BULLETIN №081Last updated · 26 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -20.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 24 Jun 2024 | WWPD CINVENTO INTERNATIONAL PATENT TRADING, S.L.The entity sent postal advertising to an individual without any prior commercial relationship, using data from the Official Industrial Property Bulletin. The authority found this to be a breach of data protection rules. | ES | AEPD | GDPR | €500 | ↗ |
| 21 Jul 2022 | WUNSCHURLAUB S.L.WUNSCHURLAUB S.L. was fined by the AEPD 3,000 EUR for storing user passwords in plain text and sending them by email without encryption. The authority found this breached GDPR Article 32 on appropriate security measures. | ES | AEPD | GDPR | €3,000 | ↗ |
| 01 Dec 2016 | Wu KuanzhaoWu Kuanzhao was fined EUR 2,400 by the Garante. The authority found that data subjects were not informed about the processing of personal data through a video surveillance system. | IT | Garante | GDPR | €2,400 | ↗ |
| 01 Jan 2014 | WUAKI TV, S.L.WUAKI TV, S.L. was fined by the AEPD EUR 2,300 for sending unsolicited commercial emails to a user. The emails were sent after the company had confirmed the user's unsubscribe request and request to stop processing their data. | ES | AEPD | ePrivacy | €2,300 | ↗ |
| 01 Oct 2023 | wspólnota mieszkaniowaUODO found that the housing community breached GDPR requirements. The case concerned improper processing of personal data and required supervisory intervention. | PL | UODO | GDPR | €1,080 | ↗ |
| 06 Jun 2024 | WORLD 2 MEET, S.L.WORLD 2 MEET, S.L. was fined EUR 70,000 by the AEPD for requesting excessive personal data from guests during traveler registration. The company required full copies of identity documents, which breached the data minimization principle. | ES | AEPD | GDPR | €70,000 | ↗ |
| 13 Jul 2006 | Work Safety Training Italia s.r.l.Work Safety Training Italia s.r.l. was fined by the Garante for sending unsolicited promotional emails. The authority found that the company failed to provide adequate information about data processing, breaching the information duty under data protection rules. | IT | Garante | GDPR | €1,549 | ↗ |
| 28 Sept 2010 | WORKING MARESME S.L.WORKING MARESME S.L. was fined by the AEPD in the amount of EUR 600 for sending unsolicited commercial emails. The conduct breached Article 21 of the LSSI, which prohibits marketing communications without prior consent. | ES | AEPD | ePrivacy | €600 | ↗ |
| 19 Nov 2021 | Working Capital Management España, S.L.Working Capital Management España, S.L. was fined by the AEPD 40,000 EUR for unlawfully processing personal data. The company included an individual's data in a credit information system without a valid contract, in connection with an identity theft case. | ES | AEPD | GDPR | €40,000 | ↗ |
| 01 Dec 2022 | WoolenWoolen was fined EUR 3,000 by the Garante for a video surveillance system that did not meet transparency requirements. The authority cited a breach of GDPR Article 13 and Article 114 of the Italian Privacy Code. | IT | Garante | GDPR | €3,000 | ↗ |
| 03 Aug 2016 | WOLTERS KLUWER ESPAÑA, S.A.WOLTERS KLUWER ESPAÑA, S.A. was fined by the AEPD EUR 1,000 for sending unsolicited commercial emails to a complainant after confirming the cancellation of their data. The authority found this conduct breached Article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €1,000 | ↗ |
| 01 Nov 2025 | Właścicielka lecznicy stomatologicznejThe owner of a dental clinic was fined 85,588 PLN by UODO for failing to notify affected patients in time after a personal data breach. The WSA and then the NSA upheld the penalty, finding that the required notices were sent too late. | PL | President of the Personal Data Protection Office (UODO) | GDPR | €20,110 | ↗ |
| 11 Jan 2017 | WIZINK BANK, S.A.WIZINK BANK, S.A. was fined by the AEPD EUR 5,000 for sending unsolicited commercial emails despite a request to unsubscribe. The authority found a breach of Article 21 of the LSSI. | ES | AEPD | ePrivacy | €5,000 | ↗ |
| 17 Apr 2023 | WIZINK BANK, S.A.WIZINK BANK, S.A. was fined 5,000 EUR by the AEPD for sending commercial emails to a complainant who had opted out of receiving such communications. The authority found this conduct to be a breach of Article 21 of the LSSI. | ES | AEPD | ePrivacy | €5,000 | ↗ |
| 01 Jan 2016 | WIZINK BANK S.A.WIZINK BANK S.A. was fined by the AEPD €4,100 for sending unsolicited commercial communications by electronic means. The authority found that the legal requirements for such communications were not met. | ES | AEPD | ePrivacy | €4,100 | ↗ |
| 17 Apr 2017 | WIZINK BANK S.A.WIZINK BANK S.A. was fined by the AEPD in the amount of 5,000 EUR for sending unsolicited commercial communications by email. The conduct violated the recipient's request to opt out of advertising. | ES | AEPD | ePrivacy | €5,000 | ↗ |
| 06 Dec 2012 | Wire s.r.l.Wire s.r.l. was fined by the Garante in the amount of EUR 32,000 for making pre-recorded electoral propaganda calls without prior, specific, and informed consent from the recipients. The authority found this to be a breach of data protection rules. | IT | Garante | GDPR | €32,000 | ↗ |
| 12 Dec 2024 | Wind Tre S.p.A.Wind Tre S.p.A. was fined €347,520 by the Garante for violations related to processing personal data for promotional purposes and for inadequate technical and organizational measures. The case concerned telemarketing activities and the protection of the data involved. | IT | Garante | GDPR | €347,000 | ↗ |
| 29 Nov 2018 | Wind Tre S.p.A.Wind Tre S.p.A. was fined EUR 600,000 by the Garante for unsolicited promotional calls and SMS. The authority found breaches of several provisions of the Italian Data Protection Code. | IT | Garante | GDPR | €600,000 | ↗ |
| 09 Jul 2020 | Wind Tre S.p.A.Wind Tre S.p.A. was fined by the Garante 16,729,600 EUR for carrying out promotional activities without ensuring that contacts respected the wishes of individuals who did not want to receive marketing communications. The case concerns GDPR requirements on consent and the right to object to direct marketing. | IT | Garante | GDPR | €16,729,000 | ↗ |