BULLETIN №082Last updated · 29 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 24 Apr 2013 | Free Time s.r.l.Free Time s.r.l. was fined EUR 54,000 by the Italian Garante. The case concerned the registration of numerous phone cards to unaware third parties without providing the required information on data processing. | IT | Garante | GDPR | €54,000 | ↗ |
| 20 Mar 2008 | GS S.p.A.GS S.p.A. was fined for collecting personal data in connection with a loyalty card program without providing adequate notice to data subjects. The authority found a breach of Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €54,000 | ↗ |
| 11 Dec 2008 | Eutelia S.p.A.Eutelia S.p.A. was fined by the Garante for processing personal data without providing the required privacy notice. The breach occurred during the activation of an unsolicited telephone service and concerned Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €54,000 | ↗ |
| 21 Mar 2013 | Compu & Games srlCompu & Games srl was fined EUR 54,000 by the Garante. The company registered numerous phone cards to unaware third parties without providing the required data protection information. | IT | Garante | GDPR | €54,000 | ↗ |
| 23 May 2022 | ANOIXISThe fine was imposed for sending unsolicited SMS messages for direct marketing without prior consent. The company also failed to provide a valid opt-out address, affecting data subjects’ rights of access and objection. | GR | HDPA | ePrivacy | €54,000 | ↗ |
| 08 Feb 2007 | RFI S.p.A.RFI S.p.A. was fined EUR 54,000 by the Garante for failing to provide the required data protection information to individuals covered by video surveillance at several train stations. The authority found a breach of data protection rules. | IT | Garante | GDPR | €54,000 | ↗ |
| 26 Feb 2019 | телекомуникационен операторThe telecommunications operator was fined BGN 53,000 by the CPDP for processing personal data without consent. The case involved changing a subscription plan to a prepaid service without the data subject's knowledge or agreement. | BG | CPDP | GDPR | €27,099 | ↗ |
| 20 Jan 2015 | SYNERTEC GROUP S.L.SYNERTEC GROUP S.L. was fined by the AEPD in the amount of €52,000 for sending unsolicited commercial emails. The conduct breached Article 21 of the LSSI, which restricts marketing communications without prior consent. | ES | AEPD | ePrivacy | €52,000 | ↗ |
| 02 Apr 2020 | XFERA MÓVILES, S.A.XFERA MÓVILES, S.A. was fined EUR 52,000 by the AEPD for sending SMS messages to a complainant about another customer's unpaid bills. The authority found that this disclosure breached data protection rules. | ES | AEPD | GDPR | €52,000 | ↗ |
| 24 Jan 2013 | Gruppo Finelco s.p.a.Gruppo Finelco s.p.a. was fined EUR 52,000 by the Garante for processing personal data without providing adequate information to data subjects. The company also failed to notify the Garante about profiling activities carried out through its websites. | IT | Garante | GDPR | €52,000 | ↗ |
| 16 Dec 2021 | LiikennevakuutuskeskusThe entity was fined for collecting patient data excessively for insurance claim resolution. The authority found breaches of data minimization and fairness principles. | FI | TSV | GDPR | €52,000 | ↗ |
| 01 Mar 2018 | Priolo Servizi S.c.p.A.Priolo Servizi S.c.p.A. was fined EUR 52,000 for the unlawful processing of biometric data of about 6,700 workers. The authority found that the company failed to properly notify the Garante and provided inadequate information to the data subjects. | IT | Garante | GDPR | €52,000 | ↗ |
| 01 Mar 2023 | Spółdzielnie Mieszkaniową „UODO imposed an administrative fine of PLN 51,876 on the controller for failing to notify the supervisory authority of a personal data breach without undue delay. The authority also found that the affected data subject was not informed about the breach. | PL | UODO | GDPR | €11,098 | ↗ |
| 30 Jan 2026 | deținătorul site-ului evita-teparii.roANSPDCP imposed total fines of 51,000 lei, about 10,000 euro, on the operator, a natural person who runs the site evita-teparii.ro. The case involved multiple GDPR breaches, including the unlawful publication of identity, contact, sensitive, and alleged criminal data without a legal basis. | RO | ANSPDCP | GDPR | €10,007 | ↗ |
| 25 Mar 2021 | Centro diagnostico italiano di MilanoThe Italian Data Protection Authority imposed a fine of EUR 50,000 on Centro diagnostico italiano di Milano. The sanction concerned violations of data protection rules. | IT | Garante | GDPR | €50,000 | ↗ |
| 24 Apr 2025 | Darian Bishop trading as ECO4UBetween 9 January 2023 and 9 October 2023, 194,110 unsolicited direct marketing calls were made to subscribers registered with the TPS who had not indicated consent to receive such calls. The conduct generated 21 complaints to the Commissioner and the TPS, leading to an ICO fine. | GB | ICO | GDPR | €58,480 | ↗ |
| 05 Jun 2020 | EDP Energía, S.A.U.EDP Energía, S.A.U. was fined €50,000 by the AEPD for processing personal data without consent. The authority found this conduct to be in breach of Article 6(1) of the GDPR. | ES | AEPD | GDPR | €50,000 | ↗ |
| 13 May 2022 | UNIDAD EDITORIAL INFORMACIÓN GENERAL, S.L.U.The entity published an audio recording of a victim's court testimony without consent. AEPD found this to be a breach of data protection law and imposed a 50,000 EUR fine. | ES | AEPD | GDPR | €50,000 | ↗ |
| 29 Oct 2020 | Ministero dell’InternoThe Italian Data Protection Authority fined the Ministry of the Interior EUR 50,000 for the incorrect disclosure of personal data to a limited number of organizations. It also ordered the Ministry to consider training initiatives to improve data accuracy. | IT | Garante | GDPR | €50,000 | ↗ |
| 24 Jun 2021 | NEXTGEN FINANCIAL SERVICES S.L.NEXTGEN FINANCIAL SERVICES S.L. failed to update the address in a loan contract and did not correct inaccurate data in a credit file. The AEPD found this to be a breach of the right to data rectification and imposed a fine of 50,000 EUR. | ES | AEPD | GDPR | €50,000 | ↗ |