BULLETIN №082Last updated · 30 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.2%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 06 Feb 2024 | GESTIÓN DE PATRIMONIOS ANFIPOLIS SOCIEDAD DE RESPONSABILIDAD LIMITADAThe AEPD fined GESTIÓN DE PATRIMONIOS ANFIPOLIS SOCIEDAD DE RESPONSABILIDAD LIMITADA EUR 2,000 for sending unsolicited commercial communications without the recipient's consent. The authority noted that the messages were sent despite the recipient's opposition. | ES | AEPD | ePrivacy | €2,000 | ↗ |
| 05 Feb 2024 | Asociație de proprietari din Miercurea CiucIn January 2024, ANSPDCP completed an investigation at a homeowners’ association in Miercurea Ciuc and found a breach of GDPR provisions. The operator was fined EUR 500. | RO | ANSPDCP | GDPR | €500 | ↗ |
| 02 Feb 2024 | SIA "AQUAPHOTO"DVI imposed a fine of 1,000 EUR on SIA "AQUAPHOTO". The decision has been appealed to court. | LV | DVI | GDPR | €1,000 | ↗ |
| 02 Feb 2024 | [...] Zrt.The controller did not provide adequate information about data processing through camera systems in bank branches. This constituted a breach of GDPR Articles 12 and 13. | HU | NAIH | GDPR | €156,000 | ↗ |
| 01 Feb 2024 | HOGAR LUZ Y GAS S.L.HOGAR LUZ Y GAS S.L. was fined EUR 4,000 by the Spanish Data Protection Agency (AEPD). The case concerned the failure to provide requested information, which breaches Article 58.1 of the GDPR. | ES | AEPD | GDPR | €4,000 | ↗ |
| 01 Feb 2024 | Capio A/SThe Danish Data Protection Authority reported Capio A/S to the police and recommended a fine of at least DKK 1,500,000. The case concerned insufficient supervision of data processors, breaching the GDPR accountability principle. | DK | Datatilsynet | GDPR | €201,000 | ↗ |
| 31 Jan 2024 | EDITEUR DE SITE WEB PROPOSANT AUX PARTICULIERS DE PUBLIER OU CONSULTER DES ANNONCES IMMOBILIERES ET AUTRES SERVICESCNIL imposed an administrative fine of EUR 100,000 on EDITEUR DE SITE WEB PROPOSANT AUX PARTICULIERS DE PUBLIER OU CONSULTER DES ANNONCES IMMOBILIERES ET AUTRES SERVICES. The case concerns identified breaches of rules supervised by the CNIL. | FR | CNIL | GDPR | €100,000 | ↗ |
| 31 Jan 2024 | Sectorul 1 al Municipiului BucureștiThe National Supervisory Authority for Personal Data Processing fined Sectorul 1 of Bucharest Municipality for GDPR violations. The entity failed to demonstrate compliance with a remediation measure, which formed the basis for the sanction. | RO | ANSPDCP | GDPR | €2,010 | ↗ |
| 31 Jan 2024 | MARINA SALUD, S.A.MARINA SALUD, S.A. was fined by the AEPD 500,000 EUR for failing to comply with data processing agreement obligations under Article 28 GDPR. The case involved the handling of sensitive health data, which increased the compliance risk. | ES | AEPD | GDPR | €500,000 | ↗ |
| 31 Jan 2024 | Uber Technologies Inc. en Uber B.V.Uber Technologies Inc. and Uber B.V. were fined by the AP for failing to provide guidance notes in local languages, for making data access request information insufficiently accessible, and for giving inadequate privacy policy details on data retention and transfer. The authority found these shortcomings breached GDPR transparency requirements. | NL | AP | GDPR | €10,000,000 | ↗ |
| 31 Jan 2024 | SOCIETE AYANT POUR ACTIVITE LE SOUTIEN AUX ENTREPRISES (procédure simplifiée)The CNIL imposed an administrative fine of EUR 10,000 on SOCIETE AYANT POUR ACTIVITE LE SOUTIEN AUX ENTREPRISES. The decision concerns a breach of rules supervised by the CNIL. | FR | CNIL | GDPR | €10,000 | ↗ |
| 31 Jan 2024 | EDITEUR DE SITE WEB - ACTUALITES DANS LE DOMAINE DES NOUVELLES TECHNOLOGIES (procédure simplifiée)The CNIL imposed an administrative fine of EUR 20,000 on EDITEUR DE SITE WEB - ACTUALITES DANS LE DOMAINE DES NOUVELLES TECHNOLOGIES under a simplified procedure. The case concerned a breach of personal data protection rules. | FR | CNIL | GDPR | €20,000 | ↗ |
| 31 Jan 2024 | SOCIETE AYANT POUR ACTIVITE LA COMMERCIALISATION ET GESTION DE PROGRAMMES ET CARTES DE FIDELITECNIL imposed an administrative fine of EUR 310,000 on SOCIETE AYANT POUR ACTIVITE LA COMMERCIALISATION ET GESTION DE PROGRAMMES ET CARTES DE FIDELITE. The case concerns identified breaches of rules supervised by CNIL. | FR | CNIL | GDPR | €310,000 | ↗ |
| 31 Jan 2024 | CHIRURGIEN DENTISTE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 5,000 on CHIRURGIEN DENTISTE. The case was handled under a simplified procedure. | FR | CNIL | GDPR | €5,000 | ↗ |
| 31 Jan 2024 | PARTICULIER (procédure simplifiée)CNIL imposed an administrative fine of EUR 500 on PARTICULIER under a simplified procedure. The case concerned a regulatory breach, with no further details provided in the record. | FR | CNIL | GDPR | €500 | ↗ |
| 30 Jan 2024 | Könnycsepp Nélkül a Beteg Gyermekekért AlapítványThe NAIH imposed a 1,000,000 HUF fine on the foundation for GDPR breaches related to personal data processing during phone calls. The authority found that data subjects were not adequately informed and that the processing lacked a valid legal basis. | HU | NAIH | GDPR | €2,580 | ↗ |
| 30 Jan 2024 | HUELLAS AVENTURA, S.L.The company was fined by the AEPD for tying consent for a school trip service to acceptance of data protection policies and commercial communications. The authority also found that users were not given an option to object to the processing of minors' images. | ES | AEPD | GDPR | €10,000 | ↗ |
| 29 Jan 2024 | IDFINANCE SPAIN, S.A.U.The AEPD fined IDFINANCE SPAIN, S.A.U. 70,000 EUR for including personal data in credit information systems in connection with a disputed debt. The authority found that the processing breached Article 6 GDPR. | ES | AEPD | GDPR | €70,000 | ↗ |
| 29 Jan 2024 | JAÉN, SENTIDO Y COMÚNThe entity was fined by the AEPD for failing to comply with a data protection authority resolution. The breach concerned sending emails to multiple recipients without using BCC, contrary to Article 58(2) GDPR. | ES | AEPD | GDPR | €1,000 | ↗ |
| 26 Jan 2024 | Allium UPI OÜEstonia’s Data Protection Inspectorate fined Allium UPI OÜ, operator of the Apotheka loyalty program, 3 million euros. The authority found that the company failed to protect customer data and used inadequate security measures, exposing the data of more than 750,000 people. | EE | Andmekaitse Inspektsioon | GDPR | €3,000,000 | ↗ |