BULLETIN №082Last updated · 02 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 01 Jan 2015 | OCIO MANAGEMENT S.L.OCIO MANAGEMENT S.L. was fined EUR 600 by the AEPD for sending unsolicited advertising messages via WhatsApp without consent. The authority also found that the company failed to provide the required data processing information on its website. | ES | AEPD | ePrivacy | €600 | ↗ |
| 23 May 2025 | OCI CINE, S.L.OCI CINE, S.L. was fined EUR 30,000 by the AEPD after an incident in which a user's personal information was auto-filled with another person's details in its app. The authority found a breach of data accuracy and processing security principles. | ES | AEPD | GDPR | €30,000 | ↗ |
| 20 Oct 2022 | Occhiali24.it S.r.l.Occhiali24.it S.r.l. was fined by the Garante 20,000 EUR for sending unsolicited marketing communications without prior consent. The authority also found that the company failed to respond to data subject rights requests, indicating non-compliance with data protection obligations. | IT | Garante | GDPR | €20,000 | ↗ |
| 05 Feb 2026 | Óbudai EgyetemÓbudai Egyetem was fined by the NAIH 1,500,000 HUF for breaching the principles of transparency and data minimization. The authority also found no lawful basis for processing and that the conditions for processing special categories of data were not met. | HU | NAIH | GDPR | €3,945 | ↗ |
| 16 Mar 2017 | Obiettivo Ferrari s.r.l.Obiettivo Ferrari s.r.l. was fined by the Garante €16,000 for making an unsolicited promotional call. The company did not provide the required data protection information or obtain consent from the recipient. | IT | Garante | GDPR | €16,000 | ↗ |
| 04 Jul 2013 | OASI AZZURRA di Intravaia Lorenzo & C. S.a.s.OASI AZZURRA di Intravaia Lorenzo & C. S.a.s. was fined EUR 2,400 by the Italian data protection authority, Garante. The case concerned inadequate privacy notices for the website contact form and the video surveillance system. | IT | Garante | GDPR | €2,400 | ↗ |
| 25 Sept 2023 | OASAThe Athens Urban Transport Organization (OASA) was fined for failing to timely conduct a Data Protection Impact Assessment (DPIA) for its Automatic Fare Collection System. The authority found this to be a breach of data protection principles in connection with the system's processing activities. | GR | HDPA | GDPR | €20,000 | ↗ |
| 08 Aug 2024 | OAC LOGÍSTICA, S.L.OAC LOGÍSTICA, S.L. was fined by the AEPD in the amount of EUR 600 for failing to provide access. The breach concerned Article 58(1) of the GDPR. | ES | AEPD | GDPR | €600 | ↗ |
| 03 Dec 2019 | Nusvar ABNusvar AB was fined SEK 35,000 by IMY. The authority found unauthorized processing of personal data relating to criminal offenses and a failure to comply with data minimization principles in credit reporting activities. | SE | IMY | GDPR | €3,313 | ↗ |
| 10 Dec 2015 | Nuovo Pic Nic s.r.l.Nuovo Pic Nic s.r.l. was fined 2,400 EUR by the Garante for failing to provide adequate simplified information about its video surveillance system. The authority treated this as a breach of data protection rules. | IT | Garante | GDPR | €2,400 | ↗ |
| 23 Mar 2011 | Nuova Demolizione Sas di Saviotti GaetanoNuova Demolizione Sas was fined by the Garante 6,000 EUR for sending unsolicited promotional faxes without proper consent. The conduct breached data protection and direct marketing rules. | IT | Garante | GDPR | €6,000 | ↗ |
| 29 Apr 2026 | Nuova Corrente S.r.l.Nuova Corrente S.r.l. was fined EUR 15,000 by the Garante for making promotional calls without a valid legal basis. The authority found this to be a breach of GDPR lawfulness principles. | IT | Garante | GDPR | €15,000 | ↗ |
| 17 Nov 2022 | NUEVAS TECNOLOGIAS MEDITERRANEO, S.L.NUEVAS TECNOLOGIAS MEDITERRANEO, S.L. was fined by the AEPD EUR 800 for sending unsolicited advertising emails without prior consent. The case concerned a breach of Article 21 of the LSSI and unlawful direct marketing. | ES | AEPD | ePrivacy | €800 | ↗ |
| 30 Jul 2024 | NUDE PROJECT, S.L.NUDE PROJECT, S.L. was fined EUR 20,000 by the AEPD for sending unsolicited advertising emails to a customer without obtaining explicit consent. The authority found this conduct breached Article 21 of the LSSI. | ES | AEPD | ePrivacy | €20,000 | ↗ |
| 25 Mar 2025 | NTT DATA ROMÂNIA S.A.NTT DATA ROMÂNIA S.A. was fined by ANSPDCP in the amount of EUR 25,000 for GDPR violations. The case concerned non-compliance with personal data protection requirements. | RO | ANSPDCP | GDPR | €25,000 | ↗ |
| 11 Mar 2025 | Noy Business Tranzactions SRLANSPDCP completed an investigation in February 2025 at Noy Business Tranzactions SRL and found a breach of Article 17 of the GDPR. As a result, the controller was fined EUR 1,000. | RO | ANSPDCP | GDPR | €1,000 | ↗ |
| 01 Jan 2013 | NOVOPRINT, C.B.NOVOPRINT, C.B. was fined by the AEPD 1,800 EUR for sending unsolicited commercial emails. The emails did not include an unsubscribe mechanism, which breached Article 21 of the LSSI. | ES | AEPD | ePrivacy | €1,800 | ↗ |
| 05 Sept 2012 | NOVOPRINT C.B.NOVOPRINT C.B. was fined by the AEPD in the amount of 38,000 EUR for sending commercial emails to LLACRUTECH, S.L. despite requests to remove the address from mailing lists. The authority found this to be a breach of the LSSI rules on electronic communications. | ES | AEPD | ePrivacy | €38,000 | ↗ |
| 23 Apr 2015 | Novelli DonataNovelli Donata was fined EUR 20,000 by the Garante. The case concerned the activation of eight phone cards in the names of four individuals without their knowledge, which breached data protection rules. | IT | Garante | GDPR | €20,000 | ↗ |
| 27 Mar 2025 | NOVATES ALIMENTACIÓN MADRID, S.L.NOVATES ALIMENTACIÓN MADRID, S.L. was fined by the AEPD for a personal data protection breach involving the improper handling of video surveillance footage. The footage was shared via WhatsApp without adequate security measures, increasing the risk of unauthorized access. | ES | AEPD | GDPR | €20,000 | ↗ |