BULLETIN №082Last updated · 30 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.2%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 12 Mar 2024 | Fiziska personaA monetary penalty of 150 EUR was imposed by DVI. The decision is final and has entered into force. | LV | DVI | GDPR | €150 | ↗ |
| 07 Mar 2024 | Banca di Credito Cooperativo Appulo Lucana soc. cooperativaThe Garante fined Banca di Credito Cooperativo Appulo Lucana 20,000 EUR for failing to provide adequate access to personal data requested by a former employee. The authority found a breach of GDPR Article 15 on the right of access. | IT | Garante | GDPR | €20,000 | ↗ |
| 07 Mar 2024 | CAIXABANK, S.A.CAIXABANK, S.A. was fined by the AEPD EUR 2,000,000 for pre-setting consent to share data with the Social Security Treasury without giving customers the option to refuse. The authority found this practice breached GDPR requirements for valid consent. | ES | AEPD | GDPR | €2,000,000 | ↗ |
| 07 Mar 2024 | BdM Banca S.p.a.BdM Banca S.p.a. was fined 10,000 EUR by the Garante for failing to provide an adequate response to a data access request submitted by an heir. The authority found that the response did not meet the requirements of GDPR Article 15. | IT | Garante | GDPR | €10,000 | ↗ |
| 07 Mar 2024 | Pinnacle Life LimitedBetween 5 May 2021 and 5 May 2022, the company made 47,998 connected unsolicited direct marketing calls to subscribers registered with the TPS who had not consented to receive such calls. Four complaints were submitted, and the ICO imposed a fine of 80,000 GBP. | GB | ICO | GDPR | €93,624 | ↗ |
| 07 Mar 2024 | Giuliana VinziThe Garante fined Giuliana Vinzi, owner of Rocky Bar, 2,000 EUR for operating video surveillance without the required notices to data subjects. The authority also found that authorization from the Labor Inspectorate was missing, resulting in a GDPR breach. | IT | Garante | GDPR | €2,000 | ↗ |
| 07 Mar 2024 | Centro Riparazioni Piacentino S.p.A.Centro Riparazioni Piacentino S.p.A. was fined by the Garante for continuing to operate individual company accounts months after employment ended and for accessing messages without proper deletion. The authority also found inadequate information and insufficient access rights for former employees. | IT | Garante | GDPR | €20,000 | ↗ |
| 07 Mar 2024 | Ministero della saluteThe Italian Ministry of Health was fined EUR 100,000 by the Garante for inadequate data protection and communication measures in the National Health Information System. The authority found breaches of GDPR requirements on data security and breach notification. | IT | Garante | GDPR | €100,000 | ↗ |
| 07 Mar 2024 | Hotel Milano di Foschi Eros e Righini Rina & C. SncThe Garante fined Hotel Milano EUR 3,000 for improper installation of surveillance cameras. The cameras captured public streets and third-party properties, and the informational signage was inadequate. | IT | Garante | GDPR | €3,000 | ↗ |
| 06 Mar 2024 | The Central Young Men’s Christian AssociationThe Central YMCA sent an email to participants in a programme for people living with HIV using “CC” instead of “BCC”, which exposed recipients’ email addresses to all recipients. From those addresses, 166 individuals could be identified or potentially identified, allowing an inference that they were likely living with HIV. The ICO imposed a £7,500 fine and issued a reprimand. | GB | ICO | GDPR | €8,772 | ↗ |
| 06 Mar 2024 | Sectorul 1 al Municipiului BucureștiSectorul 1 of Bucharest was fined 159,000 RON by ANSPDCP for failing to comply with a remediation measure. The authority had required the requested information to be provided within 10 days, but the obligation was not met. | RO | ANSPDCP | GDPR | €31,988 | ↗ |
| 05 Mar 2024 | ROCA & ASOCIADOS ABOGADOS Y ECONOMISTAS, S.L.P.ROCA & ASOCIADOS ABOGADOS Y ECONOMISTAS, S.L.P. was fined 5,000 EUR by the AEPD. The authority found that the company published employees’ personal data on its website without consent, breaching Article 6(1) of the GDPR. | ES | AEPD | GDPR | €5,000 | ↗ |
| 05 Mar 2024 | EURO MINI STORAGE ROMANIA SRLEURO MINI STORAGE ROMANIA SRL was fined by ANSPDCP EUR 5,000 for a data security breach caused by a cyber attack. The incident led to unauthorized access to personal data and affected data availability for several weeks. | RO | ANSPDCP | GDPR | €5,000 | ↗ |
| 04 Mar 2024 | EXESRIVAS GESTIÓN PATRIMONIALThe entity sent unsolicited commercial messages via WhatsApp despite the complainant's explicit refusal to receive such communications. AEPD found a breach of Article 21 of the LSSI and imposed a 300 EUR fine. | ES | AEPD | ePrivacy | €300 | ↗ |
| 03 Mar 2024 | FUNDACIÓN C.R.E.T.A. CENTRO PARA EL ESTUDIO Y REPRESENTACIÓN DEL TEATRO ANTIGUOThe organization failed to properly handle a data subject access request. AEPD imposed a fine of 1,000 EUR for non-compliance with GDPR obligations. | ES | AEPD | GDPR | €1,000 | ↗ |
| 29 Feb 2024 | WATIUM S.L.WATIUM S.L. was fined by the Spanish Data Protection Agency (AEPD) in the amount of EUR 160,000. The case concerned the failure to provide the required information, which constitutes a breach of Article 58.1 of the GDPR. | ES | AEPD | GDPR | €160,000 | ↗ |
| 29 Feb 2024 | SOCIETE AYANT POUR ACTIVITE LA RECHERCHE ET LE DEVELOPPEMENT SCIENTIFIQUE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 10,000 on SOCIETE AYANT POUR ACTIVITE LA RECHERCHE ET LE DEVELOPPEMENT SCIENTIFIQUE under a simplified procedure. The case concerns a violation identified by the French supervisory authority. | FR | CNIL | GDPR | €10,000 | ↗ |
| 29 Feb 2024 | CHIRURGIEN DENTISTE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 4,000 on CHIRURGIEN DENTISTE under a simplified procedure. The case concerns a breach of rules covered by the supervisory authority’s decision. | FR | CNIL | GDPR | €4,000 | ↗ |
| 28 Feb 2024 | Hellenic Post S.A.Hellenic Post S.A. was fined by the HDPA for insufficient technical and organizational measures to protect data. The deficiencies led to unauthorized access and a data breach. | GR | HDPA | GDPR | €2,995,000 | ↗ |
| 26 Feb 2024 | Ministry of DefenceThe UK Ministry of Defence sent emails using the “To” field instead of “BCC”, which disclosed 265 unique email addresses. The ICO found this breached GDPR Article 5(1)(f) and imposed a fine of 350,000 GBP. | GB | ICO | GDPR | €409,000 | ↗ |