BULLETIN №082Last updated · 30 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.2%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 11 Oct 2023 | B.B.B.The entity installed surveillance cameras without consent in a rented equestrian club. The recordings captured minors and disabled individuals, which constituted a privacy violation. | ES | AEPD | GDPR | €2,000 | ↗ |
| 10 Oct 2023 | UAB RamidonasThe supervisory authority imposed a €6,000 fine on UAB Ramidonas for personal data security violations. The case concerned deficiencies in data protection controls that could have exposed individuals’ information to risk. | LT | Valstybinė duomenų apsaugos inspekcija | GDPR | €6,000 | ↗ |
| 10 Oct 2023 | American ExpressCNIL imposed a EUR 1,500,000 fine on American Express for placing cookies without prior user consent. The case concerns breaches of GDPR and privacy law requirements. | FR | CNIL | GDPR | €1,500,000 | ↗ |
| 10 Oct 2023 | ComuneThe Italian data protection authority fined a municipality EUR 12,000 for unlawfully publishing personal data online in access request registers. Documents in the transparency section of the municipal website exposed names, protocol numbers, and other sensitive details of hundreds of citizens. | IT | Garante per la protezione dei dati personali | GDPR | €12,000 | ↗ |
| 10 Oct 2023 | TemuThe European Commission imposed a EUR 200 million fine on Temu under the Digital Services Act. The authority said Temu failed to identify, analyse, and assess systemic risks linked to illegal products offered on its platform. | EU | European Commission | DSA | €200,000,000 | ↗ |
| 10 Oct 2023 | Hogeschool van Arnhem en Nijmegen (HAN)The Autoriteit Persoonsgegevens imposed a fine of EUR 175,000 on Hogeschool van Arnhem en Nijmegen (HAN). The authority found that the institution did not provide sufficient protection for students’ personal data. | NL | Autoriteit Persoonsgegevens | GDPR | €175,000 | ↗ |
| 10 Oct 2023 | GALENICUM HEALTH, S.L.U.GALENICUM HEALTH, S.L.U. was fined EUR 500 by the AEPD for failing to display informational signage about its video surveillance system. The authority found a breach of Article 5(1)(c) GDPR in relation to transparency and proper notice. | ES | AEPD | GDPR | €500 | ↗ |
| 06 Oct 2023 | Ítélet a NAIH-19-18-2024 sz. ügyben (Kúria Kfv.IV.37.804/2025/2)The entity was fined for improper processing of personal data in a nationwide energy efficiency program. The authority found inadequate transparency and consent procedures, as well as insufficient data security measures. | HU | NAIH | GDPR | €194,000 | ↗ |
| 06 Oct 2023 | Texas Andreas Petersen A/SThe Danish Data Protection Authority reported Texas Andreas Petersen A/S to the police and recommended a fine of at least DKK 200,000. The case concerned the collection and sharing of website visitors' personal data without a legal basis. | DK | Datatilsynet | GDPR | €26,818 | ↗ |
| 06 Oct 2023 | SOCIETE DE CONSEILS EN SYSTEMES ET LOGICIELS INFORMATIQUES (procédure simplifiée)CNIL imposed a fine of EUR 20,000 on SOCIETE DE CONSEILS EN SYSTEMES ET LOGICIELS INFORMATIQUES under a simplified procedure. The decision concerns a breach of personal data protection rules. | FR | CNIL | GDPR | €20,000 | ↗ |
| 05 Oct 2023 | DPP Law LtdThe Information Commissioner's Office issued a monetary penalty notice against DPP Law Ltd. The firm was fined GBP 60,000 for failing to implement appropriate technical and organisational measures to secure personal data. | GB | Information Commissioner's Office | GDPR | €69,282 | ↗ |
| 04 Oct 2023 | Amazon EuropeThe CNPD imposed a fine of EUR 746,000,000 on Amazon Europe for breaches of data protection rules. The case concerned shortcomings in the processing of personal data and compliance with GDPR requirements. | LU | CNPD | GDPR | €746,000,000 | ↗ |
| 03 Oct 2023 | ASOCIACIÓN DE PROFESIONALES DE LA SEGURIDAD PRIVADA DE ESPAÑAThe association was fined for sending emails from personal email addresses instead of corporate ones. The authority found that this practice breached GDPR confidentiality and security requirements. | ES | AEPD | GDPR | €1,500 | ↗ |
| 03 Oct 2023 | MAPFRE ESPAÑA COMPAÑÍA DE SEGUROS Y REASEGUROS, S.A.MAPFRE España was fined by the AEPD 1,140,000 EUR for requesting excessive personal data from a guarantor in a rental contract. The authority found breaches of GDPR data minimization and transparency principles. | ES | AEPD | GDPR | €1,140,000 | ↗ |
| 03 Oct 2023 | Digivo Media LimitedBetween 24 March 2021 and 7 September 2021, 415,041 text messages were sent without valid consent, breaching Regulation 22 of PECR. The ICO identified the matter after reviewing debt management complaints submitted via the SPAM reporting tool. | GB | ICO | ePrivacy | €57,620 | ↗ |
| 03 Oct 2023 | Utbildningsnämnden i Stockholms stad – Aspuddens skolaThe Stockholm City Education Committee was fined by IMY 800,000 SEK for unlawful camera surveillance at Aspuddens school. The authority found breaches of legality and data minimization principles, as well as a failure to provide the required information under GDPR. | SE | IMY | GDPR | €68,744 | ↗ |
| 02 Oct 2023 | AVENTURA EN TRAMPOLINES, S.L.Aventura en Trampolines, S.L. was fined by the AEPD EUR 2,000 for breaching GDPR Article 7. The company required consent for image use without allowing users to refuse specific terms, which did not meet data protection requirements. | ES | AEPD | GDPR | €2,000 | ↗ |
| 02 Oct 2023 | COMUNIDAD DE PROPIETARIOS A.A.A.The president of a homeowners' association shared a bank receipt containing personal data in a WhatsApp group. AEPD found a breach of confidentiality principles under GDPR and imposed a EUR 2,000 fine. | ES | AEPD | GDPR | €2,000 | ↗ |
| 02 Oct 2023 | Cez Vânzare S.A.Cez Vânzare S.A. was fined by ANSPDCP EUR 1,000 for a data protection breach. The incident resulted in unauthorized disclosure or access to personal data, including names, correspondence addresses, and customer codes of both individuals and legal entities. | RO | ANSPDCP | GDPR | €1,000 | ↗ |
| 01 Oct 2023 | Capita plc and CPSLThe Information Commissioner's Office imposed a GBP 2,000,000 fine on Capita plc and CPSL. The case concerned data protection breaches linked to unsolicited marketing calls, indicating improper use of contact data. | GB | Information Commissioner's Office | GDPR | €2,313,000 | ↗ |