BULLETIN №082Last updated · 30 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.2%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 23 Jan 2024 | CAJA RURAL DE BURGOS, FUENTEPELAYO, SEGOVIA Y CASTELLDANS, S.C.C.CAJABURGOS was fined by the AEPD for failing to ensure the confidentiality and integrity of personal data. The breach resulted in unauthorized access following a data security incident. | ES | AEPD | GDPR | €15,000 | ↗ |
| 22 Jan 2024 | ASILO DE ANCIANOS SANTO DOMINGO Y SANTA ELOISAThe organization was fined for repeatedly sending emails with visible recipient addresses. The case involved a breach of data protection principles and a failure to implement adequate security measures. | ES | AEPD | GDPR | €1,000 | ↗ |
| 22 Jan 2024 | AVOCAT (procédure simplifiée)The CNIL imposed an administrative fine of EUR 500 on AVOCAT (procédure simplifiée). The record indicates a regulatory breach, but no further details are provided. | FR | CNIL | GDPR | €500 | ↗ |
| 22 Jan 2024 | Hvidovre KommuneHvidovre Kommune was fined by Datatilsynet for failing to maintain an appropriate level of security. The issue allowed unauthorized access to protected addresses of children through the municipal dental service's self-service solution, which incorrectly extended access to both custodial parents. | DK | Datatilsynet | GDPR | €26,816 | ↗ |
| 22 Jan 2024 | CAJASIETE, CAJA RURAL SOCIEDAD COOPERATIVA DE CREDITOCAJASIETE was fined by the AEPD in the amount of 250,000 EUR for a data security incident. The incident compromised the confidentiality and integrity of personal data, breaching GDPR Article 5(1)(f). | ES | AEPD | GDPR | €250,000 | ↗ |
| 22 Jan 2024 | CAJA RURAL DE SORIA, S.C.C.CAJA RURAL DE SORIA, S.C.C. was fined by the AEPD 15,000 EUR for breaching personal data protection principles. The case involved a failure to protect confidentiality and integrity, resulting in unauthorized access following a data breach. | ES | AEPD | GDPR | €15,000 | ↗ |
| 19 Jan 2024 | L.A.D.H LimitedL.A.D.H Limited sent 31,329 direct marketing text messages to individuals in breach of regulations 22 and 23 of PECR. The ICO imposed a fine of GBP 50,000 and issued an enforcement notice. | GB | ICO | ePrivacy | €58,260 | ↗ |
| 19 Jan 2024 | GEO ALTERNATIVA, S.L.GEO ALTERNATIVA, S.L. was fined by the AEPD for unlawfully processing personal data. The company included a customer's information in a credit file even though an agreement had already been reached regarding the disputed gas bill. | ES | AEPD | GDPR | €20,000 | ↗ |
| 18 Jan 2024 | Dane anonimowe (przez Pana B.W. prowadzącego działalność gospodarczą pod firmą: B.)UODO imposed an administrative fine on B. for failing to notify the supervisory authority of a personal data breach without undue delay. The authority also found that the affected individuals were not informed of the breach without undue delay. | PL | UODO | GDPR | €2,251 | ↗ |
| 18 Jan 2024 | Fiziska personaA fine of EUR 250 was imposed by the DVI. The decision is final and has entered into force. | LV | DVI | GDPR | €250 | ↗ |
| 17 Jan 2024 | Dane anonimowe (V. sp. z o. o. z siedzibą w S. za naruszenie art. 5 ust. 1 lit. f), art. 5 ust. 2, art. 25 ust. 1 oraz art. 32 ust. 1 lit. b) i lit. d) i ust. 2 rozporządzenia 2016/679)UODO imposed a fine of PLN 3,819,960 on V. sp. z o.o. for breaches of GDPR rules on data security and confidentiality. The case concerned, among other things, data processing principles, data protection by design, and the implementation of appropriate technical and organizational measures. | PL | UODO | GDPR | €868,000 | ↗ |
| 16 Jan 2024 | Poxell LtdThe ICO found that Poxell Ltd made 2,647,805 unsolicited direct marketing calls between 31 March 2022 and 20 July 2022, breaching regulations 21 and 24 of PECR. This led to 413 complaints to the ICO and TPS, with recipients reporting persistent calls about energy-related products and home improvements. | GB | ICO | ePrivacy | €174,000 | ↗ |
| 16 Jan 2024 | Skean Homes LtdSkean Homes Ltd was fined by the ICO after it was found to have instigated 614,342 unsolicited direct marketing calls between 2 March 2022 and 31 May 2022. The calls promoted energy grants for resin driveways and generated 31 complaints through the ICO and TPS reporting tools. The ICO found breaches of regulations 21 and 24 of PECR. | GB | ICO | ePrivacy | €116,000 | ↗ |
| 16 Jan 2024 | International Card Services B.V.International Card Services B.V. was fined by the Dutch AP in the amount of EUR 150,000. The company failed to carry out a Data Protection Impact Assessment (DPIA) before implementing a customer identification and verification process, in breach of Article 35 GDPR. | NL | AP | GDPR | €150,000 | ↗ |
| 15 Jan 2024 | TECHNINK LEB SRLThe company was fined EUR 3,000 by ANSPDCP for unauthorized disclosure of personal data on its website. The exposed information included IDs, addresses, names, email addresses, and sales information. | RO | ANSPDCP | GDPR | €3,000 | ↗ |
| 15 Jan 2024 | AVOCAT (procédure simplifiée)The CNIL imposed an administrative fine of EUR 5,000 on AVOCAT (procédure simplifiée). The case concerned a confirmed regulatory breach, with no further details provided in the record. | FR | CNIL | GDPR | €5,000 | ↗ |
| 15 Jan 2024 | CUBILLO GALLEGO, S.L.CUBILLO GALLEGO, S.L. was fined by the AEPD 3,000 EUR for failing to provide adequate information about personal data processing on its website. The authority found a breach of Article 13 GDPR, which requires clear notice to data subjects. | ES | AEPD | GDPR | €3,000 | ↗ |
| 12 Jan 2024 | Grocery Delivery E-Services UK Ltd t/a HelloFreshThe ICO fined Grocery Delivery E-Services UK Ltd t/a HelloFresh 140,000 GBP for sending 79 million spam emails and 1 million spam texts over seven months. The marketing consent was inadequate because it did not mention text messages and was bundled with an age confirmation statement that may have unfairly encouraged agreement. Customers were also not clearly told that their data would continue to be used for marketing for up to 24 months after cancelling subscriptions. | GB | ICO | GDPR | €162,000 | ↗ |
| 12 Jan 2024 | Alior Bank SA Varșovia Sucursala BucureștiAlior Bank SA, through its Romanian branch, was fined EUR 17,000 by ANSPDCP. The sanction followed an investigation that identified GDPR violations. | RO | ANSPDCP | GDPR | €17,000 | ↗ |
| 11 Jan 2024 | Provincia di SassariThe Garante imposed a fine of 2,000 EUR on Provincia di Sassari for breaches of data protection obligations under Article 37 GDPR. The case concerned failure to comply with requirements related to the designation of a data protection officer. | IT | Garante | GDPR | €2,000 | ↗ |