BULLETIN №082Last updated · 30 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.2%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 16 Apr 2024 | ARRENDAMIENTOS DEUDORES, S.L.ARRENDAMIENTOS DEUDORES, S.L. accessed personal data in the ASNEF file without proper authorization. The AEPD found a breach of Article 6(1) GDPR and imposed a fine of EUR 2,000. | ES | AEPD | GDPR | €2,000 | ↗ |
| 15 Apr 2024 | BANCO BILBAO VIZCAYA ARGENTARIA, S.A.Banco Bilbao Vizcaya Argentaria, S.A. was fined by the AEPD for including personal data in a credit solvency file without proper prior notice. The authority found this to be a breach of data protection rules. | ES | AEPD | GDPR | €200,000 | ↗ |
| 12 Apr 2024 | Centrul Medical dr. Furtună DanThe National Supervisory Authority for Personal Data Processing imposed a fine on Centrul Medical dr. Furtună Dan for breaching Article 6 of the GDPR. The infringement concerned the absence of a proper legal basis for personal data processing. | RO | ANSPDCP | GDPR | €1,500 | ↗ |
| 12 Apr 2024 | TECNOCRÁTICA CENTRO DE DATOS S.L.TECNOCRÁTICA CENTRO DE DATOS S.L. was fined by the AEPD for failing to provide access to personal data and information requested during an investigation. The authority found a breach of Article 58.1 of the GDPR. | ES | AEPD | GDPR | €6,000 | ↗ |
| 12 Apr 2024 | DATACENTRICDATACENTRIC was fined by the AEPD 60,000 EUR for processing personal data of self-employed individuals without a valid legal basis. The data was also exposed online and used for marketing purposes, breaching GDPR Articles 6(1) and 14. | ES | AEPD | GDPR | €60,000 | ↗ |
| 11 Apr 2024 | BAR DEL PORTICO S.A.S.BAR DEL PORTICO S.A.S. was fined EUR 1,000 by the Garante for operating active video surveillance. The system recorded both customers and employees without meeting GDPR requirements. | IT | Garante | GDPR | €1,000 | ↗ |
| 11 Apr 2024 | Facile.Energy S.r.l.Facile.Energy S.r.l. was fined EUR 100,000 by the Garante for making unsolicited promotional calls without prior consent and activating energy supplies without a request from the customer. The authority found that these practices breached GDPR rules on data protection and security measures. | IT | Garante | GDPR | €100,000 | ↗ |
| 11 Apr 2024 | Innova Camera – Azienda speciale della Camera di commercio, industria, artigianato e agricoltura di RomaInnova Camera was fined by the Garante EUR 25,000 for inadequate data security measures. The breach resulted in personal data being accessed and published online following an SQL Injection attack. | IT | Garante | GDPR | €25,000 | ↗ |
| 11 Apr 2024 | Olimpia S.r.l.Olimpia S.r.l. was fined for making unsolicited promotional calls without prior consent and for using numbers listed in the Public Opposition Register. The conduct breached GDPR requirements on data protection and security measures. | IT | Garante | GDPR | €100,000 | ↗ |
| 11 Apr 2024 | Libero Consorzio comunale di EnnaThe Garante fined Libero Consorzio comunale di Enna €6,000 for improperly assigning tasks to the Data Protection Officer. Those tasks should have been performed by the data controller or processor, not the DPO. | IT | Garante | GDPR | €6,000 | ↗ |
| 11 Apr 2024 | Comune di MadignanoThe Garante fined Comune di Madignano EUR 3,000 for unlawfully using surveillance data in a disciplinary proceeding against an employee. The authority found breaches of data protection and transparency principles. | IT | Garante | GDPR | €3,000 | ↗ |
| 11 Apr 2024 | GS S.p.A.GS S.p.A. was fined by the Garante for failing to respond to an employee's access request. The request concerned disciplinary records and work time stamps, which constitutes a breach of GDPR Article 15. | IT | Garante | GDPR | €10,000 | ↗ |
| 11 Apr 2024 | Istituto Nazionale Previdenza Sociale - INPSThe Italian Data Protection Authority fined INPS EUR 20,000 for violating data protection principles. The case concerned the improper handling of candidates’ personal data in a public competition. | IT | Garante | GDPR | €20,000 | ↗ |
| 09 Apr 2024 | ADNAYA GREEN SOLUTIONS, S.L.ADNAYA GREEN SOLUTIONS, S.L. was fined by the AEPD EUR 10,000 for unlawfully sharing personal data with a third party without consent. The authority found this conduct breached Article 6(1) of the GDPR. | ES | AEPD | GDPR | €10,000 | ↗ |
| 08 Apr 2024 | VODAFONE ESPAÑA, S.A.U.The AEPD imposed a fine of 250,000 EUR on VODAFONE ESPAÑA, S.A.U. for failing to implement adequate measures to prevent unauthorized access to personal data. The authority found a breach of the GDPR confidentiality requirements. | ES | AEPD | GDPR | €250,000 | ↗ |
| 08 Apr 2024 | IBERDROLA CLIENTES, S.A.U.IBERDROLA CLIENTES, S.A.U. was fined by the AEPD 200,000 EUR for unlawfully including personal data in a credit information system without proper notification. The authority found this to be a breach of data protection rules. | ES | AEPD | GDPR | €200,000 | ↗ |
| 05 Apr 2024 | PALANCAMAR, S.L.PALANCAMAR, S.L. was fined EUR 5,000 by the AEPD for failing to inform a customer about the processing of their personal data during a vehicle purchase. The authority treated this as a breach of Article 13 GDPR. | ES | AEPD | GDPR | €5,000 | ↗ |
| 04 Apr 2024 | COMMERCE DE DETAIL DE MATERIEL DE TELECOMMUNICATIONCNIL imposed an administrative fine of EUR 525,000 on COMMERCE DE DETAIL DE MATERIEL DE TELECOMMUNICATION. The case concerns identified breaches of rules supervised by CNIL. | FR | CNIL | GDPR | €525,000 | ↗ |
| 04 Apr 2024 | SOCIETE AYANT POUR ACTIVITE LA PROSPECTION COMMERCIALE PAR COURRIEL POUR LE COMPTE D'ANNONCEURSThe CNIL imposed EUR 25,000 on SOCIETE AYANT POUR ACTIVITE LA PROSPECTION COMMERCIALE PAR COURRIEL POUR LE COMPTE D'ANNONCEURS as a liquidation of a penalty. The measure relates to non-compliance with a prior obligation and is enforcement in nature. | FR | CNIL | GDPR | €25,000 | ↗ |
| 04 Apr 2024 | GAFAS EN RED DE ÓPTICAS, S.L.GAFAS EN RED DE ÓPTICAS, S.L. was fined €10,000 by the AEPD for sending unsolicited advertising SMS messages without providing an opt-out link. The conduct breached the LSSI rules governing electronic marketing communications. | ES | AEPD | ePrivacy | €10,000 | ↗ |