BULLETIN №082Last updated · 29 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 05 Jul 2022 | Global Greece MEPEThe company was fined for sending unsolicited marketing emails without obtaining the recipients’ prior explicit consent. The authority found this conduct to be in breach of Article 11 of Law 3471/2006. | GR | HDPA | ePrivacy | €3,000 | ↗ |
| 07 Feb 2020 | SOLO EMBRAGUE, S.L.SOLO EMBRAGUE, S.L. was fined by the AEPD 3,000 EUR for failing to provide information about its privacy policy and for not obtaining consent for cookies on its website. The case concerns breaches of transparency obligations and consent requirements under data protection rules. | ES | AEPD | ePrivacy | €3,000 | ↗ |
| 17 Jun 2020 | LA CASA COMPROMETIDA, S.Coop.The entity was fined by the AEPD in the amount of 3,000 EUR for failing to comply with data protection rules regarding its website cookie policy. The case concerned deficiencies in the required information or consent related to cookies. | ES | AEPD | ePrivacy | €3,000 | ↗ |
| 01 Jan 2021 | LYNGUAL GMBHLYNGUAL GMBH was fined by the AEPD 3,000 EUR for sending unsolicited commercial emails. The messages continued despite the recipient’s attempts to unsubscribe and requests to stop communications. | ES | AEPD | ePrivacy | €3,000 | ↗ |
| 14 Mar 2023 | Tinmar Energy SATinmar Energy SA was fined EUR 3,000 by ANSPDCP after unauthorized access to its email server. The incident resulted in a personal data breach. | RO | ANSPDCP | GDPR | €3,000 | ↗ |
| 14 Sept 2006 | De.Mo. s.r.l.De.Mo. s.r.l. was fined 3,000 EUR by the Garante for failing to provide the required information to data subjects under Article 13 of the Italian Data Protection Code. The breach occurred in connection with the company’s marketing activities. | IT | Garante | GDPR | €3,000 | ↗ |
| 03 Dec 2025 | FUNDACIÓN TRILEMAFUNDACIÓN TRILEMA was fined 3,000 EUR by the AEPD for publishing a minor’s image on social media without parental consent. The authority found this to be a breach of data protection rules. | ES | AEPD | GDPR | €3,000 | ↗ |
| 11 Mar 2020 | SALAD MARKET S.L.SALAD MARKET S.L. was fined by the AEPD €3,000 for using video cameras to monitor employees without informing them. The company also added employees to WhatsApp groups without consent, which breached data protection rules. | ES | AEPD | ePrivacy | €3,000 | ↗ |
| 22 May 2014 | SOFTWARE INFORMÁTICA VEDCOR S.L.SOFTWARE INFORMÁTICA VEDCOR S.L. was fined by the AEPD EUR 3,000 for sending unsolicited commercial emails despite the recipient’s request to stop. The conduct breached Article 21 of the LSSI on unsolicited electronic communications. | ES | AEPD | ePrivacy | €3,000 | ↗ |
| 20 Nov 2006 | Anonymised (HDPA 61/2006)A hospital was fined for failing to properly inform the complainant about the transmission of sensitive health data. The case concerns a breach of the duty to provide clear information to the data subject. | GR | HDPA | GDPR | €3,000 | ↗ |
| 22 Jun 2020 | ARANOW PACKAGING MACHINERY, S.L.ARANOW PACKAGING MACHINERY, S.L. was fined by the AEPD for non-compliance of its website with data protection rules. The breach concerned the absence of compliant Privacy and Cookie Policies. | ES | AEPD | ePrivacy | €3,000 | ↗ |
| 26 Mar 2026 | SOCIÉTÉ AYANT POUR ACTIVITÉ L'HÉBERGEMENT DE TOURISME (procédure simplifiée)CNIL imposed an administrative fine of EUR 3,000 on SOCIÉTÉ AYANT POUR ACTIVITÉ L'HÉBERGEMENT DE TOURISME under a simplified procedure. The case concerns a confirmed breach of rules supervised by CNIL. | FR | CNIL | GDPR | €3,000 | ↗ |
| 01 Mar 2023 | ILUROBOX, S.L.ILUROBOX, S.L. was fined by the AEPD EUR 3,000 for including individuals in a WhatsApp group without their consent. The authority found that this breached Article 6(1) GDPR because there was no lawful basis for the processing. | ES | AEPD | GDPR | €3,000 | ↗ |
| 28 Jun 2022 | ALPA 57 PRODUCCIONES, S.L.ALPA 57 PRODUCCIONES, S.L. failed to provide the required information to the Spanish Data Protection Agency, which constitutes a breach of Article 58.1 of the GDPR. The AEPD imposed a fine of 3,000 EUR. | ES | AEPD | GDPR | €3,000 | ↗ |
| 15 Apr 2021 | Ordine degli Avvocati di LagonegroOrdine degli Avvocati di Lagonegro was fined EUR 3,000 by the Garante for publishing the content of a PEC email on its institutional website. The authority found breaches of lawfulness, fairness, transparency, and data minimization. | IT | Garante | GDPR | €3,000 | ↗ |
| 27 Jul 2018 | Anonymizováno (ÚOOÚ UOOU-08596/17-64)The individual was fined for publishing the personal data of a municipal social department employee on Facebook. The authority found a breach of confidentiality obligations under Czech law. | CZ | UOOU | GDPR | €117 | ↗ |
| 15 Jan 2024 | CUBILLO GALLEGO, S.L.CUBILLO GALLEGO, S.L. was fined by the AEPD 3,000 EUR for failing to provide adequate information about personal data processing on its website. The authority found a breach of Article 13 GDPR, which requires clear notice to data subjects. | ES | AEPD | GDPR | €3,000 | ↗ |
| 08 May 2024 | Genpact România SRLThe ANSPDCP imposed a fine of EUR 3,000 on Genpact România SRL. The sanction concerned sending a file containing recruitment data to an unauthorized employee email address. The incident indicates a failure to control access to personal data and maintain confidentiality. | RO | ANSPDCP | GDPR | €3,000 | ↗ |
| 06 Jul 2023 | Comune di AvianoThe Garante fined Comune di Aviano EUR 3,000 for publishing employees’ personal data, including names and productivity bonuses, on its institutional website. The authority found a breach of data minimization and transparency principles. | IT | Garante | GDPR | €3,000 | ↗ |
| 22 Nov 2019 | CENTRAL SINDICAL INDEPENDIENTE Y DE FUNCIONARIOS CSI-CSIFThe union CSI-CSIF was fined EUR 3,000 by the AEPD for publishing an electoral census list containing personal data, including DNI numbers, in a public WhatsApp group. The authority found this breached data protection principles. | ES | AEPD | GDPR | €3,000 | ↗ |