BULLETIN №082Last updated · 30 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.2%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 01 Jan 2024 | MAD COOL FESTIVAL, S.L.MAD COOL FESTIVAL, S.L. was fined 3,500 EUR by the AEPD for a data breach on its website. The incident exposed users’ personal data, indicating non-compliance with GDPR Articles 5(1)(f) and 32. | ES | AEPD | GDPR | €3,500 | ↗ |
| 10 Mar 2022 | Anonymisé (CNPD decision-07-fr-2022)The CNPD found that Société A breached the GDPR by failing to comply with data minimization, retention limitation, and information provision requirements. The case concerned improper personal data processing in relation to compliance obligations. | LU | CNPD | GDPR | €3,500 | ↗ |
| 27 Mar 2025 | Comune di MilazzoThe Garante fined the Comune di Milazzo €3,600 for failing to provide adequate data protection information on its website. The authority found a breach of GDPR principles of lawfulness, fairness, and transparency. | IT | Garante | GDPR | €3,600 | ↗ |
| 13 Dec 2022 | Anonymisé (CNPD decision-21-fr-2022)The company was fined EUR 3,700 by the CNPD for breaching the transparency obligations under Article 12(1) of the GDPR. The authority found that information was not sufficiently accessible to users. | LU | CNPD | GDPR | €3,700 | ↗ |
| 13 Dec 2022 | Anonymisé (CNPD decision-24-fr-2022)The entity failed to meet GDPR transparency obligations, particularly regarding the accessibility and comprehensibility of information provided to data subjects. CNPD imposed a fine of EUR 3,700. | LU | CNPD | GDPR | €3,700 | ↗ |
| 10 Oct 2016 | ROCK INTERNET S.L.ROCK INTERNET S.L. was fined 3,800 EUR by the AEPD. The case concerned sending unsolicited commercial emails without recipient consent, in breach of Article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €3,800 | ↗ |
| 13 Jan 2015 | LEROY MERLIN ESPAÑA S.L.U.LEROY MERLIN ESPAÑA S.L.U. was fined by the AEPD EUR 3,900 for sending unsolicited commercial SMS messages without recipient consent. The authority found this conduct breached Article 21 of the LSSI. | ES | AEPD | ePrivacy | €3,900 | ↗ |
| 13 Jun 2022 | SOCIETE D'ENTRETIEN ET REPARATION DE VEHICULESCNIL imposed a liquidation of the penalty payment against SOCIETE D'ENTRETIEN ET REPARATION DE VEHICULES in the amount of EUR 3,900. The measure relates to failure to comply with a prior obligation within the required deadline. | FR | CNIL | GDPR | €3,900 | ↗ |
| 28 May 2026 | Action Fit di MilanoThe Garante fined Action Fit di Milano EUR 3,930 for sending unsolicited commercial emails to a customer without consent. The authority found this to be a breach of data protection rules. | IT | Garante | GDPR | €3,930 | ↗ |
| 25 Sept 2025 | Comune di PazzanoThe Garante imposed a fine of 3,960 EUR on Comune di Pazzano for failing to meet data protection obligations. The case concerned, among other issues, the improper provision of the Data Protection Officer’s contact details and other GDPR requirements. | IT | Garante | GDPR | €3,960 | ↗ |
| 09 Oct 2025 | SOCIETE EXERCANT UNE ACTIVITE DE VENTE A DISTANCE SUR CATALOGUE GENERAL (procédure simplifiée)The CNIL imposed an administrative fine of EUR 4,000 on SOCIETE EXERCANT UNE ACTIVITE DE VENTE A DISTANCE SUR CATALOGUE GENERAL. The case was handled under a simplified procedure. | FR | CNIL | GDPR | €4,000 | ↗ |
| 23 Apr 2015 | Soprintendenza per i Beni Architettonici e Paesaggistici di Venezia e LagunaThe Soprintendenza per i Beni Architettonici e Paesaggistici di Venezia e Laguna was fined 4,000 EUR by the Garante. The authority found that personal data had been unlawfully communicated to private entities without an appropriate legal basis, in breach of Article 19 of the Italian Data Protection Code. | IT | Garante | GDPR | €4,000 | ↗ |
| 25 Mar 2021 | Comune di MonteiasiComune di Monteiasi was fined by the Garante €4,000 for breaching the data minimization principle. The municipality published personal data on its website, including names and IBANs, that were not necessary for transparency purposes. | IT | Garante | GDPR | €4,000 | ↗ |
| 13 Oct 2022 | B.B.B.A tenant complained that the landlord installed a surveillance camera in the kitchen of the rented property without consent. The AEPD found a breach of data protection rules and imposed a EUR 4,000 fine. | ES | AEPD | GDPR | €4,000 | ↗ |
| 13 Feb 2025 | Comune di TuscaniaThe Garante imposed a 4,000 EUR fine on Comune di Tuscania for violating data protection rules. The authority took into account the limited financial resources of the small municipality when setting the sanction. | IT | Garante | GDPR | €4,000 | ↗ |
| 27 Mar 2014 | Comune di ConversanoComune di Conversano was fined 4,000 EUR by the Garante for failing to update the annual Security Policy Document. The breach concerned compliance with data protection obligations. | IT | Garante | GDPR | €4,000 | ↗ |
| 07 Nov 2018 | Comune di BuccinoComune di Buccino was fined for unlawfully publishing personal data online without a legal basis. This violated Article 19 of the Italian Data Protection Code. | IT | Garante | GDPR | €4,000 | ↗ |
| 06 Oct 2016 | Comune di FurnariThe Municipality of Furnari was fined 4,000 EUR by the Garante. The authority found that personal data remained published on the institutional website beyond the legally permitted period. | IT | Garante | GDPR | €4,000 | ↗ |
| 18 Nov 2015 | G.M.C. - Giuseppe Marra Communications s.a.p.a.G.M.C. - Giuseppe Marra Communications s.a.p.a. was fined by the Garante in the amount of €4,000 for unlawfully obtaining consent for data processing through a newsletter subscription. The form included marketing purposes beyond the stated intent, which breached Article 23 of the Italian Data Protection Code. | IT | Garante | GDPR | €4,000 | ↗ |
| 11 Dec 2014 | Progetto Acqua Firenze s.r.l.Progetto Acqua Firenze s.r.l. was fined by the Garante for making an unsolicited promotional phone call. The conduct infringed the complainant's right to object as recorded in the public opt-out list. | IT | Garante | GDPR | €4,000 | ↗ |