BULLETIN №082Last updated · 30 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.2%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 09 May 2024 | Polisportiva Mimmo Ferrito s.r.l.The Garante fined Polisportiva Mimmo Ferrito s.r.l. EUR 3,000 for failing to respond to a data subject's request to exercise their rights. The case concerns non-compliance with data protection obligations. | IT | Garante | GDPR | €3,000 | ↗ |
| 09 May 2024 | HEADBLUE MARKETING, S.L.HEADBLUE MARKETING, S.L. was fined by the AEPD in the amount of 1,000 EUR for sending unsolicited commercial electronic communications without consent. The authority also found a failure to respond to access requests. | ES | AEPD | ePrivacy | €1,000 | ↗ |
| 09 May 2024 | MEDICOVER SRLMEDICOVER SRL was fined EUR 1,000 by ANSPDCP for the unauthorized disclosure of personal data from a medical consultation report to an unintended patient. The case concerns a breach of confidentiality involving special-category data and indicates a need to strengthen access controls and recipient verification procedures. | RO | ANSPDCP | GDPR | €1,000 | ↗ |
| 09 May 2024 | Provvedimento del 9 maggio 2024 [10027595]The authority imposed a fine on an anonymized healthcare entity for unauthorized access to patient health records by personnel without proper authorization. The case concerned GDPR requirements on data protection and processing security. | IT | Garante | GDPR | €25,000 | ↗ |
| 09 May 2024 | Unicredit S.p.a.Unicredit S.p.a. was fined EUR 30,000 by the Garante for failing to respond to a personal data access request submitted by an heir. The authority found a breach of GDPR Article 15 and the Italian privacy code. | IT | Garante | GDPR | €30,000 | ↗ |
| 09 May 2024 | Vodafone Italia S.p.A.Vodafone Italia S.p.A. was fined EUR 500,000 by the Garante for violations related to telemarketing and teleselling. The authority found that individuals listed in the opposition register were contacted without proper consent. | IT | Garante | GDPR | €500,000 | ↗ |
| 09 May 2024 | IRIDEX GROUP SALUBRIZARE SRLIRIDEX GROUP SALUBRIZARE SRL was fined by ANSPDCP 2,000 EUR for sending a collective email to clients with recipients' email addresses visible. The incident resulted in unauthorized disclosure of personal data. | RO | ANSPDCP | GDPR | €2,000 | ↗ |
| 09 May 2024 | Caffetteria 77 di Dughetti BarbaraThe Garante fined Caffetteria 77 di Dughetti Barbara EUR 3,000 for operating a video surveillance system without meeting the legal requirements. The system captured both customers and employees, creating a data protection compliance breach. | IT | Garante | GDPR | €3,000 | ↗ |
| 08 May 2024 | CENTRUL MEDICAL UNIREA SRLCENTRUL MEDICAL UNIREA SRL was fined EUR 5,000 by ANSPDCP for unauthorized disclosure of personal data on the internet. The case indicates a breach of data protection rules and warrants review of security controls and publication procedures. | RO | ANSPDCP | GDPR | €5,000 | ↗ |
| 08 May 2024 | CREMA GAMES, S.L.CREMA GAMES, S.L. was fined EUR 5,000 by the AEPD for breaching Article 15 of the GDPR. The company obstructed the complainant’s exercise of the right of access to their personal data. | ES | AEPD | GDPR | €5,000 | ↗ |
| 08 May 2024 | Genpact România SRLThe ANSPDCP imposed a fine of EUR 3,000 on Genpact România SRL. The sanction concerned sending a file containing recruitment data to an unauthorized employee email address. The incident indicates a failure to control access to personal data and maintain confidentiality. | RO | ANSPDCP | GDPR | €3,000 | ↗ |
| 08 May 2024 | DIMAGAZA, S.L.DIMAGAZA, S.L. was fined by the AEPD 1,000 EUR for posting personal data of employees affected by a collective dismissal on a notice board accessible to outsiders. The authority found a breach of the principles of integrity and confidentiality. | ES | AEPD | GDPR | €1,000 | ↗ |
| 08 May 2024 | KVIKU SPAIN, S.L.KVIKU SPAIN, S.L. was fined EUR 600 by the AEPD for failing to provide access to personal data and related information. The authority found a breach of Article 58(1) of the GDPR. | ES | AEPD | GDPR | €600 | ↗ |
| 07 May 2024 | PINKGREEN BARCELONA, S.L.PINKGREEN BARCELONA, S.L. was fined by the AEPD 4,000 EUR for disclosing personal data of individuals in responses to negative Google reviews. The authority found that the processing breached Articles 6 and 9 of the GDPR. | ES | AEPD | GDPR | €4,000 | ↗ |
| 06 May 2024 | DQG NORTE A.I.E.DQG NORTE A.I.E. was fined by the AEPD for collecting copies of identity documents and personal data of minors and their guardians without proper data protection information. The authority found breaches of GDPR data minimization and transparency principles. | ES | AEPD | GDPR | €5,000 | ↗ |
| 03 May 2024 | D.D.D.The entity published images of a minor on its Telegram channel without consent, breaching data protection rules. AEPD imposed a fine of EUR 5,000. | ES | AEPD | GDPR | €5,000 | ↗ |
| 30 Apr 2024 | Dane anonimowe (Stowarzyszenie F. z siedzibą w X. przy ul.)UODO imposed an administrative fine on Association F. for failing to notify the supervisory authority of a personal data breach without undue delay, and no later than 72 hours after becoming aware of it. The case concerns the obligation to report data security incidents within the required timeframe. | PL | UODO | GDPR | €212 | ↗ |
| 29 Apr 2024 | Csomagküldő cég adatkezeléseThe controller was fined for sending emails without a proper legal basis and for failing to respond to a data protection complaint. The authority found breaches of GDPR Articles 5 and 13. | HU | NAIH | GDPR | €12,750 | ↗ |
| 29 Apr 2024 | Dane anonimowe (A. Sp. k. z siedzibą w T.)UODO imposed a PLN 238,345 administrative fine on A. Sp. k. for failing to implement appropriate technical and organizational measures proportionate to the risk of data processing, including the use of external storage media. The authority also found a lack of regular testing, measurement, and evaluation of the effectiveness of the security measures in place. | PL | UODO | GDPR | €55,103 | ↗ |
| 26 Apr 2024 | Nationalt Genom CenterThe Danish DPA fined Nationalt Genom Center 50,000 DKK for processing personal data without consulting the supervisory authority. Its own DPIA identified a high risk, which should have triggered prior consultation before processing began. | DK | Datatilsynet | GDPR | €6,705 | ↗ |