BULLETIN №082Last updated · 31 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.4%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 06 Sept 2017 | ORANGE ESPAGNE, S.A.U.ORANGE ESPAGNE, S.A.U. was fined EUR 66,000 by the AEPD for sending commercial SMS messages without consent. The authority also found that recipients were not given an effective option to object, in breach of the LSSI rules. | ES | AEPD | ePrivacy | €66,000 | ↗ |
| 12 Sept 2017 | Little Kook - K. Tzortzis – I. Thanos I.K.EThe company was fined EUR 7,000 by the HDPA for operating a video surveillance system without proper notification to the authority. It also monitored employee workspaces, which breached privacy requirements. | GR | HDPA | GDPR | €7,000 | ↗ |
| 13 Sept 2017 | Coleman s.p.a.Coleman s.p.a. was fined by the Garante 20,000 EUR for failing to implement minimum security measures for online booking requests. This allowed access to personal data without authentication. | IT | Garante | GDPR | €20,000 | ↗ |
| 13 Sept 2017 | NO QUIERO PERDER EL TIEMPO, S.L.The company was fined by the AEPD for displaying the AEPD quality seal and another association’s seal on its website without authorization. The authority also found inadequate information and no valid consent for data collection. | ES | AEPD | ePrivacy | €8,000 | ↗ |
| 13 Sept 2017 | Jump 3000 s.r.l.Jump 3000 s.r.l. was fined by the Garante 14,800 EUR for providing clients with inadequate data protection information. The authority found that the privacy notices did not properly identify the data controller. | IT | Garante | GDPR | €14,800 | ↗ |
| 13 Sept 2017 | MASTERZEN, S.L.MASTERZEN, S.L. was fined by the AEPD €4,500 for sending unsolicited marketing emails without the recipient’s consent. The emails were sent despite the recipient’s objection, indicating a breach of rules on direct electronic marketing. | ES | AEPD | ePrivacy | €4,500 | ↗ |
| 13 Sept 2017 | Serval s.r.l.Serval s.r.l. was fined by the Garante in the amount of €10,000 for failing to adopt minimum security measures. The authority also found that employees were not appointed as data processors, in breach of the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 19 Sept 2017 | CEPSA COMERCIAL PETRÓLEO, S.A.U.CEPSA was fined by the AEPD 3,300 EUR for sending two unsolicited commercial emails without prior consent from the recipients. The authority found this breached Article 21 of the LSSI on commercial communications. | ES | AEPD | ePrivacy | €3,300 | ↗ |
| 21 Sept 2017 | Tra.n.sider S.p.A.Tra.n.sider S.p.A. was fined EUR 20,000 by the Italian Garante. The case concerned the failure to notify the installation of a geolocation system on company vehicles, breaching data protection notification requirements. | IT | Garante | GDPR | €20,000 | ↗ |
| 21 Sept 2017 | AMI S.p.A.AMI S.p.A. was fined by the Garante for installing electronic monitoring and localization devices on public transport vehicles without proper notification. The authority found this to be a breach of data protection rules. | IT | Garante | GDPR | €40,000 | ↗ |
| 21 Sept 2017 | Unidata s.p.a.Unidata s.p.a. was fined EUR 36,000 by the Garante for failing to implement adequate security measures for personal data processing. The authority noted, among other issues, the use of passwords shorter than eight characters, which breached data protection requirements. | IT | Garante | GDPR | €36,000 | ↗ |
| 04 Oct 2017 | PRENATAL SAPRENATAL SA was fined by the AEPD EUR 20,000 for sending commercial SMS messages without providing recipients with an opt-out mechanism. The case concerns a breach of electronic communications rules and marketing consent requirements. | ES | AEPD | ePrivacy | €20,000 | ↗ |
| 05 Oct 2017 | Regione autonoma Valle d'AostaRegione autonoma Valle d'Aosta was fined by the Garante 100,000 EUR for publishing a regional council resolution on its institutional website that contained an employee’s personal data. The document included professional evaluations and transfer details. | IT | Garante | GDPR | €100,000 | ↗ |
| 05 Oct 2017 | Start S.p.A.Start S.p.A. was fined by the Garante 40,000 EUR for operating a geolocation system on its buses without full compliance with data protection rules. The case concerned location data processing without the required legal basis and safeguards. | IT | Garante | GDPR | €40,000 | ↗ |
| 05 Oct 2017 | Comune di CivitavecchiaComune di Civitavecchia was fined by the Garante for unlawfully transmitting sensitive data revealing the health status of disabled students to service providers without a proper legal basis. The authority found that the processing breached data protection and confidentiality requirements. | IT | Garante | GDPR | €30,000 | ↗ |
| 05 Oct 2017 | Regione autonoma Valle d'AostaRegione autonoma Valle d'Aosta was fined by the Garante for publishing a regional council resolution on its website that contained personal evaluations and information about an employee. The authority found this to be a breach of data protection rules. | IT | Garante | GDPR | €20,000 | ↗ |
| 05 Oct 2017 | Italprest di Luca Bosimini & C. s.a.s.Italprest di Luca Bosimini & C. s.a.s. was fined €10,000 by the Garante. The authority found that the company failed to implement minimum security measures, including the use of passwords shorter than eight characters, in breach of Article 33 of the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 05 Oct 2017 | Qiu JunjieQiu Junjie was fined EUR 10,000 by the Garante for failing to protect video surveillance recordings with a password. The authority found this breached the minimum security measures required under the Italian Data Protection Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 11 Oct 2017 | SANTANDER CONSUMER EFC, S.A.SANTANDER CONSUMER EFC, S.A. was fined by the AEPD for sending promotional SMS messages without the recipient’s consent. The authority also noted that the messages were sent despite the recipient’s objection to receiving advertising. | ES | AEPD | ePrivacy | €8,000 | ↗ |
| 12 Oct 2017 | Hu GuangyuHu Guangyu was fined EUR 14,400 by the Garante. The authority found inadequate simplified information on video surveillance and retention of recorded images beyond the permitted period. | IT | Garante | GDPR | €14,400 | ↗ |