BULLETIN №082Last updated · 31 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.4%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 26 May 2023 | B.B.B.B.B.B. was fined EUR 300 by the AEPD for installing a video surveillance system that captured public areas and a private path without authorization. The authority found a breach of the data minimization principle under GDPR Article 5(1)(c). | ES | AEPD | GDPR | €300 | ↗ |
| 24 May 2023 | PARTIDO LOCAL DE VILLANUEVA DEL PARDILLOPartido Local de Villanueva del Pardillo was fined EUR 500 by the AEPD for publishing an image on Facebook without the data subject's consent. The authority found a breach of Article 6(1) GDPR. | ES | AEPD | GDPR | €500 | ↗ |
| 23 May 2023 | Global Baby Brands SRLIn May 2023, the Romanian supervisory authority ANSPDCP completed an investigation into Global Baby Brands SRL. It found a GDPR violation and imposed a fine of EUR 1,000. | RO | ANSPDCP | GDPR | €1,000 | ↗ |
| 19 May 2023 | B.B.B.The entity was fined by the AEPD for installing a video surveillance system that captured public areas without authorization. The footage was then used for dissemination via WhatsApp, which breached Article 5(1)(c) GDPR. | ES | AEPD | GDPR | €300 | ↗ |
| 19 May 2023 | MADRID TOURISTIC CAPITAL, S.L.MADRID TOURISTIC CAPITAL, S.L. was fined by the AEPD €1,200 for failing to provide proper signage and information about its video surveillance system. The case concerns a breach of data protection transparency and notice requirements. | ES | AEPD | GDPR | €1,200 | ↗ |
| 18 May 2023 | AUTOMOBILE BAVARIA SRLThe fine was imposed for the unauthorized disclosure of personal data of 290 clients and potential clients, which were publicly accessible on the operator's website. The case concerns a breach of data protection rules through disclosure without an appropriate legal basis or safeguards. | RO | ANSPDCP | GDPR | €18,000 | ↗ |
| 17 May 2023 | Ministero delle infrastrutture e dei trasportiThe Ministry of Infrastructure and Transport was fined by the Garante for improper online disclosure of personal data. The authority found a breach of GDPR transparency obligations. | IT | Garante | GDPR | €24,000 | ↗ |
| 17 May 2023 | Santander Consumer Bank S.p.A.Santander Consumer Bank S.p.A. was fined by the Garante EUR 10,000 for failing to provide timely and adequate access to personal data. The authority also found that prejudicial information related to a loan was not deleted, constituting a breach of GDPR Article 15. | IT | Garante | GDPR | €10,000 | ↗ |
| 17 May 2023 | Fabio Giovanni PettaFabio Giovanni Petta was fined by the Garante 60,000 EUR for the unauthorized publication of personal data, including names, addresses, and phone numbers, on www.trovanumeri.com. The authority also noted continued processing of the data despite a prior prohibition. The case constitutes a GDPR violation. | IT | Garante | GDPR | €60,000 | ↗ |
| 17 May 2023 | M.S.M. Immobiliare s.r.l.M.S.M. Immobiliare s.r.l. was fined €1,000 by the Garante for a video surveillance system that captured areas beyond its property. The authority also found that proper informational signage was missing, in breach of data protection rules. | IT | Garante | GDPR | €1,000 | ↗ |
| 17 May 2023 | Volkswagen Leasing GmbHVolkswagen Leasing GmbH was fined EUR 40,000 by the Garante for failing to adequately respond to a data access request. The authority found a breach of GDPR provisions on data subject rights. | IT | Garante | GDPR | €40,000 | ↗ |
| 17 May 2023 | Azienda ULSS 6 EuganeaThe Garante fined Azienda ULSS 6 Euganea 10,000 EUR for the incorrect handling of health-related documents. The authority found breaches of GDPR Articles 5, 6, and 32. | IT | Garante | GDPR | €10,000 | ↗ |
| 17 May 2023 | Grizzaffi Management S.r.l.Grizzaffi Management S.r.l. was fined by the Garante in the amount of 10,000 EUR for sending unsolicited promotional emails without recipient consent. The conduct breached GDPR rules on electronic marketing and consent for commercial communications. | IT | Garante | GDPR | €10,000 | ↗ |
| 17 May 2023 | Anonymizováno (ÚOOÚ UOOU-03562/22-14)The entity was fined for repeatedly sending commercial communications without prior consent from recipients. The messages were not clearly marked as advertising, did not identify the sender, and did not provide a valid address for opting out. | CZ | UOOU | ePrivacy | €2,539 | ↗ |
| 17 May 2023 | La Gazzetta di Parma S.r.l.La Gazzetta di Parma S.r.l. was fined by the Garante EUR 10,000 for publishing an image of a presumed murderer in breach of privacy rules. The person was shown in a state of physical restraint without proper anonymization. | IT | Garante | GDPR | €10,000 | ↗ |
| 17 May 2023 | Breikot Management LtdBreikot Management Ltd was fined EUR 3,000 by the CyDPC for publishing personal data, including names and photos. The authority found a breach of the data minimization principle under the GDPR. | CY | CyDPC | GDPR | €3,000 | ↗ |
| 16 May 2023 | Dane anonimowe (Burmistrza Miasta Z.)UODO imposed an administrative fine of PLN 30,000 on the Mayor of City Z. and ordered the processing operations to be brought into compliance with the GDPR. The authority required appropriate technical and organizational measures, including regular testing, measuring, and evaluating their effectiveness to ensure processing security. | PL | UODO | GDPR | €6,687 | ↗ |
| 16 May 2023 | UK Direct Business Solutions LimitedUK Direct Business Solutions Limited was fined by the ICO for making 410,369 unsolicited marketing calls to businesses registered with the CTPS or TPS. The calls were made between 1 March 2020 and 31 October 2021 and breached rules on telephone marketing. | GB | ICO | GDPR | €115,000 | ↗ |
| 16 May 2023 | Ice Telecommunications LtdIce Telecommunications Ltd made 72,682 unsolicited marketing calls to businesses registered with the CTPS or TPS between 13 September 2021 and 31 January 2022. The ICO imposed a fine of £80,000 for breaching direct marketing rules. | GB | ICO | GDPR | €92,016 | ↗ |
| 16 May 2023 | Compania Națională Poșta Română S.A.Compania Națională Poșta Română S.A. was fined EUR 5,000 by ANSPDCP for GDPR violations related to the completion of Form 230. The case arose from complaints, and the authority instructed the company to ensure personal data processing complies with processing principles. | RO | ANSPDCP | GDPR | €5,000 | ↗ |