BULLETIN №082Last updated · 31 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.4%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 12 Jun 2023 | Spotify, rätten till tillgångIMY fined Spotify AB SEK 58 million for failing to provide clear and understandable information about the purposes of processing, categories of personal data, and other required details under Article 15 GDPR. The authority also found that technical log file descriptions were provided in English, which did not meet the requirement for clear communication in the data subject’s language. | SE | IMY | GDPR | €4,992,000 | ↗ |
| 12 Jun 2023 | Piraeus Bank S.A.Piraeus Bank S.A. was fined by the HDPA in the amount of 100,000 EUR for failing to implement appropriate technical and organizational measures. The authority found that the bank did not ensure data protection by design and by default. | GR | HDPA | GDPR | €100,000 | ↗ |
| 12 Jun 2023 | Piraeus Bank S.A.Piraeus Bank S.A. was fined 10,000 EUR by the HDPA. The authority found that the bank did not adequately satisfy the data subject’s right of access. | GR | HDPA | GDPR | €10,000 | ↗ |
| 12 Jun 2023 | Piraeus Bank S.A.Piraeus Bank S.A. was fined by the HDPA EUR 100,000 for processing personal data without a legal basis. The breach affected a large number of data subjects, which increases its compliance significance. | GR | HDPA | GDPR | €100,000 | ↗ |
| 09 Jun 2023 | UNIÓN DE RADIOS LIBRES Y COMUNITARIAS DE MADRIDThe entity did not comply with a data protection authority resolution concerning the right to erasure. As a result, AEPD imposed a fine for breaching Article 58.2 of the GDPR. | ES | AEPD | GDPR | €1,000 | ↗ |
| 08 Jun 2023 | La Rinascente S.p.A.La Rinascente S.p.A. was fined by the Garante for unauthorized access to customer data and its modification. The breach led to the issuance of a new loyalty card containing incorrect personal details. | IT | Garante | GDPR | €300,000 | ↗ |
| 08 Jun 2023 | AziendaThe company was fined for failing to process personal data in a lawful, fair, and transparent manner. The authority also found breaches of data minimization and inadequate security measures. | IT | Garante | GDPR | €5,000 | ↗ |
| 08 Jun 2023 | RCS Mediagroup S.p.a.RCS Mediagroup S.p.a. was fined EUR 40,660 by the Italian Garante. The case concerned the publication of unauthorized photographs of a private individual taken inside her home, which infringed her privacy rights. | IT | Garante | GDPR | €40,660 | ↗ |
| 08 Jun 2023 | Maxen Power Supply LimitedMaxen Power Supply Limited used overseas call centres to make unsolicited marketing calls to businesses. The conduct breached regulations 21 and 24 of PECR, and the ICO imposed a fine of 120,000 GBP and issued an enforcement notice. | GB | ICO | ePrivacy | €139,000 | ↗ |
| 08 Jun 2023 | Mirva s.r.l.Mirva s.r.l. was fined by the Garante 5,000 EUR for installing a video surveillance system without proper informational signage. The system also captured areas not pertaining to the company, which breached data protection rules. | IT | Garante | GDPR | €5,000 | ↗ |
| 08 Jun 2023 | Crown Glazing LtdThe case was part of Operation Tinago, which assessed complaint trends in the energy and home improvements sector. Crown Glazing Ltd made 503,445 unsolicited calls to TPS-registered numbers between 4 January and 11 November 2021, resulting in 37 complaints. | GB | ICO | GDPR | €150,000 | ↗ |
| 08 Jun 2023 | L’Editoriale Nazionale S.r.l.The Garante fined L’Editoriale Nazionale S.r.l. EUR 30,000 for publishing articles that breached privacy rules. The company disclosed personal and sensitive data relating to a deceased minor without showing that the information was essential. | IT | Garante | GDPR | €30,000 | ↗ |
| 08 Jun 2023 | Liguria News S.r.l.Liguria News S.r.l. was fined by Garante EUR 10,000 for publishing an article that breached privacy rules. The article disclosed personal and sensitive information about individuals involved in the reported incident, including a minor. | IT | Garante | GDPR | €10,000 | ↗ |
| 08 Jun 2023 | SOCIÉTÉ DE VOYANCECNIL imposed a fine of EUR 150,000 on SOCIÉTÉ DE VOYANCE. The case concerns a regulatory breach, with no further details provided on the specific nature of the violation. | FR | CNIL | GDPR | €150,000 | ↗ |
| 08 Jun 2023 | Marcozzi Brand s.r.l.Marcozzi Brand s.r.l. was fined €8,400 by the Garante. The case concerned the failure to provide the complainant with the name of the occupational physician and the specific reasons for a negative fitness-for-work assessment, breaching GDPR transparency and access rights. | IT | Garante | GDPR | €8,400 | ↗ |
| 08 Jun 2023 | ALTERNATIVA CORELLANA INDEPENDIENTE (ACI)ALTERNATIVA CORELLANA INDEPENDIENTE (ACI) was fined by the AEPD for failing to respond to information requests. The authority treated this as a breach of Article 58.1 of the GDPR. | ES | AEPD | GDPR | €4,000 | ↗ |
| 07 Jun 2023 | ELECTRAWORKS - CEUTA, S.A.ELECTRAWORKS - CEUTA, S.A. did not comply with a data deletion request and retained personal data for 10 years without proper justification. The AEPD found this to be a breach of Article 13 GDPR and imposed a 10,000 EUR fine. | ES | AEPD | GDPR | €10,000 | ↗ |
| 06 Jun 2023 | S.C.In May 2023, ANSPDCP completed an investigation at operator S.C. and found a violation of GDPR provisions. As a result, a fine of EUR 3,000 was imposed. | RO | ANSPDCP | GDPR | €3,000 | ↗ |
| 05 Jun 2023 | HIPER STORE, S.L.HIPER STORE, S.L. was fined EUR 500 by the AEPD for not properly signposting its video surveillance system. The authority also found that the company failed to provide customers with the required data protection information under Article 13 GDPR. | ES | AEPD | GDPR | €500 | ↗ |
| 05 Jun 2023 | CHINA CENTER LLEIDACHINA CENTER LLEIDA was fined EUR 700 by the AEPD for failing to properly sign its video surveillance system and for not providing customers with required data protection information. The authority found a breach of Article 13 of the GDPR. | ES | AEPD | GDPR | €700 | ↗ |