BULLETIN №082Last updated · 29 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 07 Jul 2021 | Anonymizováno (ÚOOÚ UOOU-04873/20-24)The entity was fined for unlawfully publishing personal data on YouTube. The authority found a breach of GDPR principles of lawfulness, fairness, and transparency. | CZ | UOOU | GDPR | €117 | ↗ |
| 08 Mar 2017 | Elliniki Etaireia Systimikon MeletonThe company was fined by the HDPA for illegally collecting and using personal data for direct marketing purposes. The infringement involved unsolicited electronic communications sent without prior consent from the data subjects. | GR | HDPA | ePrivacy | €3,000 | ↗ |
| 30 Mar 2025 | MODEL REYNA, C.B.MODEL REYNA, C.B. was fined by the AEPD EUR 3,000 for failing to provide access to personal data and related information. The authority found a breach of Article 58.1 of the GDPR. | ES | AEPD | GDPR | €3,000 | ↗ |
| 18 Dec 2013 | Anonymised (HDPA 154/2013)The HDPA imposed a fine of EUR 3,000 on the company for unlawfully collecting an individual's creditworthiness data. The case concerned processing without a valid legal basis, which breaches data protection rules. | GR | HDPA | GDPR | €3,000 | ↗ |
| 29 Jul 2015 | LEIPZIG COMUNICACIONES, S.L.LEIPZIG COMUNICACIONES, S.L. was fined by the AEPD for sending six unsolicited advertising SMS messages without prior consent. The authority also found that no opt-out mechanism was provided, which breached Article 21 of the LSSI. | ES | AEPD | ePrivacy | €3,000 | ↗ |
| 20 Jun 2023 | CARRETERAS Y ASFALTOS, S.L.The company installed surveillance cameras that recorded both image and audio without proper signage or informing employees. This breached data protection requirements. | ES | AEPD | GDPR | €3,000 | ↗ |
| 17 Sept 2024 | Constanța South Container Terminal SRLConstanța South Container Terminal SRL was fined by ANSPDCP EUR 3,000 after a third party gained unauthorized access to employees’ personal data. The breach resulted from inadequate security measures on a publicly accessible file management platform. | RO | ANSPDCP | GDPR | €3,000 | ↗ |
| 18 Jan 2022 | BAZARDELALEGION.COMBAZARDELALEGION.COM was fined by the AEPD for failing to provide the required information on its website under Article 13 GDPR. The breach concerned the website’s information duties toward individuals whose data are collected online. | ES | AEPD | GDPR | €3,000 | ↗ |
| 28 May 2026 | Regione Autonoma della SardegnaThe Garante fined Regione Autonoma della Sardegna EUR 3,000 for sharing disciplinary sanction information with unauthorized internal units. The authority found this breached the GDPR and national data protection rules. | IT | Garante | GDPR | €3,000 | ↗ |
| 05 Mar 2020 | Comune di San Giorgio JonicoComune di San Giorgio Jonico was fined by the Garante for publishing personal data on its institutional website. The authority found breaches of lawfulness, fairness, transparency, and data minimization principles. | IT | Garante | GDPR | €3,000 | ↗ |
| 11 Dec 2023 | Veranda Obor S.A.The National Supervisory Authority for Personal Data Processing imposed a fine on Veranda Obor S.A. for violating GDPR provisions. The case concerned non-compliance with personal data protection requirements. | RO | ANSPDCP | GDPR | €3,000 | ↗ |
| 13 May 2015 | HellastatHellastat was fined EUR 3,000 by the HDPA for failing to inform data subjects. The authority found a breach of data protection rules requiring transparent notice to individuals. | GR | HDPA | GDPR | €3,000 | ↗ |
| 19 Apr 2023 | Partidul Uniunea Salvați RomâniaThe National Supervisory Authority imposed a fine on Partidul Uniunea Salvați România (USR) for publishing personal data of persons with disabilities on its website without a legal basis. The authority found a breach of personal data processing principles. | RO | ANSPDCP | GDPR | €3,000 | ↗ |
| 15 Dec 2022 | Scuola Statale Secondaria di I^ grado “Bianco-Pascoli”, di Fasano (BR)The school was fined by the Garante 3,000 EUR for violations in the processing of personal data, including minors' health information. The authority found that the processing lacked a proper legal basis and sufficient transparency. | IT | Garante | GDPR | €3,000 | ↗ |
| 26 Mar 2026 | Ordine degli Avvocati di PiacenzaOrdine degli Avvocati di Piacenza was fined EUR 3,000 by the Garante for improper handling of disciplinary sanctions in its professional register. The authority found that the processing did not comply with data protection requirements. | IT | Garante | GDPR | €3,000 | ↗ |
| 15 Jul 2022 | FEDERACIÓN DE ATENCIÓN A LA CIUDADANÍA DE LA UNIÓN SINDICAL OBRERA (FAC-USO)The organization continued sending emails to an individual after they requested deletion of their personal data. The AEPD found a breach of Article 6 of the GDPR and imposed a EUR 3,000 fine. | ES | AEPD | GDPR | €3,000 | ↗ |
| 17 Oct 2024 | CHIRURGIEN DENTISTE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 3,000 on CHIRURGIEN DENTISTE under a simplified procedure. The authority also issued an injunction, indicating that remedial action is required. | FR | CNIL | GDPR | €3,000 | ↗ |
| 25 Sept 2025 | Comune di Isola del Gran Sasso d’ItaliaThe Garante fined the Comune di Isola del Gran Sasso d’Italia EUR 3,000 for unlawfully publishing personal data on its institutional website, including information related to criminal proceedings. The authority found breaches of lawfulness, fairness, transparency, and data minimization. | IT | Garante | GDPR | €3,000 | ↗ |
| 21 Jul 2022 | WUNSCHURLAUB S.L.WUNSCHURLAUB S.L. was fined by the AEPD 3,000 EUR for storing user passwords in plain text and sending them by email without encryption. The authority found this breached GDPR Article 32 on appropriate security measures. | ES | AEPD | GDPR | €3,000 | ↗ |
| 12 Aug 2021 | NATURAL LOGISTICS, S.L.NATURAL LOGISTICS, S.L. was fined by the AEPD EUR 3,000 for sending unsolicited commercial emails despite the recipient's objection. This breached Article 21 of the LSSI on marketing communications without consent. | ES | AEPD | ePrivacy | €3,000 | ↗ |