BULLETIN №082Last updated · 31 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.4%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 01 Mar 2023 | VODAFONE ESPAÑA, S.A.U.Vodafone España was fined by the AEPD in the amount of 20,000 EUR for sending unsolicited commercial communications by text messages and phone calls. The conduct continued despite the recipient’s request to stop contacting them and not to share their phone number for commercial purposes. | ES | AEPD | GDPR | €20,000 | ↗ |
| 28 May 2015 | People & Comunication s.r.l.People & Comunication s.r.l. was fined EUR 20,000 by the Garante. The authority found that the company retained telephone traffic data for more than 24 months, in breach of Article 132 of the Italian Data Protection Code. | IT | Garante | GDPR | €20,000 | ↗ |
| 12 Dec 2024 | SOCIETE EXPLOITANT DES PORTAILS INTERNET (procédure simplifiée)The CNIL imposed an administrative fine of EUR 20,000 on SOCIETE EXPLOITANT DES PORTAILS INTERNET and issued an injunction. The case was handled under a simplified procedure. | FR | CNIL | GDPR | €20,000 | ↗ |
| 09 Mar 2021 | NBQ TECHNOLOGY, S.A.U.NBQ TECHNOLOGY, S.A.U. was fined by the AEPD €20,000 for processing personal data without a legal basis. The case was related to identity theft in a microcredit contract. | ES | AEPD | GDPR | €20,000 | ↗ |
| 01 May 2025 | ALBOR ENERGÍA S.L.ALBOR ENERGÍA S.L. was fined by the AEPD in the amount of 20,000 EUR for a data protection breach. The case concerned unauthorized subcontracting without informing the responsible party, as required by Article 28 of the GDPR. | ES | AEPD | GDPR | €20,000 | ↗ |
| 30 Apr 2025 | SOCIETE EDITANT UN SITE WEB DE RENCONTRES DESTINE AUX PERSONNES PARTAGEANT DES CONVICTIONS POLITIQUES SIMILAIRES (procédure simplifiée)CNIL imposed an administrative fine of 20,000 EUR on the company operating a dating website for people sharing similar political convictions. The case was handled under a simplified procedure. | FR | CNIL | GDPR | €20,000 | ↗ |
| 25 Jul 2024 | ETABLISSEMENT D'ENSEIGNEMENT SUPERIEUR PRIVE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 20,000 on ETABLISSEMENT D'ENSEIGNEMENT SUPERIEUR PRIVE under a simplified procedure. The case concerned a confirmed breach of rules supervised by the CNIL. | FR | CNIL | GDPR | €20,000 | ↗ |
| 09 Sept 2022 | JOLY DIGITAL, S.L.U.JOLY DIGITAL, S.L.U. was fined by the AEPD EUR 20,000 for publishing the complainant’s private Instagram photo without consent. The authority found a breach of Article 6 GDPR because there was no lawful basis for processing the personal data. | ES | AEPD | GDPR | €20,000 | ↗ |
| 11 Feb 2021 | ZCALL LEVANTE, S.L.ZCALL LEVANTE, S.L. was fined by the AEPD 20,000 EUR for making a commercial call to a number registered on the Robinson List. This conduct breached telecommunications and consumer protection rules. | ES | AEPD | GDPR | €20,000 | ↗ |
| 09 Mar 2020 | Dane anonimowe (V. Sp. z o.o. w likwidacji z siedzibą w Z. przy ul.)The President of UODO imposed a PLN 20,000 fine on V. Sp. z o.o. in liquidation for failing to provide access to personal data, other information, and premises. This prevented the authority from carrying out inspection activities necessary for its duties. | PL | UODO | GDPR | €4,637 | ↗ |
| 28 Sept 2023 | COMMERCE INTERENTREPRISES DE PRODUITS SURGELES (procédure simplifiée)The CNIL imposed an administrative fine of EUR 20,000 on COMMERCE INTERENTREPRISES DE PRODUITS SURGELES under a simplified procedure. The case concerns a confirmed breach of rules supervised by the CNIL. | FR | CNIL | GDPR | €20,000 | ↗ |
| 20 Feb 2024 | SPORT & SPA GEST, S.L.SPORT & SPA GEST, S.L. was fined by the AEPD 20,000 EUR for breaches of GDPR Articles 6(1), 13, 9, and 35. The case concerned improper data processing and insufficient information provided to users. | ES | AEPD | GDPR | €20,000 | ↗ |
| 04 Oct 2012 | Ministero dell'Istruzione, dell'Università e della Ricerca - Direzione generale per l'università, lo studente e il diritto allo studio universitarioThe Ministry of Education, University and Research was fined by the Garante for unlawfully disclosing personal data on its website. The authority found no legal basis for the processing. | IT | Garante | GDPR | €20,000 | ↗ |
| 16 Jun 2022 | Deutsche Bank S.p.A.Deutsche Bank S.p.A. was fined EUR 20,000 by the Garante for unlawfully processing personal data. The bank reported an individual's name to CRIF S.p.A. without prior notice, which breached data protection rules. | IT | Garante | GDPR | €20,000 | ↗ |
| 01 Jan 2021 | DAVISER SERVICIOS, S.L.DAVISER SERVICIOS, S.L. was fined by the AEPD 20,000 EUR for using biometric data from fingerprint readers and surveillance cameras without properly informing employees. The authority found this to be a breach of data protection principles. | ES | AEPD | GDPR | €20,000 | ↗ |
| 18 Nov 2024 | Altex România S.A.ANSPDCP completed an investigation in October 2024 at Altex România S.A. and found violations of GDPR provisions. As a result, the company was fined EUR 20,000. | RO | ANSPDCP | GDPR | €20,000 | ↗ |
| 11 May 2017 | Bianalisi s.p.a.Bianalisi s.p.a. was fined by the Italian data protection authority, Garante, for failing to update its notification concerning the processing of genetic data. The obligation arose under the Italian Privacy Code and was intended to ensure proper disclosure of sensitive data processing. | IT | Garante | GDPR | €20,000 | ↗ |
| 11 Jul 2025 | NN HellasNN Hellas was fined EUR 20,000 for failing to satisfy the complainant’s access request concerning recorded telephone conversations. The authority found a violation of Article 15 GDPR. | GR | HDPA | GDPR | €20,000 | ↗ |
| 09 Oct 2014 | People & Communication s.r.l.People & Communication s.r.l. was fined by the Italian data protection authority, Garante, in the amount of EUR 20,000. The case concerned the sending of pre-recorded promotional phone calls without obtaining the required consent from recipients. | IT | Garante | GDPR | €20,000 | ↗ |
| 15 Dec 2011 | Casa di cura Villa Domelia s.r.l.Casa di cura Villa Domelia s.r.l. was fined by the Garante for failing to notify personal data processing activities. The breach concerned requirements under the Italian Data Protection Code. | IT | Garante | GDPR | €20,000 | ↗ |