BULLETIN №082Last updated · 31 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.4%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 07 Mar 2023 | SIA "Euronics Latvia"The DVI imposed a fine of EUR 20,000 on SIA "Euronics Latvia". The decision entered into force on 7 March 2023. | LV | DVI | GDPR | €20,000 | ↗ |
| 10 Nov 2011 | Idea Service S.r.l.Idea Service S.r.l. was fined EUR 20,000 by the Garante for failing to provide information about an unwanted switch of telephone service provider. The authority found a breach of Article 164 of the Italian Data Protection Code. | IT | Garante | GDPR | €20,000 | ↗ |
| 18 Sept 2008 | Eutelia S.p.A.Eutelia S.p.A. was fined by the Garante EUR 20,000 for using an automated calling system without obtaining prior consent from the individuals concerned. The case concerned a breach of data protection rules and consent requirements for automated communications. | IT | Garante | GDPR | €20,000 | ↗ |
| 12 May 2022 | Hu XiaoyanThe Garante fined Hu Xiaoyan EUR 20,000 for operating a video surveillance system without proper informational signage and required safeguards. The authority found this to be a breach of data protection rules. | IT | Garante | GDPR | €20,000 | ↗ |
| 01 Jan 2022 | JEG'S LIFE STYLE, S.L.JEG'S LIFE STYLE, S.L. was fined by the AEPD 20,000 EUR for breaching data protection rules. The company disclosed private information about a former employee to third parties by email without consent. | ES | AEPD | GDPR | €20,000 | ↗ |
| 05 May 2011 | Idrablu SpaIdrablu Spa was fined by the Garante in the amount of EUR 20,000 for failing to respond to requests for information about the transfer of personal data to another company. The authority treated this as a breach of data protection rules. | IT | Garante | GDPR | €20,000 | ↗ |
| 22 Feb 2018 | Technical Hunter s.r.l.Technical Hunter s.r.l. was fined by the Garante 20,000 EUR for processing job applicants’ personal data without proper compliance with data protection rules. The data was collected and used through the company website, job portals, and social networks. | IT | Garante | GDPR | €20,000 | ↗ |
| 26 Apr 2018 | Raffaele FrancescoRaffaele Francesco was fined by the Garante for processing the personal data of five patients without the required consent during dental services. The conduct breached the Italian Privacy Code. | IT | Garante | GDPR | €20,000 | ↗ |
| 05 Dec 2024 | SOCIETE OFFRANT DES PRESTATIONS DE SECURITE PRIVE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 20,000 on SOCIETE OFFRANT DES PRESTATIONS DE SECURITE PRIVE and issued an injunction. The case was handled under a simplified procedure. | FR | CNIL | GDPR | €20,000 | ↗ |
| 06 Sept 2012 | One Italia S.p.A.One Italia S.p.A. was fined €20,000 by the Garante for sending promotional MMS messages without obtaining prior consent from recipients. The conduct breached Articles 23 and 130 of the Italian Data Protection Code. | IT | Garante | GDPR | €20,000 | ↗ |
| 31 Dec 2025 | UNIVERSITE (procédure simplifiée)CNIL imposed an administrative fine of EUR 20,000 on UNIVERSITE (procédure simplifiée). The case concerned a confirmed breach of rules supervised by CNIL. | FR | CNIL | GDPR | €20,000 | ↗ |
| 27 Sept 2022 | ALBERO FORTE COMPOSITE, S.L.The company used employees’ facial images for clocking in and out without proper notice about biometric data processing. AEPD found this to be a breach of data protection rules and imposed a 20,000 EUR fine. | ES | AEPD | GDPR | €20,000 | ↗ |
| 15 Apr 2025 | COLPER BUSINESS 2020 S.L.COLPER BUSINESS 2020 S.L. was fined by the AEPD EUR 20,000 for failing to provide access to personal data and the information requested by the data protection authority. The conduct was found to breach Article 58(1) of the GDPR. | ES | AEPD | GDPR | €20,000 | ↗ |
| 02 Dec 2021 | La Duomo S.r.l.s.La Duomo S.r.l.s. was fined EUR 20,000 by the Garante for sending unsolicited promotional SMS messages without valid consent. The authority found that the company’s conduct breached data protection rules. | IT | Garante | GDPR | €20,000 | ↗ |
| 02 Nov 2021 | MYHERITAGE, LTDMYHERITAGE, LTD was fined EUR 20,000 by the AEPD for international data transfers without adequate safeguards and for unclear legal grounds for processing. The authority also found insufficient information provided to data subjects and improper handling of genetic data. | ES | AEPD | ePrivacy | €20,000 | ↗ |
| 27 Jan 2021 | Powerplay S.r.l.Powerplay S.r.l. was fined by the Garante for making unsolicited promotional calls despite the recipient's clear request not to receive further communications. The company failed to place the number on a blacklist, which breached data protection rules. | IT | Garante | GDPR | €20,000 | ↗ |
| 07 Mar 2024 | Centro Riparazioni Piacentino S.p.A.Centro Riparazioni Piacentino S.p.A. was fined by the Garante for continuing to operate individual company accounts months after employment ended and for accessing messages without proper deletion. The authority also found inadequate information and insufficient access rights for former employees. | IT | Garante | GDPR | €20,000 | ↗ |
| 04 Oct 2017 | PRENATAL SAPRENATAL SA was fined by the AEPD EUR 20,000 for sending commercial SMS messages without providing recipients with an opt-out mechanism. The case concerns a breach of electronic communications rules and marketing consent requirements. | ES | AEPD | ePrivacy | €20,000 | ↗ |
| 13 Sept 2024 | DIGITAL PHOTO IMAGE, S.A.DIGITAL PHOTO IMAGE, S.A. was fined EUR 20,000 by the AEPD for breaching the LSSI. The company sent emails without providing recipients with a valid means to exercise their right to stop receiving such communications. | ES | AEPD | ePrivacy | €20,000 | ↗ |
| 11 May 2017 | Laboratorio Villafranca sncLaboratorio Villafranca snc was fined EUR 20,000 by the Italian data protection authority, Garante. The case concerned a failure to properly notify data processing activities under the Italian data protection code. | IT | Garante | GDPR | €20,000 | ↗ |