BULLETIN №082Last updated · 30 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.2%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 13 Nov 2023 | Rompetrol Downstream SRLRompetrol Downstream SRL was fined EUR 110,000 by ANSPDCP for failing to ensure the security of personal data. The authority found a breach of Article 32 GDPR, which requires appropriate technical and organizational measures. | RO | ANSPDCP | GDPR | €110,000 | ↗ |
| 13 Nov 2023 | RECICLAJES LOGROÑO, S.L.RECICLAJES LOGROÑO, S.L. was fined by the AEPD 10,000 EUR for photocopying a customer's ID without consent and for failing to provide privacy policy information. The authority found breaches of GDPR data minimization and transparency principles. | ES | AEPD | GDPR | €10,000 | ↗ |
| 13 Nov 2023 | Kerepesi Polgármesteri HivatalKerepesi Polgármesteri Hivatal was fined by NAIH for unlawful data processing linked to the operation of a public surveillance camera system. The authority found violations of several provisions of the Infotv. | HU | NAIH | GDPR | €21,200 | ↗ |
| 10 Nov 2023 | VERNE INFORMATION TECHNOLOGY, S.L.VERNE INFORMATION TECHNOLOGY, S.L. was fined 2,000 EUR by the AEPD. The case concerned sending unsolicited commercial electronic communications without prior consent or an existing contractual relationship. | ES | AEPD | ePrivacy | €2,000 | ↗ |
| 09 Nov 2023 | Complete Marketing Services LtdBetween 8 June 2021 and 4 February 2022, Complete Marketing Services Ltd instigated 242,497 unsolicited direct marketing calls in breach of PECR. The ICO became aware of the matter after complaints about live marketing calls relating to road traffic accidents and personal injury claims were reported via the TPS. | GB | ICO | ePrivacy | €172,000 | ↗ |
| 09 Nov 2023 | DPG Professional Services LtdBetween 3 August 2021 and 3 August 2022, DPG made 74,119 unsolicited calls for direct marketing purposes, breaching Reg 21 of PECR. The activity resulted in 13 complaints and came to the Commissioner’s attention through an operation focused on life insurance and later life planning marketing. | GB | ICO | ePrivacy | €103,000 | ↗ |
| 08 Nov 2023 | SOCIETE AYANT POUR ACTIVITE LE DEVELOPPEMENT ET LA MISE EN OEUVRE DE LOGICIELS DE SURVEILLANCE DES EMPLOYES (procédure simplifiée)CNIL imposed an administrative fine of 20,000 EUR on the company under a simplified procedure. The decision concerns breaches linked to the company's activity in employee monitoring software. | FR | CNIL | GDPR | €20,000 | ↗ |
| 07 Nov 2023 | FondrådgivareIndecap AB was fined by IMY SEK 500,000 for failing to ensure an appropriate level of security for personal data. As a result, an email was sent to unauthorized recipients and contained sensitive customer information. | SE | IMY | GDPR | €42,845 | ↗ |
| 03 Nov 2023 | OTP BANK ROMANIA SAThe National Supervisory Authority for Personal Data Processing imposed a fine of EUR 3,000 on OTP BANK ROMANIA SA for GDPR violations. The case concerned non-compliance with personal data protection requirements. | RO | ANSPDCP | GDPR | €3,000 | ↗ |
| 02 Nov 2023 | ASYMECO, S.A.ASYMECO, S.A. was fined EUR 5,000 by the AEPD for sending clients’ personal data to an employee’s private WhatsApp without proper authorization. The authority found this breached GDPR Articles 6(1) and 32. | ES | AEPD | GDPR | €5,000 | ↗ |
| 02 Nov 2023 | KOMPASS SPAIN, S.L.U.KOMPASS SPAIN, S.L.U. was fined by the AEPD in the amount of 5,000 EUR for sending unsolicited email messages. The emails were sent despite the recipient’s attempts to unsubscribe and their inclusion on the Robinson List. | ES | AEPD | ePrivacy | €5,000 | ↗ |
| 30 Oct 2023 | CLÍNICA PARÍS, S.L.CLÍNICA PARÍS, S.L. was fined 1,000 EUR by the AEPD for failing to properly handle a data subject access request. The authority found a breach of GDPR obligations. | ES | AEPD | GDPR | €1,000 | ↗ |
| 27 Oct 2023 | Telemach HrvatskaAZOP imposed a EUR 4.5 million fine on Telemach Hrvatska for GDPR violations. The authority found that the company transferred personal data to Serbia without valid transfer safeguards, failed to properly inform data subjects, and overprocessed copies of employee ID documents. | HR | AZOP | GDPR | €4,500,000 | ↗ |
| 27 Oct 2023 | Asociația de Proprietari bloc A1The homeowners association was fined by ANSPDCP for failing to implement measures ordered by the authority and for unlawfully disclosing owners’ names on maintenance lists without consent. The case concerns breaches of personal data protection rules and non-compliance with supervisory instructions. | RO | ANSPDCP | GDPR | €501 | ↗ |
| 26 Oct 2023 | Edizioni Proposta Sud S.r.l.The Garante fined Edizioni Proposta Sud S.r.l. €20,000 for publishing false information about an individual's health status without verifying its accuracy. The authority found this breached GDPR principles on data protection and accuracy. | IT | Garante | GDPR | €20,000 | ↗ |
| 26 Oct 2023 | Argentum Data Solutions LtdBetween 1 January 2021 and 31 January 2022, a total of 2,330,423 SMS messages were sent without consent. Argentum Data Solutions Ltd sent 24,309 messages directly and allowed its lines to be used by third parties to send the remaining 2,306,114. The conduct breached regulation 22 of PECR and came to the ICO’s attention through complaints reported via the 7726 spam tool. | GB | ICO | ePrivacy | €74,568 | ↗ |
| 26 Oct 2023 | Regione LombardiaThe Garante fined Regione Lombardia EUR 20,000 for improperly publishing the personal data of numerous workers online. The disclosed information also included health-related data, which breached privacy rules. | IT | Garante | GDPR | €20,000 | ↗ |
| 26 Oct 2023 | SOCIETE AYANT POUR ACTIVITE PRINCIPALE L'EVENEMENTIEL (procédure simplifiée)The CNIL imposed a EUR 2,000 fine on SOCIETE AYANT POUR ACTIVITE PRINCIPALE L'EVENEMENTIEL under a simplified procedure. The case concerned a breach of personal data protection rules. | FR | CNIL | GDPR | €2,000 | ↗ |
| 26 Oct 2023 | Azienda Sanitaria Locale TO3Azienda Sanitaria Locale TO3 was fined by the Garante for a health data breach affecting four individuals. The incident lasted nine days and was deemed negligent. | IT | Garante | GDPR | €6,000 | ↗ |
| 26 Oct 2023 | Provvedimento del 26 ottobre 2023 [9960920]The Garante imposed a EUR 1,000 fine on a condominium administrator for installing a video surveillance system without a proper legal basis or assembly resolution. The conduct was found to breach GDPR rules on lawful processing. | IT | Garante | GDPR | €1,000 | ↗ |