BULLETIN №082Last updated · 30 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.2%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 26 Apr 2024 | SANTANDER CONSUMER, S.A.SANTANDER CONSUMER, S.A. was fined by the AEPD in the amount of 50,000 EUR for sending postal advertising after the complainant had exercised the right to object to processing for marketing purposes. The case concerns failure to respect the data subject’s objection to commercial use of personal data. | ES | AEPD | GDPR | €50,000 | ↗ |
| 25 Apr 2024 | SOCIETE EXPLOITANT DES MAGASINS DE CHAUSSURES ET D'HABILLEMENT DE SPORT (procédure simplifiée)The CNIL imposed an administrative fine of EUR 15,000 on SOCIETE EXPLOITANT DES MAGASINS DE CHAUSSURES ET D'HABILLEMENT DE SPORT. The case was handled under a simplified procedure. | FR | CNIL | GDPR | €15,000 | ↗ |
| 25 Apr 2024 | ALL IN DIGITAL MARKETING, S.L.ALL IN DIGITAL MARKETING, S.L. was fined by the AEPD EUR 3,000 for sending unsolicited commercial emails without prior consent from recipients. The authority found this conduct to be in breach of Article 21 of the LSSI. | ES | AEPD | ePrivacy | €3,000 | ↗ |
| 25 Apr 2024 | REVUE LITTERAIRE FRANCAISE (procédure simplifiée)The CNIL imposed a EUR 3,000 penalty on REVUE LITTERAIRE FRANCAISE under a simplified procedure. The case concerns the liquidation of an astreinte, meaning enforcement of a previously ordered monetary obligation. | FR | CNIL | GDPR | €3,000 | ↗ |
| 25 Apr 2024 | ASSOCIATION PARTICIPANT AUX ACTIVITES DES ORGANISATIONS POLITIQUES (procédure simplifiée)The CNIL imposed an administrative fine of EUR 16,000 on ASSOCIATION PARTICIPANT AUX ACTIVITES DES ORGANISATIONS POLITIQUES. The authority also issued an injunction requiring corrective action. | FR | CNIL | GDPR | €16,000 | ↗ |
| 24 Apr 2024 | C.I.EL. S.p.A.C.I.EL. S.p.A. was fined 10,000 EUR by the Garante following a complaint from a former employee. The case concerned violations related to the right of access to training certificates. | IT | Garante | GDPR | €10,000 | ↗ |
| 24 Apr 2024 | Rossi Carta S.r.l. UnipersonaleRossi Carta S.r.l. Unipersonale was fined by the Garante 30,000 EUR for sending unsolicited promotional emails and failing to respond to a data subject rights request. The authority also noted the use of an outdated content management system on the company website, which created potential security risks for personal data. | IT | Garante | GDPR | €30,000 | ↗ |
| 24 Apr 2024 | I.N.P.A.S.The Garante imposed a fine on I.N.P.A.S. for violations related to the processing of employees' personal data, including sensitive data. The authority found that the processing did not ensure lawfulness, fairness, transparency, and data minimization. | IT | Garante | GDPR | €3,000 | ↗ |
| 24 Apr 2024 | Dane anonimowe (Komitet Inicjatywy Ustawodawczej W. na rzecz ustawy o zmianie ustawy z dn. 24 lipca 2015 r. Prawo o zgromadzeniach oraz niektórych innych ustaw)UODO imposed an administrative fine on the entity responsible for a list of citizens supporting a legislative initiative. The authority found inadequate technical and organisational measures for the risk, a failure to regularly test security controls, and delays in reporting and notifying the personal data breach. | PL | UODO | GDPR | €2,527 | ↗ |
| 24 Apr 2024 | Dly S.r.l.Dly S.r.l. was fined by the Garante EUR 5,000 for deploying a non-compliant video surveillance system. The system recorded both customers and employees, in breach of data protection rules. | IT | Garante | GDPR | €5,000 | ↗ |
| 24 Apr 2024 | Gestore Dei Servizi Energetici - Gse S.p.A.The Garante fined Gestore Dei Servizi Energetici - Gse S.p.A. 30,000 EUR for failing to respond to a data subject access request. The request concerned the individual's personal performance evaluation records for 2019 and 2020. | IT | Garante | GDPR | €30,000 | ↗ |
| 23 Apr 2024 | ALPHA BANK ROMANIA SAALPHA BANK ROMANIA SA was fined by ANSPDCP for a data security breach caused by improper management of a record system by an employee. This led to unauthorized disclosure and access to the personal data of certain clients. | RO | ANSPDCP | GDPR | €2,000 | ↗ |
| 23 Apr 2024 | Odsherred KommuneOdsherred Kommune was fined by Datatilsynet for failing to implement adequate security measures, including encryption of laptops containing sensitive personal data. The deficiency resulted in a data breach. | DK | Datatilsynet | GDPR | €13,404 | ↗ |
| 22 Apr 2024 | S.C. Tensa Art Design S.A.In April 2024, ANSPDCP completed an investigation into S.C. Tensa Art Design S.A., the operator of www.lensa.ro. The authority found GDPR violations and imposed a fine of EUR 2,000. | RO | ANSPDCP | GDPR | €2,000 | ↗ |
| 22 Apr 2024 | B.B.B.The entity did not provide a way for the user to unsubscribe from the website. As a result, personal data was indexed on Google without the data subject’s consent. | ES | AEPD | GDPR | €300 | ↗ |
| 18 Apr 2024 | COMUNIDAD DE PROPIETARIOS R.R.R.The entity was fined for sending an email to all community members containing a list of individual heating consumption linked to specific apartments. The authority found this to be a breach of data protection rules. | ES | AEPD | GDPR | €600 | ↗ |
| 18 Apr 2024 | DELPASO CAR HIRE, S.L.U.DELPASO CAR HIRE, S.L.U. was fined by the AEPD EUR 2,000 for failing to provide a customer with access to their personal data. The authority found a breach of Article 15 of the GDPR. | ES | AEPD | GDPR | €2,000 | ↗ |
| 18 Apr 2024 | MOURO PRODUCCIONES, S.R.L.MOURO PRODUCCIONES, S.R.L. was fined by the AEPD 20,000 EUR for collecting copies of identity documents and personal data of minors and their guardians without proper data protection information. The authority found breaches of the data minimization and transparency principles. | ES | AEPD | GDPR | €20,000 | ↗ |
| 18 Apr 2024 | H&M Hennes & MauritzH&M Hennes & Mauritz GBC AB was fined for conducting camera surveillance without a legal basis and for failing to provide required information to data subjects. The authority found breaches of GDPR Articles 6(1) and 13. | SE | IMY | GDPR | €25,779 | ↗ |
| 17 Apr 2024 | BANCO BILBAO VIZCAYA ARGENTARIA, S.A.BBVA was fined EUR 100,000 by the AEPD for processing a payment to a new account without the account holder’s explicit consent. The authority found this conduct to be a breach of GDPR Article 6. | ES | AEPD | GDPR | €100,000 | ↗ |