BULLETIN №082Last updated · 29 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 02 Jul 2020 | GTL s.r.l.GTL s.r.l. was fined EUR 3,000 by the Garante for failing to respond to an individual's data access request. The authority treated this as a breach of GDPR obligations. | IT | Garante | GDPR | €3,000 | ↗ |
| 04 Apr 2023 | Tensa Art Design SRLThe company was fined for sending commercial messages to individuals by phone and email despite their requests to stop contact. The case concerned failure to respect opt-out requests against further marketing communication. | RO | ANSPDCP | GDPR | €3,000 | ↗ |
| 19 Dec 2024 | SOCIETE GERANT UNE SALLE DE SPORT (procédure simplifiée)The CNIL imposed an administrative fine of EUR 3,000 on SOCIETE GERANT UNE SALLE DE SPORT under a simplified procedure. The case concerns a breach of rules covered by the supervisory authority’s decision. | FR | CNIL | GDPR | €3,000 | ↗ |
| 07 Mar 2024 | Hotel Milano di Foschi Eros e Righini Rina & C. SncThe Garante fined Hotel Milano EUR 3,000 for improper installation of surveillance cameras. The cameras captured public streets and third-party properties, and the informational signage was inadequate. | IT | Garante | GDPR | €3,000 | ↗ |
| 07 Apr 2022 | Анонимизирано (CPDP решение-по-жалба-с-рег-№-ппн-01-101136-0)The CPDP imposed fines on two individuals for unlawful video surveillance in a co-owned property. The authority found breaches of GDPR principles of lawfulness and data minimization. | BG | CPDP | GDPR | €1,534 | ↗ |
| 28 Apr 2022 | Comune di Monte Sant’AngeloThe Municipality of Monte Sant’Angelo was fined 3,000 EUR by the Garante for breaching data protection principles. The authority found that personal data had been made accessible online in violation of lawfulness, fairness, transparency, and data minimization. | IT | Garante | GDPR | €3,000 | ↗ |
| 01 Jan 2020 | JUST LANDED, S.L.JUST LANDED, S.L. was fined EUR 3,000 by the AEPD for failing to provide a privacy policy and a cookie policy on its website. The authority cited a breach of GDPR Article 13 and LSSI Article 22.2. | ES | AEPD | ePrivacy | €3,000 | ↗ |
| 04 Aug 2014 | SERVICIOS DE DEPILACION BLOC, S.L.SERVICIOS DE DEPILACION BLOC, S.L. was fined by the AEPD EUR 3,000 for sending unsolicited commercial SMS messages to a former client. The authority found that this conduct breached Article 21 of the LSSI on marketing communications. | ES | AEPD | ePrivacy | €3,000 | ↗ |
| 12 Feb 2021 | KUKIMBIA S.L.KUKIMBIA S.L. was fined EUR 3,000 by the AEPD for leaving documents containing personal data unattended. The authority found this to be a breach of data security obligations under Article 32(1) of the GDPR. | ES | AEPD | GDPR | €3,000 | ↗ |
| 06 Feb 2025 | ALPHA BANK ANONYMI ETAIREIAAlpha Bank was fined by the HDPA for failing to implement adequate security measures. This led to unauthorized access to the personal data of 6,176 employees after a system administrator role was not revoked following an internal transfer. | GR | HDPA | GDPR | €3,000 | ↗ |
| 06 Jun 2021 | FLY FUT, S.L.FLY FUT, S.L. was fined by the AEPD in the amount of 3,000 EUR for recording a minor during football matches without prior consent. The case concerns a breach of data protection rules and the requirement to obtain consent before processing a child’s image. | ES | AEPD | GDPR | €3,000 | ↗ |
| 18 Jul 2025 | LEIVA BUS, S.L.LEIVA BUS, S.L. was fined by the AEPD 3,000 EUR for disclosing the personal data of a claimant and a third party in a damage assessment document. The case concerned a breach of data protection rules and unauthorized disclosure of information. | ES | AEPD | GDPR | €3,000 | ↗ |
| 01 Dec 2022 | WoolenWoolen was fined EUR 3,000 by the Garante for a video surveillance system that did not meet transparency requirements. The authority cited a breach of GDPR Article 13 and Article 114 of the Italian Privacy Code. | IT | Garante | GDPR | €3,000 | ↗ |
| 19 Sept 2016 | CONVERSALES INNOVA, S.L.CONVERSALES INNOVA, S.L. was fined by the AEPD €3,000 for sending unsolicited commercial emails without prior consent from recipients. This conduct breached Article 21 of the LSSI. | ES | AEPD | ePrivacy | €3,000 | ↗ |
| 08 Feb 2007 | Comune di FirenzeGarante imposed a EUR 3,000 fine on Comune di Firenze for failing to provide adequate information to individuals about the processing of personal data through a video surveillance system. The authority found a breach of Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €3,000 | ↗ |
| 29 Apr 2026 | Consiglio Nazionale dei Periti Industriali e dei Periti Industriali LaureatiThe Consiglio Nazionale dei Periti Industriali e dei Periti Industriali Laureati was fined €3,000 by the Garante. The authority found that the organization failed to ensure transparency in data processing, breaching GDPR principles of lawfulness, fairness, and transparency. | IT | Garante | GDPR | €3,000 | ↗ |
| 22 Feb 2024 | Comune di Civita CastellanaComune di Civita Castellana was fined EUR 3,000 by the Garante for improper handling of personal data during COVID-19 data transmission. The authority found that GDPR formalities were not properly complied with. | IT | Garante | GDPR | €3,000 | ↗ |
| 19 Nov 2025 | Greencorp S.R.L.Greencorp S.R.L. was fined EUR 3,000 by ANSPDCP. The authority found that the company failed to notify a personal data security breach. | RO | ANSPDCP | GDPR | €3,000 | ↗ |
| 18 Jan 2023 | CONSEJERÍA DE CULTURA DE LA RIOJACONSEJERÍA DE CULTURA DE LA RIOJA was fined for failing to implement corrective measures after the unauthorized recording and dissemination of surveillance footage from the Museo de La Rioja. The authority found a breach of Article 32 GDPR concerning appropriate security measures. | ES | AEPD | GDPR | €3,000 | ↗ |
| 22 Nov 2021 | COMUNIDAD DE PROPIETARIOS R.R.R.The entity was fined by the AEPD for operating a video surveillance system that recorded public transit areas without a justified basis. The authority found a breach of data protection principles. | ES | AEPD | GDPR | €3,000 | ↗ |