BULLETIN №082Last updated · 31 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.4%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 02 Nov 2022 | QUALITY-PROVIDER S.A.QUALITY-PROVIDER S.A. was fined EUR 20,000 by the AEPD for processing personal data without a valid legal basis and for failing to comply with data deletion requests. The violations concerned Articles 6 and 17 of the GDPR. | ES | AEPD | GDPR | €20,000 | ↗ |
| 16 Nov 2017 | S.T.E.A.T. S.p.a.S.T.E.A.T. S.p.a. was fined by the Garante for failing to properly notify the installation of electronic monitoring and localization devices on public transport buses. The authority found a breach of data protection notification obligations. | IT | Garante | GDPR | €20,000 | ↗ |
| 29 Mar 2018 | Fin Solution Italia S.p.a.Fin Solution Italia S.p.a. was fined EUR 20,000 by the Garante for inadequate security measures in the processing of personal data. The authority found that weak passwords were used on company PCs, increasing the risk of unauthorized access. | IT | Garante | GDPR | €20,000 | ↗ |
| 02 Jun 2016 | TELEFONICA MOVILES ESPAÑA, S.A.U.Telefónica Móviles España was fined €20,000 by the AEPD for using “supercookies” without properly informing users or obtaining their consent. The authority found this conduct to be in breach of Article 22.2 of the LSSI. | ES | AEPD | ePrivacy | €20,000 | ↗ |
| 17 Oct 2024 | SOCIETE AYANT POUR ACTIVITE LA FOURNITURE DE PRESTATIONS DE SERVICE (GESTION APPELS TELEPHONIQUES) (procédure simplifiée)The CNIL imposed an administrative fine of EUR 20,000 on SOCIETE AYANT POUR ACTIVITE LA FOURNITURE DE PRESTATIONS DE SERVICE (GESTION APPELS TELEPHONIQUES). The case was handled under a simplified procedure. | FR | CNIL | GDPR | €20,000 | ↗ |
| 26 Oct 2017 | M&M Centro analisi s.r.l.M&M Centro analisi s.r.l. was fined by the Garante 20,000 EUR for failing to notify the processing of sensitive health data. The obligation arose under the Italian Data Protection Code. | IT | Garante | GDPR | €20,000 | ↗ |
| 29 Apr 2025 | Cooperativa Sociale QuadrifoglioThe Garante imposed a fine of EUR 20,000 on Cooperativa Sociale Quadrifoglio for violations related to data processing. The case concerned non-compliance with personal data protection requirements. | IT | Garante | GDPR | €20,000 | ↗ |
| 18 Feb 2020 | ZSZZS.440.768.2018StatusuchylonaTytuUODO found a breach related to the processing of children’s biometric data in connection with use of the school canteen. A fine of PLN 20,000 was imposed. | PL | UODO | GDPR | €4,679 | ↗ |
| 28 Sept 2023 | SOCIETE DE FABRICATION DE PRODUITS DE CONSOMMATION COURANTE EN MATIERES PLASTIQUES (procédure simplifiée)The CNIL imposed a fine of EUR 20,000 on SOCIETE DE FABRICATION DE PRODUITS DE CONSOMMATION COURANTE EN MATIERES PLASTIQUES under a simplified procedure. The decision concerns a breach of the rules covered by the administrative proceeding. | FR | CNIL | GDPR | €20,000 | ↗ |
| 27 Mar 2023 | QUALITY-PROVIDER S.A.QUALITY-PROVIDER S.A. was fined EUR 20,000 by the Spanish data protection authority, AEPD. The company failed to provide requested information, obstructing the authority’s investigative powers under Article 58(1) GDPR. | ES | AEPD | GDPR | €20,000 | ↗ |
| 13 May 2021 | Synlab Med srlSynlab Med srl was fined EUR 20,000 by the Garante. The authority found that personal data were improperly transmitted to an entity not competent to process them, breaching the principles of data minimization and integrity. | IT | Garante | GDPR | €20,000 | ↗ |
| 24 Jan 2024 | ACTIVITE DE COMMERCE DE GROS PHARMACEUTIQUES (procédure simplifiée)The CNIL imposed an administrative fine of EUR 20,000 on ACTIVITE DE COMMERCE DE GROS PHARMACEUTIQUES. The case was handled under a simplified procedure. | FR | CNIL | GDPR | €20,000 | ↗ |
| 08 Oct 2024 | SEAT, S.A.SEAT, S.A. was fined by the AEPD €20,000 for using cookies on its website without obtaining user consent. The authority found this conduct to be in breach of the LSSI. | ES | AEPD | ePrivacy | €20,000 | ↗ |
| 11 Dec 2025 | SOCIETE AYANT POUR ACTIVITE L'ACCOMPAGNEMENT, L'ORIENTATION ET L'EDUCATION DE VICTIMES D'INCESTES (procédure simplifiée)The CNIL imposed an administrative fine of EUR 20,000 on SOCIETE AYANT POUR ACTIVITE L'ACCOMPAGNEMENT, L'ORIENTATION ET L'EDUCATION DE VICTIMES D'INCESTES and issued an injunction. The case was handled under a simplified procedure. | FR | CNIL | GDPR | €20,000 | ↗ |
| 25 Jan 2024 | ASSOCIATION A CARACTERE POLITIQUE (procédure simplifiée)The CNIL imposed an administrative fine of EUR 20,000 on ASSOCIATION A CARACTERE POLITIQUE. The case was handled under a simplified procedure. | FR | CNIL | GDPR | €20,000 | ↗ |
| 21 Apr 2021 | Isinc S.r.l.s.Isinc S.r.l.s. was fined 20,000 EUR by the Garante for sending promotional emails using personal data taken from public databases without proper consent. The authority found this conduct to be in breach of GDPR Article 5. | IT | Garante | GDPR | €20,000 | ↗ |
| 21 Apr 2011 | Azienda USL della Valle D'AostaAzienda USL della Valle D'Aosta was fined for processing personal data during phone bookings without providing the required information notice and for failing to update the security program document. The authority found these actions breached data protection rules. | IT | Garante | GDPR | €20,000 | ↗ |
| 23 Jan 2024 | CAJA RURAL DE NAVARRA, S.C.C.CAJA RURAL DE NAVARRA was fined EUR 20,000 by the AEPD for a personal data breach. The incident compromised the confidentiality and integrity of personal data, breaching Article 5(1)(f) of the GDPR. | ES | AEPD | GDPR | €20,000 | ↗ |
| 09 May 2018 | Amiu S.p.a.Amiu S.p.a. was fined by the Garante 20,000 EUR for improper processing of personal data through its video surveillance systems. The authority found that the company failed to properly designate data processing personnel and to implement adequate data protection measures. | IT | Garante | GDPR | €20,000 | ↗ |
| 31 Jan 2024 | EDITEUR DE SITE WEB - ACTUALITES DANS LE DOMAINE DES NOUVELLES TECHNOLOGIES (procédure simplifiée)The CNIL imposed an administrative fine of EUR 20,000 on EDITEUR DE SITE WEB - ACTUALITES DANS LE DOMAINE DES NOUVELLES TECHNOLOGIES under a simplified procedure. The case concerned a breach of personal data protection rules. | FR | CNIL | GDPR | €20,000 | ↗ |