BULLETIN №082Last updated · 30 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 15 Jun 2022 | S.C.In May 2022, the Romanian supervisory authority ANSPDCP completed an investigation into the operator S.C. and found a violation of GDPR provisions. A fine of 3,000 EUR was imposed. | RO | ANSPDCP | GDPR | €3,000 | ↗ |
| 17 Apr 2026 | Provvedimento del 17 aprile 2026 [10254325]The supervisory authority found that a video surveillance system with 25 cameras operated without the required informational signage. The breach concerned GDPR information obligations. | IT | Garante | GDPR | €3,000 | ↗ |
| 09 Mar 2023 | Aesse S.r.l.s.Aesse S.r.l.s. was fined by the Italian Garante in the amount of €3,000. The case concerned unsolicited telemarketing calls made without consent and insufficient information provided about the source of personal data. | IT | Garante | GDPR | €3,000 | ↗ |
| 09 Mar 2023 | Stefano MolenaThe Garante imposed a EUR 3,000 fine on Stefano Molena for operating a surveillance camera without the required informational signage. The breach concerned privacy rules and the duty to properly inform individuals subject to monitoring. | IT | Garante | GDPR | €3,000 | ↗ |
| 18 Aug 2021 | EULEN SEGURIDAD, S.A.EULEN SEGURIDAD, S.A. was fined by the AEPD 3,000 EUR for disclosing employees' DNI numbers in a workplace notice. The authority found a breach of confidentiality and data security principles. | ES | AEPD | GDPR | €3,000 | ↗ |
| 15 Dec 2022 | B.B.B.The entity was fined for operating surveillance cameras directed at public areas without the required authorization or signage. The authority found this to be a breach of data protection rules. | ES | AEPD | GDPR | €3,000 | ↗ |
| 29 May 2008 | Circolo privato 'Astoria'The private club “Astoria” was fined 3,000 EUR by the Garante for failing to provide the required data protection notice to individuals identified through its video surveillance system. The breach concerned Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €3,000 | ↗ |
| 27 Mar 2025 | Comune di Palma di MontechiaroThe Municipality of Comune di Palma di Montechiaro was fined EUR 3,000 by the Italian data protection authority, Garante. The sanction concerned the failure to communicate the contact details of its Data Protection Officer to the authority, as required by Article 37 GDPR. | IT | Garante | GDPR | €3,000 | ↗ |
| 25 Nov 2022 | OTP LEASING ROMANIA IFN SAOTP LEASING ROMANIA IFN SA was fined by ANSPDCP for breaching data security provisions. The penalty followed a data breach notification indicating that personal data had not been adequately protected. | RO | ANSPDCP | GDPR | €3,000 | ↗ |
| 08 Feb 2023 | MEDECIN GENERALISTE (procédure simplifiée)The CNIL imposed a EUR 3,000 fine on MEDECIN GENERALISTE under a simplified procedure. The authority also issued an injunction to remedy the identified deficiencies. | FR | CNIL | GDPR | €3,000 | ↗ |
| 12 Nov 2025 | Fan Courier Express S.R.L.Fan Courier Express S.R.L. was fined by ANSPDCP in the amount of €3,000 for processing personal data in breach of GDPR. The case concerned unlawful handling of personal data by the company. | RO | ANSPDCP | GDPR | €3,000 | ↗ |
| 24 Jun 2025 | I ASPIDA TOU DAVIDThe entity did not satisfy a minor's request to access personal data, which constitutes a breach of GDPR principles. HDPA imposed a fine of EUR 3,000. | GR | HDPA | GDPR | €3,000 | ↗ |
| 16 Oct 2024 | Your Consulting SRLThe national supervisory authority completed an investigation into Your Consulting SRL and found violations of GDPR provisions. As a result, a fine of EUR 3,000 was imposed. | RO | ANSPDCP | GDPR | €3,000 | ↗ |
| 20 Nov 2008 | G.F.A. marketing di Cavezzali PatriziaG.F.A. marketing di Cavezzali Patrizia was fined EUR 3,000 by the Italian Garante for failing to provide the required data protection notice to recipients of promotional faxes. The conduct breached Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €3,000 | ↗ |
| 01 Mar 2017 | FRONTERA SISTEMAS DE ESPAÑA SLFRONTERA SISTEMAS DE ESPAÑA SL was fined EUR 3,000 by the AEPD for installing cookies on users' devices without prior consent. The authority found this breached the information and consent requirements for data storage and retrieval devices. | ES | AEPD | ePrivacy | €3,000 | ↗ |
| 12 Jun 2021 | MERCEDES GERENCIA, S.L.MERCEDES GERENCIA, S.L. was fined by the AEPD in the amount of 3,000 EUR for breaching Article 58.1 of the GDPR. The case concerned non-compliance with obligations related to the supervisory authority’s powers. | ES | AEPD | GDPR | €3,000 | ↗ |
| 12 Apr 2021 | INSTAPACK, S.L.INSTAPACK, S.L. was fined by the AEPD for sending unsolicited SMS messages without valid consent. The authority also found that the company failed to respond to a deletion request, constituting a breach of GDPR Article 6(1)(a). | ES | AEPD | GDPR | €3,000 | ↗ |
| 01 May 2025 | SC Piramida Trade Invest SRLThe Romanian DPA ANSPDCP imposed a total fine of EUR 3,000 on SC Piramida Trade Invest SRL for unlawful audio-video monitoring of employees and inadequate staff information. It also found that the company failed to respond to access, erasure, and objection requests within the legal deadline; a separate email-forwarding issue resulted only in a warning. | RO | Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal | GDPR | €3,000 | ↗ |
| 28 Sept 2023 | Palombaro s.r.l.Palombaro s.r.l. was fined by the Garante in the amount of 3,000 EUR for operating a video surveillance system without adequate informational signage. The authority found a breach of GDPR transparency requirements toward individuals being recorded. | IT | Garante | GDPR | €3,000 | ↗ |
| 30 Sept 2024 | ASSOCIATION AYANT POUR OBJET LA CREATION D'UN RESEAU DE SANTE PSYCHIATRIQUE (procédure simplifiée)CNIL imposed an administrative fine of EUR 3,000 on ASSOCIATION AYANT POUR OBJET LA CREATION D'UN RESEAU DE SANTE PSYCHIATRIQUE. The case concerns a breach of personal data protection rules under a simplified procedure. | FR | CNIL | GDPR | €3,000 | ↗ |