BULLETIN №082Last updated · 29 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 22 Nov 2021 | SCF ZHU, S.L.SCF ZHU, S.L. was fined by the AEPD 1,000 EUR for failing to display visible information signs for its video surveillance system and for not maintaining a record of processing activities. The case reflects deficiencies in basic transparency and documentation obligations under data protection rules. | ES | AEPD | GDPR | €1,000 | ↗ |
| 18 Aug 2025 | SC Elite Conta SRLThe National Supervisory Authority for Personal Data Processing completed an investigation in July 2025 at SC Elite Conta SRL and found a GDPR violation. The company was fined for failing to properly notify a personal data security breach. | RO | ANSPDCP | GDPR | €3,000 | ↗ |
| 19 Jun 2025 | SC Diamir SRLIn May 2025, ANSPDCP completed an investigation at SC Diamir SRL and found violations of GDPR provisions. The company received a warning and a fine of EUR 1,000. | RO | ANSPDCP | GDPR | €1,000 | ↗ |
| 09 Nov 2022 | SC Das Sense Society SRLSC Das Sense Society SRL was fined EUR 1,000 by ANSPDCP. The authority found a GDPR breach for failing to provide the requested information. | RO | ANSPDCP | GDPR | €1,000 | ↗ |
| 16 Sept 2024 | SC Class IT Outsourcing SRLSC Class IT Outsourcing SRL was fined EUR 1,000 by ANSPDCP for GDPR violations. The case concerned non-compliance with personal data protection requirements. | RO | ANSPDCP | GDPR | €1,000 | ↗ |
| 25 Jan 2018 | Scaramuzza MarioScaramuzza Mario was fined EUR 140,000 by the Garante for the unauthorized activation of multiple payment cards using personal data without the consent of the individuals concerned. The case indicates a breach of lawful processing requirements and the absence of a valid legal basis. | IT | Garante | GDPR | €140,000 | ↗ |
| 17 Sept 2020 | Scanshare s.r.l.Scanshare s.r.l. was fined by the Garante 60,000 EUR for inadequate technical and organizational measures in handling candidate data during a hospital recruitment process. The authority also found a breach of GDPR Article 13 because the required information was not provided to candidates. | IT | Garante | GDPR | €60,000 | ↗ |
| 06 Jun 2023 | S.C.In May 2023, ANSPDCP completed an investigation at operator S.C. and found a violation of GDPR provisions. As a result, a fine of EUR 3,000 was imposed. | RO | ANSPDCP | GDPR | €3,000 | ↗ |
| 09 Jun 2021 | S.C.The operator was fined by ANSPDCP for failing to provide requested information to the supervisory authority. This constituted a breach of GDPR requirements. | RO | ANSPDCP | GDPR | €2,000 | ↗ |
| 15 Jun 2022 | S.C.In May 2022, the Romanian supervisory authority ANSPDCP completed an investigation into the operator S.C. and found a violation of GDPR provisions. A fine of 3,000 EUR was imposed. | RO | ANSPDCP | GDPR | €3,000 | ↗ |
| 24 Jan 2013 | Saverio ProcopioSaverio Procopio was fined €16,800 by the Garante for sending unsolicited promotional emails without obtaining explicit consent from recipients. The authority also found that the required privacy notice was not provided, in breach of the Italian Data Protection Code. | IT | Garante | GDPR | €16,800 | ↗ |
| 16 Jun 2020 | SAUNIER-TEC, MANTENIMIENTOS DE CALOR Y FRIO, S.LSAUNIER-TEC was fined EUR 6,000 by the AEPD for a data breach. The incident involved unauthorized access to personal data and bank account information, breaching GDPR Articles 33 and 34. | ES | AEPD | GDPR | €6,000 | ↗ |
| 08 Feb 2023 | SatsThe Norwegian DPA, Datatilsynet, fined Sats 10,000,000 NOK for breaches of GDPR requirements. The case concerned data subjects' rights to information, access, and erasure, as well as the lack of a legal basis for processing certain personal data. | NO | Datatilsynet | GDPR | €906,000 | ↗ |
| 22 Feb 2024 | S.A.T.E. (Servizi Ambiente Territorio Energia)The Garante fined S.A.T.E. 6,000 EUR for breaches of data protection principles, including lawfulness, integrity, and confidentiality. The authority found that inadequate security measures led to unauthorized access to data. | IT | Garante | GDPR | €6,000 | ↗ |
| 16 Nov 2017 | Sarida s.r.l.Sarida s.r.l. was fined by the Italian Garante 10,000 EUR for inadequate security measures in the processing of personal data. The authority specifically noted insufficient password requirements for access to the company’s systems. | IT | Garante | GDPR | €10,000 | ↗ |
| 12 Mar 2024 | SARARTE, S.L.SARARTE, S.L. was fined 6,000 EUR by the AEPD for disclosing personal data, including a private mobile number, to 18 people without consent. The case indicates a breach of data protection rules and unauthorized sharing of information. | ES | AEPD | GDPR | €6,000 | ↗ |
| 01 Oct 2015 | San Vincenzo di Fernando Rota s.r.l.San Vincenzo di Fernando Rota s.r.l. was fined by the Garante for processing employees’ biometric data without notifying the authority and without requesting prior verification. The conduct breached privacy rules and the requirements applicable to sensitive data processing. | IT | Garante | GDPR | €30,000 | ↗ |
| 22 Jul 2019 | SANTI 3000, S.L.SANTI 3000, S.L. was fined by the AEPD for using video surveillance footage without informing employees. The authority treated this as a breach of data protection principles. | ES | AEPD | GDPR | €5,500 | ↗ |
| 26 Apr 2024 | SANTANDER CONSUMER, S.A.SANTANDER CONSUMER, S.A. was fined by the AEPD in the amount of 50,000 EUR for sending postal advertising after the complainant had exercised the right to object to processing for marketing purposes. The case concerns failure to respect the data subject’s objection to commercial use of personal data. | ES | AEPD | GDPR | €50,000 | ↗ |
| 01 Jan 2024 | SANTANDER CONSUMER FINANCE, S.A.Santander Consumer Finance, S.A. was fined by the AEPD 500,000 EUR for a data protection breach. The incident affected personal identification and contact data of 28,120 individuals. | ES | AEPD | GDPR | €500,000 | ↗ |