BULLETIN №082Last updated · 31 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.4%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 18 Aug 2023 | Személyes adatok kezelése online közszolgáltatás nyújtása soránThe supervisory authority found that the controller did not provide adequate information about the data retention period. It also unlawfully refused access to the requested call recordings, breaching GDPR Articles 12, 13, and 15. | HU | NAIH | GDPR | €13,050 | ↗ |
| 09 Aug 2023 | AUTOFER, S.L.AUTOFER, S.L. was fined EUR 10,000 by the AEPD for sending multiple unsolicited advertising SMS messages. The messages were sent despite the recipient’s prior request not to receive further communications, breaching Article 21 of the LSSI. | ES | AEPD | ePrivacy | €10,000 | ↗ |
| 08 Aug 2023 | VODAFONE ESPAÑA, S.A.U.The AEPD fined VODAFONE ESPAÑA, S.A.U. 100,000 EUR for processing personal data without proper authorization. The case involved unsolicited marketing calls and messages sent to a complainant who had no commercial relationship with the company. | ES | AEPD | GDPR | €100,000 | ↗ |
| 07 Aug 2023 | FORMACIÓN Y EMPLEO DE EXTREMADURA, S.L.The company sent emails to multiple recipients without using BCC, allowing each recipient to see the other recipients’ email addresses. AEPD treated this as a breach of data protection rules and imposed an 8,000 EUR fine. | ES | AEPD | GDPR | €8,000 | ↗ |
| 07 Aug 2023 | Anonymizováno (ÚOOÚ UOOU-00414.23-30)The decision confirms a fine for a healthcare entity for failing to notify data subjects and document a personal data breach after a cyberattack. The authority found breaches of GDPR transparency and notification obligations. | CZ | UOOU | GDPR | €12,756 | ↗ |
| 03 Aug 2023 | Sdam s.r.l.Sdam s.r.l. was fined by the Italian data protection authority, Garante, in the amount of 5,000 EUR. The case concerned the sending of promotional emails without proper consent, which constitutes a GDPR violation. | IT | Garante | GDPR | €5,000 | ↗ |
| 03 Aug 2023 | Med Life SAMed Life SA was fined EUR 2,000 by ANSPDCP. The authority found that the company violated the complainant’s right of access by refusing to provide certain video recordings from the reception area of one of its hospitals. | RO | ANSPDCP | GDPR | €2,000 | ↗ |
| 02 Aug 2023 | Adatbázisban tárolt személyes adatok kezelésének jogszerűségeThe entity was fined by NAIH HUF 1,500,000 for processing personal data without a legal basis. The authority also found that the entity failed to demonstrate compliance with data processing requirements and did not provide adequate information to data subjects. | HU | NAIH | GDPR | €3,870 | ↗ |
| 31 Jul 2023 | DOÑA B.B.B.The sanctioned individual created a WhatsApp group with 255 participants without prior consent. As a result, the names and phone numbers of the participants were disclosed, constituting a breach of personal data protection rules. | ES | AEPD | GDPR | €2,000 | ↗ |
| 27 Jul 2023 | B.B.B.A neighbor installed a surveillance camera that captured images of the complainant’s property without authorization. The AEPD found this to be a breach of Article 5(1)(c) GDPR and imposed a fine of EUR 300. | ES | AEPD | GDPR | €300 | ↗ |
| 27 Jul 2023 | B.B.B.B.B.B. was fined EUR 800 by the AEPD for installing a surveillance system that captured images and sounds from a neighbor’s property and potentially the public street. The authority found breaches of GDPR Articles 13 and 6(1), citing the lack of a valid legal basis and proper notice to affected individuals. | ES | AEPD | GDPR | €800 | ↗ |
| 25 Jul 2023 | EDICIONES PERIÓDICAS DEL NOROESTE, S.L.The entity published a private video on Twitter without the data subject’s consent. The authority found a breach of data minimization because excessive data were processed beyond what was necessary for the intended purpose. | ES | AEPD | GDPR | €10,000 | ↗ |
| 21 Jul 2023 | ATLAS ENTERTAINMENT, S.L.ATLAS ENTERTAINMENT, S.L. did not comply with a data subject’s request to delete personal data. The AEPD imposed a fine of EUR 1,000 for the GDPR breach. | ES | AEPD | GDPR | €1,000 | ↗ |
| 21 Jul 2023 | B.B.B.B.B.B. was fined by the AEPD 300 EUR for installing surveillance cameras without the required authorization. The cameras captured public areas and a neighbor's property, which breached data protection rules. | ES | AEPD | GDPR | €300 | ↗ |
| 21 Jul 2023 | Hozzáférési kérelem nemteljesítéseThe controller did not respond to the access request within the one-month deadline. It also failed to provide substantive information about the processing of personal data, in breach of GDPR Articles 12 and 15. | HU | NAIH | GDPR | €26,300 | ↗ |
| 20 Jul 2023 | Hozzáférési jog terjedelmeThe decision found that the bank breached GDPR by failing to provide access to camera footage and recordings and by not implementing security measures when sending data. A fine of HUF 2,000,000 was imposed. | HU | NAIH | GDPR | €5,280 | ↗ |
| 18 Jul 2023 | ING BANK NV Amsterdam Sucursala BucureștiING Bank NV Amsterdam Sucursala București received a fine from ANSPDCP for GDPR violations. The case concerned non-compliance with personal data protection requirements. | RO | ANSPDCP | GDPR | €3,000 | ↗ |
| 18 Jul 2023 | Prodav s.r.l.Prodav s.r.l. was fined by the Garante 1,000 EUR for operating a surveillance camera without the required informational signage and safeguards. The case concerned non-compliance with data protection rules and the duty to inform individuals under surveillance. | IT | Garante | GDPR | €1,000 | ↗ |
| 18 Jul 2023 | Compara Facile S.r.l.Compara Facile S.r.l. was fined EUR 40,000 by the Garante for making unsolicited marketing calls to a number listed in the Public Register of Oppositions without prior informed consent. The authority also found that the company failed to respond to data subject rights requests, indicating non-compliance with data protection obligations. | IT | Garante | GDPR | €40,000 | ↗ |
| 18 Jul 2023 | Tiscali Italia S.p.A.Tiscali Italia S.p.A. was fined EUR 100,000 by the Garante for sending promotional SMS messages to existing customers without their consent. The authority also found inadequate data retention policies and insufficient transparency in the privacy notices. | IT | Garante | GDPR | €100,000 | ↗ |