BULLETIN №082Last updated · 30 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.2%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 31 Jan 2023 | PRESTAMER, S.L.PRESTAMER, S.L. sent an email to 472 recipients without using BCC, which exposed recipients’ personal data. The AEPD imposed a 3,000 EUR fine for breaching data protection rules. | ES | AEPD | GDPR | €3,000 | ↗ |
| 14 Feb 2024 | PRENSA IBÉRICA MEDIA S.L.PRENSA IBÉRICA MEDIA S.L. was fined by the AEPD in the amount of 5,000 EUR for failing to obtain proper user consent for cookies on its website. The authority found that this practice breached the LSSI requirements on cookies. | ES | AEPD | ePrivacy | €5,000 | ↗ |
| 04 Oct 2017 | PRENATAL SAPRENATAL SA was fined by the AEPD EUR 20,000 for sending commercial SMS messages without providing recipients with an opt-out mechanism. The case concerns a breach of electronic communications rules and marketing consent requirements. | ES | AEPD | ePrivacy | €20,000 | ↗ |
| 13 Jan 2026 | PREMIER RESTAURANTS ROMANIA SRLThe National Supervisory Authority for Personal Data Processing imposed a fine on PREMIER RESTAURANTS ROMANIA SRL for GDPR violations. The case concerned non-compliance with personal data protection requirements. | RO | ANSPDCP | GDPR | €8,000 | ↗ |
| 01 Mar 2022 | PREICO JURÍDICOS, S.L.PREICO JURÍDICOS, S.L. was fined EUR 2,000 by the AEPD for deficiencies in its cookie policy. The authority found that the website did not provide the required information or obtain consent for storing and accessing data, in breach of Article 22.2 of the LSSI. | ES | AEPD | ePrivacy | €2,000 | ↗ |
| 26 May 2022 | PREICO JURIDICOS, S.L.PREICO JURIDICOS, S.L. was fined by the AEPD 3,000 EUR for failing to respond to information requests linked to a data breach investigation. The authority found a breach of Article 58(1) GDPR. | ES | AEPD | GDPR | €3,000 | ↗ |
| 26 May 2022 | PREICO JURIDICOS S.L.PREICO JURIDICOS S.L. was fined EUR 6,000 by the AEPD for failing to provide required information. The case concerned a breach of Article 58(1) GDPR. | ES | AEPD | GDPR | €6,000 | ↗ |
| 29 Sept 2021 | Prefettura - Ufficio Territoriale del Governo di GenovaPrefettura - Ufficio Territoriale del Governo di Genova was fined by the Garante for publishing personal data on its institutional website. The conduct breached GDPR requirements on lawful processing and protection of personal data. | IT | Garante | GDPR | €11,000 | ↗ |
| 19 Oct 2020 | PREDASE SERVICIOS INTEGRALES SOCIEDAD LIMITADAPREDASE SERVICIOS INTEGRALES S.L. was fined EUR 5,000 by the AEPD for failing to publish a privacy policy on its website and for misleadingly using the AEPD logo. The conduct could imply an association with the authority and influence user decisions. | ES | AEPD | GDPR | €5,000 | ↗ |
| 04 Jun 2020 | PRA IBERIA, S.L.PRA IBERIA, S.L. was fined by the AEPD 60,000 EUR for unlawful processing of personal data and for failing to provide access to personal data information. The breaches concerned Articles 6(1) and 15 of the GDPR. | ES | AEPD | GDPR | €60,000 | ↗ |
| 06 Jul 2006 | PR3 International s.r.l.PR3 International s.r.l. was fined by the Italian data protection authority, Garante, in the amount of EUR 258. The case concerned inadequate information provided to data subjects in job advertisements, which breached data protection rules. | IT | Garante | GDPR | €258 | ↗ |
| 23 Sept 2024 | PPC ENERGIE MUNTENIA S.A.In September 2024, ANSPDCP completed an investigation into PPC ENERGIE MUNTENIA S.A. and found violations of GDPR provisions. The company was fined EUR 2,000. | RO | ANSPDCP | GDPR | €2,000 | ↗ |
| 08 Nov 2024 | PPC Energie Muntenia S.AThe National Supervisory Authority for Personal Data Processing completed an investigation at PPC Energie Muntenia S.A and found a violation of GDPR provisions. As a result, a fine of EUR 1,000 was imposed. | RO | ANSPDCP | GDPR | €1,000 | ↗ |
| 10 Feb 2025 | PPC Energie Muntenia SAPPC Energie Muntenia SA was fined EUR 1,000 by ANSPDCP for violating GDPR provisions. The case concerned non-compliance with personal data protection requirements. | RO | ANSPDCP | GDPR | €1,000 | ↗ |
| 10 Feb 2025 | PPC Energie Muntenia SAThe operator was fined by ANSPDCP in the amount of EUR 2,000 for violating GDPR provisions. The case concerns non-compliance with personal data protection requirements. | RO | ANSPDCP | GDPR | €2,000 | ↗ |
| 16 Jan 2024 | Poxell LtdThe ICO found that Poxell Ltd made 2,647,805 unsolicited direct marketing calls between 31 March 2022 and 20 July 2022, breaching regulations 21 and 24 of PECR. This led to 413 complaints to the ICO and TPS, with recipients reporting persistent calls about energy-related products and home improvements. | GB | ICO | ePrivacy | €174,000 | ↗ |
| 27 Jan 2021 | Powerplay S.r.l.Powerplay S.r.l. was fined by the Garante for making unsolicited promotional calls despite the recipient's clear request not to receive further communications. The company failed to place the number on a blacklist, which breached data protection rules. | IT | Garante | GDPR | €20,000 | ↗ |
| 01 Jan 2025 | Posti Jakelu OyPosti Jakelu Oy was fined EUR 2,400,000 by the Data Protection Ombudsman for deficiencies in data protection related to the OmaPosti service. The case concerned inadequate safeguards and failures to meet personal data protection requirements. | FI | Tietosuojavaltuutettu | GDPR | €2,400,000 | ↗ |
| 10 Jul 2025 | Poste Vita S.p.a.Poste Vita S.p.a. was fined EUR 80,000 by the Garante for unlawfully disclosing personal data relating to life insurance policies to an unauthorized third party. The data were then used in judicial proceedings. | IT | Garante | GDPR | €80,000 | ↗ |
| 04 Jul 2024 | Postel S.p.A.Postel S.p.A. was fined by the Garante EUR 900,000 for a data breach following a ransomware attack. The attack exploited vulnerabilities in the Microsoft Exchange platform, resulting in unauthorized access to data and publication on the dark web. | IT | Garante | GDPR | €900,000 | ↗ |