BULLETIN №082Last updated · 02 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 29 May 2023 | NOVA TELECOMMUNICATIONS & MEDIA MONOPROSOPI A.E.The company was fined for repeatedly sending unsolicited electronic communications for marketing purposes despite the complainant’s objections. The authority also found failures to comply with requests for access, objection, and restriction of processing. | GR | HDPA | ePrivacy | €50,000 | ↗ |
| 24 Mar 2022 | NOTAIRECNIL imposed EUR 1,000 on NOTAIRE in connection with the liquidation of a penalty payment. The case concerns compliance with a prior obligation and the settlement of the penalty for non-compliance. | FR | CNIL | GDPR | €1,000 | ↗ |
| 11 May 2021 | Norges idrettsforbundThe Norwegian DPA fined Norges idrettsforbund 1,250,000 NOK for insufficient security measures during testing. As a result, personal data of 3.2 million individuals was exposed online for 87 days. | NO | Datatilsynet | GDPR | €124,000 | ↗ |
| 02 Mar 2026 | Nordic Cleaning ApSThe Danish DPA reported Klein2 ApS and Nordic Cleaning ApS to the police for failing to comply with orders to address access requests. Nordic Cleaning ApS accepted a fine notice of 60,000 DKK. | DK | Datatilsynet | GDPR | €8,031 | ↗ |
| 16 Dec 2022 | NORDETIA CLINICS IBERIA, S.L.NORDETIA CLINICS IBERIA, S.L. was fined 3,000 EUR by the AEPD. The authority found that the company obstructed an inspection by failing to provide access required under Article 58(1) GDPR. | ES | AEPD | GDPR | €3,000 | ↗ |
| 07 Jul 2021 | Nordbornholms Byggeforretning ApSNordbornholms Byggeforretning ApS was fined 100,000 DKK by Datatilsynet. The company unlawfully disclosed information about a former employee's criminal activities to customers without a legal basis. | DK | Datatilsynet | GDPR | €13,448 | ↗ |
| 13 Sept 2017 | NO QUIERO PERDER EL TIEMPO, S.L.The company was fined by the AEPD for displaying the AEPD quality seal and another association’s seal on its website without authorization. The authority also found inadequate information and no valid consent for data collection. | ES | AEPD | ePrivacy | €8,000 | ↗ |
| 04 Jul 2024 | Nomodidattica S.r.l.Nomodidattica S.r.l. was fined EUR 10,000 by the Garante for publishing a court ruling online without anonymizing minors' data. The authority found this breached GDPR data protection principles. | IT | Garante | GDPR | €10,000 | ↗ |
| 12 May 2023 | Noi sancțiuniA company in the insurance sector was fined by ANSPDCP in the amount of 1,500 EUR for violating GDPR Article 5. The case concerned non-compliance with the basic principles for processing personal data. | RO | ANSPDCP | GDPR | €1,500 | ↗ |
| 12 May 2023 | Noi sancțiuniAn insurance-sector company was fined EUR 1,000 by ANSPDCP for breaching GDPR Article 5. The case concerned non-compliance with the core principles governing personal data processing under data protection law. | RO | ANSPDCP | GDPR | €1,000 | ↗ |
| 04 Jun 2025 | Noi Compriamo Auto.it S.r.l.On 4 June 2025, the Italian Data Protection Authority fined Noi Compriamo Auto.it S.r.l. for GDPR breaches in email marketing. The authority found that the company sent promotional emails without consent, failed to properly govern its processors, and did not adequately support data subject rights. | IT | Garante per la protezione dei dati personali | GDPR | €27,800,000 | ↗ |
| 04 Jun 2025 | Noi Compriamo Auto.it S.r.l.The Italian Supervisory Authority fined Noi Compriamo Auto.it S.r.l. 45,000 EUR for sending unsolicited promotional emails without proper consent documentation. The case indicates a breach of GDPR requirements for lawful direct marketing. | IT | Garante | GDPR | €45,000 | ↗ |
| 21 May 2025 | NN ΕλληνικήThe Greek Data Protection Authority imposed a €22,000 fine on NN Ελληνική for refusing to provide recorded telephone calls in response to a data subject access request. The case concerns failure to comply with access rights obligations under data protection law. | GR | Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα | GDPR | €22,000 | ↗ |
| 11 Jul 2025 | NN HellasNN Hellas was fined EUR 20,000 for failing to satisfy the complainant’s access request concerning recorded telephone conversations. The authority found a violation of Article 15 GDPR. | GR | HDPA | GDPR | €20,000 | ↗ |
| 11 Jan 2018 | N.J.L. & Time di Bernasconi NadiaN.J.L. & Time di Bernasconi Nadia was fined 68,000 EUR by the Garante. The authority found that promotional emails were sent without proper consent, in breach of data protection rules. | IT | Garante | GDPR | €68,000 | ↗ |
| 01 Jan 2017 | NIUNO ESTÉTICA, S.L.NIUNO ESTÉTICA, S.L. was fined by the AEPD 1,000 EUR for sending unsolicited commercial SMS messages. The conduct breached the requirements of Spain’s LSSI governing marketing communications. | ES | AEPD | ePrivacy | €1,000 | ↗ |
| 07 Dec 2023 | Nirvam S.r.l.Nirvam S.r.l., an online dating platform, was fined 200,000 EUR by the Garante. The authority found inadequate personal data protection measures and GDPR breaches related to data processing and security. | IT | Garante | GDPR | €200,000 | ↗ |
| 14 Sept 2023 | Nimbus s.r.l.Nimbus s.r.l. was fined by the Garante 5,000 EUR for using a fingerprint-based attendance system. The authority found that employees were not properly informed and that the required consent was not obtained. | IT | Garante | GDPR | €5,000 | ↗ |
| 01 Jan 2012 | NIGHTBONUS, S.L.NIGHTBONUS, S.L. was fined by the AEPD EUR 1,200 for sending marketing emails without prior recipient consent. The authority found a breach of Article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €1,200 | ↗ |
| 04 Jul 2025 | Niepubliczny Zakład Opieki ZdrowotnejUODO imposed a PLN 32,832 administrative fine on Niepubliczny Zakład Opieki Zdrowotnej for failing to conduct a risk analysis for processing patient data during home visits. The authority also found that appropriate technical and organizational measures to secure the data had not been implemented. | PL | UODO | GDPR | €7,733 | ↗ |