BULLETIN №082Last updated · 29 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 01 Mar 2017 | ESPASA CALPE, S.A.ESPASA CALPE, S.A. was fined EUR 2,500 by the AEPD for continuing to send commercial emails to a customer after confirming deletion of the customer’s personal data. The authority found this to be a breach of electronic communications and data protection rules. | ES | AEPD | ePrivacy | €2,500 | ↗ |
| 25 Jul 2019 | CONTAPUBLI RIOJA, S.L. (GESTIRIOJA)CONTAPUBLI RIOJA, S.L. was fined by the AEPD 2,500 EUR for sending unsolicited commercial emails. The conduct continued despite the recipient's objection and request for data deletion. | ES | AEPD | ePrivacy | €2,500 | ↗ |
| 27 Jun 2023 | Farmacia Ardealul SRLFarmacia Ardealul SRL was fined by ANSPDCP EUR 2,500 for a data security breach on its website. Unauthorized malware installation led to the compromise of personal data confidentiality, including banking data, of a significant number of clients. | RO | ANSPDCP | GDPR | €2,500 | ↗ |
| 01 Jan 2017 | MAS MOVIL TELECOM 3.0 S.A.U. (actualmente XFERA MOVILES, S.A.)The entity was fined by the AEPD in the amount of 2,500 EUR for sending unsolicited marketing messages without providing an opt-out option. This conduct breached article 21.2 of the LSSI, which requires recipients to be able to refuse such communications. | ES | AEPD | ePrivacy | €2,500 | ↗ |
| 03 Apr 2026 | BLUE PROJECTS S.R.L.In March 2026, the Romanian supervisory authority ANSPDCP completed an investigation into BLUE PROJECTS S.R.L. and found a GDPR violation. The company was fined EUR 2,500. | RO | ANSPDCP | GDPR | €2,500 | ↗ |
| 03 Feb 2017 | CAIXABANK, S.A.CAIXABANK, S.A. was fined by the AEPD EUR 2,500 for sending a customer an unsolicited advertising SMS. The recipient had not consented to receive commercial communications, which breached Article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €2,500 | ↗ |
| 17 Apr 2026 | Carlo Maria Antonio ParisiThe Garante fined Carlo Maria Antonio Parisi, owner of the online newspaper “giornalistitalia.it”, EUR 2,500. The authority found inadequate technical and organizational measures to support data subject rights and delays in handling requests without undue delay. | IT | Garante | GDPR | €2,500 | ↗ |
| 09 Jan 2019 | TOM TOM SALES BV SUCURSAL EN ESPAÑATOM TOM SALES BV SUCURSAL EN ESPAÑA was fined by the AEPD 2,500 EUR for sending a promotional email to a user after confirming the deletion of their data. The authority found this conduct breached Article 21 of the LSSI. | ES | AEPD | ePrivacy | €2,500 | ↗ |
| 15 Dec 2022 | BENOTAC, S.L.BENOTAC, S.L. was fined by the AEPD EUR 2,500 for operating a video surveillance system without proper signage and for capturing public areas without authorization. The authority also noted the sharing of recordings without the consent of the data subjects. | ES | AEPD | GDPR | €2,500 | ↗ |
| 29 Sept 2020 | GABINETE PARAPSICOLÓGICO MYSTIC S.L.The entity was fined for sending unsolicited advertising SMS messages without the recipient's consent. This conduct breached Article 21 of the LSSI and constituted unlawful marketing communication. | ES | AEPD | ePrivacy | €2,500 | ↗ |
| 01 Jan 2019 | LA ROCA NETWORKS, S.L.LA ROCA NETWORKS, S.L. was fined by the AEPD 2,500 EUR for sending unsolicited commercial emails without proper consent. The conduct breached Article 21 of the LSSI, which governs electronic marketing communications. | ES | AEPD | ePrivacy | €2,500 | ↗ |
| 02 Apr 2020 | HAPPY FRIDAY, S.L.HAPPY FRIDAY, S.L. was fined by the AEPD in the amount of 2,500 EUR for failing to comply with data protection rules on the use of cookies. The authority found that the company did not provide the required information or obtain user consent. | ES | AEPD | ePrivacy | €2,500 | ↗ |
| 26 Mar 2026 | Comune di CassinoComune di Cassino was fined for unlawfully publishing personal data online. The case concerns a breach of data protection rules and indicates a need to review procedures for publishing public information. | IT | Garante | GDPR | €2,500 | ↗ |
| 12 Feb 2026 | Velletri ServiziVelletri Servizi was fined EUR 2,500 by the Garante for inadequate technical and organizational measures in data processing. The authority found that the company did not meet the requirements of GDPR Article 32. | IT | Garante | GDPR | €2,500 | ↗ |
| 01 Jan 2016 | TELE PIZZA S.A.U.TELE PIZZA S.A.U. was fined EUR 2,500 by the AEPD for sending commercial emails without providing a valid electronic address for exercising ARCO rights. This breached Article 21.2 of the LSSI and indicates a failure to meet required recipient information obligations. | ES | AEPD | ePrivacy | €2,500 | ↗ |
| 01 Apr 2019 | EL GYM IBERIA, S.L.EL GYM IBERIA, S.L. was fined by the AEPD 2,500 EUR for sending unsolicited marketing emails. This occurred despite a prior request to cancel personal data. | ES | AEPD | ePrivacy | €2,500 | ↗ |
| 26 Jun 2017 | LEAD CONVERSION S.L.LEAD CONVERSION S.L. was fined by the AEPD 2,500 EUR for sending unsolicited commercial emails without prior recipient consent. The conduct breached electronic communications rules and marketing consent requirements. | ES | AEPD | ePrivacy | €2,500 | ↗ |
| 01 Oct 2023 | Anonymised (IDPC CDP_COMP_344_2022)The IDPC imposed a EUR 2,500 fine on the anonymised entity for breaches of multiple GDPR provisions. The case concerned, among others, lawfulness and transparency, information duties, and controller accountability. | MT | IDPC | GDPR | €2,500 | ↗ |
| 11 Dec 2025 | CANDIDAT AUX ELECTIONS LEGISLATIVES DE 2024 (procédure simplifiée)The CNIL imposed an administrative fine of EUR 2,500 on CANDIDAT AUX ELECTIONS LEGISLATIVES DE 2024. The case was handled under a simplified procedure and concerned a confirmed regulatory breach. | FR | CNIL | GDPR | €2,500 | ↗ |
| 16 Aug 2022 | Dane anonimowe (N. Ośrodek Kultury z siedzibą w N. przy ul.)UODO imposed an administrative fine of PLN 2,500 on the Cultural Centre. The authority found that personal data were entrusted for processing without a written data processing agreement and without verifying whether the processor provided sufficient technical and organizational safeguards under the GDPR. | PL | UODO | GDPR | €531 | ↗ |