issued an enforcement notice. | GB | ICO | ePrivacy | €47,796 | ↗ |
| 13 Sept 2017 | Serval s.r.l.Serval s.r.l. was fined by the Garante in the amount of €10,000 for failing to adopt minimum security measures. The authority also found that employees were not appointed as data processors, in breach of the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 01 Oct 2024 | SERVACE, S.L.SERVACE, S.L. was fined by the AEPD EUR 1,400 for using an employee’s personal email address for work purposes without consent. The authority found this breached GDPR Articles 6(1) and 5(1)(f). | ES | AEPD | GDPR | €1,400 | ↗ |
| 12 Nov 2014 | Sergio FioreseSergio Fiorese was fined EUR 2,400 by the Garante for failing to provide data subjects with the required information about the processing of personal data. The breach concerned a video surveillance system at the association “Sottosopra”. | IT | Garante | GDPR | €2,400 | ↗ |
| 17 Oct 2024 | Serfin 97 S.r.l.Serfin 97 S.r.l. was fined EUR 60,000 by the Garante for unlawful processing of personal data. The company used a third party’s email address to contact a debtor for debt recovery purposes, which breached data protection rules. | IT | Garante | GDPR | €60,000 | ↗ |
| 29 Mar 2018 | SERCOM S.r.l.SERCOM S.r.l. was fined EUR 20,000 by the Garante. The authority found that the company failed to notify changes to its name and the cessation of data processing activities related to economic solvency risk. | IT | Garante | GDPR | €20,000 | ↗ |
| 04 Aug 2022 | Sephora Cosmetics România SASephora Cosmetics România SA was fined EUR 2,000 by ANSPDCP for violating GDPR provisions. The case concerned non-compliance with personal data protection requirements. | RO | ANSPDCP | GDPR | €2,000 | ↗ |
| 07 Jul 2022 | Senseonics Inc.Senseonics Inc. was fined EUR 45,000 by the Garante for violations related to the processing of personal data. The authority cited issues with data integrity and confidentiality, including health data. | IT | Garante | GDPR | €45,000 | ↗ |
| 07 Mar 2025 | SENDING TRANSPORTE Y COMUNICACIÓN, S.A.SENDING TRANSPORTE Y COMUNICACIÓN, S.A. was fined EUR 80,000 by the AEPD for breaching GDPR Articles 28(2) and 28(4). The company subcontracted data processing without the required authorization. | ES | AEPD | GDPR | €80,000 | ↗ |
| 14 Dec 2017 | SEMS – Servizi per la mobilità sostenibile S.r.l.SEMS – Servizi per la mobilità sostenibile S.r.l. was fined EUR 20,000 by the Garante. The authority found that the company failed to meet notification obligations linked to the installation of satellite tracking devices in its vehicle fleet, in breach of data protection rules. | IT | Garante | GDPR | €20,000 | ↗ |
| 01 Oct 2015 | Semplice viaggi s.r.l.Semplice viaggi s.r.l. was fined EUR 6,400 by the Garante for providing insufficient information to users on its website and for pre-setting consent to the processing of personal data for promotional purposes. The authority found these practices to be in breach of data protection rules. | IT | Garante | GDPR | €6,400 | ↗ |
| 08 Jul 2025 | Selgros Cash & Carry SRLIn June 2025, ANSPDCP completed an investigation at Selgros Cash & Carry SRL and found a GDPR violation. The operator was fined EUR 3,000. | RO | ANSPDCP | GDPR | €3,000 | ↗ |
| 15 Sept 2016 | SELF TRADE BANK, SAUSELF TRADE BANK, SAU was fined by the AEPD EUR 2,000 for sending unsolicited commercial emails to a customer. The customer had not authorized the use of their personal data for promotional purposes, which breached Article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €2,000 | ↗ |
| 06 Jul 2006 | Selework s.a.s.Selework s.a.s. was fined EUR 258 by the Garante for failing to provide candidates with adequate information about the processing of their personal data in job advertisements. The authority found a breach of Article 13 of the Codice Privacy. | IT | Garante | GDPR | €258 | ↗ |