BULLETIN №082Last updated · 31 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.4%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 07 Jul 2023 | THE COMAKING SPACE, S.L.U.THE COMAKING SPACE, S.L.U. was fined by the AEPD EUR 2,000 for sending unsolicited commercial emails without recipient consent. The conduct breached the LSSI rules on electronic marketing communications. | ES | AEPD | ePrivacy | €2,000 | ↗ |
| 07 Jul 2023 | Személyes adatok forrása és adatgyűjtés távhőszolgáltatás nyújtásáhozThe supervisory authority found a GDPR breach because the controller did not inform data subjects about the source of their personal data. It also failed to demonstrate accountability and compliance with data protection principles. | HU | NAIH | GDPR | €2,580 | ↗ |
| 06 Jul 2023 | AcegasApsAmga S.p.A.AcegasApsAmga S.p.A. was fined €10,000 by the Italian supervisory authority, Garante. The sanction concerned the company’s failure to respond to a data subject’s request for access to personal data, in breach of GDPR Article 15. | IT | Garante | GDPR | €10,000 | ↗ |
| 06 Jul 2023 | Romagna Dolciumi s.r.l.Romagna Dolciumi s.r.l. was fined by the Garante in the amount of €10,000 for failing to provide an employee with access to their personal data. The authority also found that the company engaged a private investigative agency to carry out defensive investigations without proper authorization, in breach of GDPR requirements. | IT | Garante | GDPR | €10,000 | ↗ |
| 06 Jul 2023 | Comune di AvianoThe Garante fined Comune di Aviano EUR 3,000 for publishing employees’ personal data, including names and productivity bonuses, on its institutional website. The authority found a breach of data minimization and transparency principles. | IT | Garante | GDPR | €3,000 | ↗ |
| 06 Jul 2023 | SUROVI (Surovi Ristorante indiano e kebab di Chowdhury Monika)The Garante fined SUROVI restaurant EUR 1,000 for operating a video surveillance system without the required privacy notice. The authority found this to be a breach of Article 13 of the GDPR. | IT | Garante | GDPR | €1,000 | ↗ |
| 06 Jul 2023 | Ristorante Francesco s.r.l.Ristorante Francesco s.r.l. was fined by the Garante in the amount of 5,000 EUR for operating surveillance cameras without the required notices to affected individuals. The authority treated this as a breach of privacy rules. | IT | Garante | GDPR | €5,000 | ↗ |
| 06 Jul 2023 | Provvedimento del 6 luglio 2023 [9925450The Garante imposed a EUR 2,000 fine on an individual for posting images of other people on social media without their consent. The authority found a breach of GDPR rights, including the rights to erasure and objection. | IT | Garante | GDPR | €2,000 | ↗ |
| 06 Jul 2023 | Regione SicilianaThe Garante fined Regione Siciliana EUR 7,000 for publishing personal data of numerous individuals, including sensitive employment-related information. The authority found breaches of lawfulness, fairness, transparency, and data minimization principles. | IT | Garante | GDPR | €7,000 | ↗ |
| 06 Jul 2023 | Ad Maiora Distribuzioni S.a.s. di Editrice Ad Maiora S.r.l.s. & C.Ad Maiora Distribuzioni was fined EUR 15,000 by the Garante. The authority found that the company made unsolicited promotional calls and failed to respond to requests for access to and deletion of personal data. | IT | Garante | GDPR | €15,000 | ↗ |
| 05 Jul 2023 | Anonymisé (CNPD decision-06-fr-2023)The company failed to implement appropriate technical and organizational measures to ensure data security. It also did not cooperate with the supervisory authority, breaching Articles 31 and 32 of the GDPR. | LU | CNPD | GDPR | €5,330 | ↗ |
| 05 Jul 2023 | 4T OCIO Y CAFÉ 2009, S.L.The company was fined EUR 500 by the AEPD for installing surveillance cameras without the express consent of the property owners. The authority found this to be a breach of Article 6 of the GDPR. | ES | AEPD | GDPR | €500 | ↗ |
| 05 Jul 2023 | Anonymisé (CNPD decision-05-fr-2023)The company did not inform data subjects about the recipients of their personal data. It also failed to implement appropriate technical and organizational measures required under the GDPR, breaching Articles 13 and 24. | LU | CNPD | GDPR | €1,500 | ↗ |
| 05 Jul 2023 | UPMOBILE SOLUTIONS, S.L.UPMOBILE SOLUTIONS, S.L. was fined EUR 500 by the AEPD for failing to provide access during the investigation. The authority treated this as a breach of Article 58(1) GDPR and an obstruction of its supervisory function. | ES | AEPD | GDPR | €500 | ↗ |
| 05 Jul 2023 | BILBAO AD INFINITUM, S.L.BILBAO AD INFINITUM, S.L. was fined by the AEPD EUR 500 for installing surveillance cameras directed at a public square without prior administrative authorization. The authority found that this conduct breached GDPR requirements on lawful processing. | ES | AEPD | GDPR | €500 | ↗ |
| 04 Jul 2023 | BALLESPE, S.LBALLESPE, S.L was fined by the AEPD in the amount of 500 EUR for installing surveillance cameras that captured public areas without proper signage. The case concerns a breach of data protection rules and the duty to inform individuals being recorded. | ES | AEPD | GDPR | €500 | ↗ |
| 03 Jul 2023 | ENDESAENDESA was fined by the AEPD EUR 2,500,000 for failing to ensure the integrity and confidentiality of personal data and for inadequate security measures. The authority found breaches of GDPR Articles 5(1)(f) and 32. | ES | AEPD | GDPR | €2,500,000 | ↗ |
| 03 Jul 2023 | LA VANGUARDIA EDICIONES, S.L.LA VANGUARDIA EDICIONES, S.L. was fined by the AEPD 5,000 EUR for attempting to install cookies on users' devices without proper consent. The conduct breached data protection rules and electronic commerce requirements. | ES | AEPD | ePrivacy | €5,000 | ↗ |
| 29 Jun 2023 | FORKMERGE S.L.FORKMERGE S.L. was fined by the AEPD EUR 2,000 for failing to comply with a data subject’s request to remove personal data from search engine results. The authority found this to be a breach of Article 17 GDPR. | ES | AEPD | GDPR | €2,000 | ↗ |
| 29 Jun 2023 | Anonymisiert (DSB 2023-0.420.407)The responsible party unlawfully processed special categories of personal data by publishing health data in response to an online review. This breached GDPR principles of lawfulness, purpose limitation, and data minimization. | AT | DSB | GDPR | €10,000 | ↗ |