BULLETIN №082Last updated · 30 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.2%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 08 Feb 2023 | Medijobs Platform SRLMedijobs Platform SRL was fined EUR 5,000 by ANSPDCP after unauthorized access to its IT infrastructure. The incident led to the downloading and deletion of certain personal data. | RO | ANSPDCP | GDPR | €5,000 | ↗ |
| 11 Feb 2021 | Istituto Superiore Statale "Pitagora"Istituto Superiore Statale "Pitagora" was fined by the Garante 5,000 EUR for unlawful processing of personal data. The authority found failures to ensure data minimization and transparency toward data subjects. | IT | Garante | GDPR | €5,000 | ↗ |
| 05 Mar 2024 | ROCA & ASOCIADOS ABOGADOS Y ECONOMISTAS, S.L.P.ROCA & ASOCIADOS ABOGADOS Y ECONOMISTAS, S.L.P. was fined 5,000 EUR by the AEPD. The authority found that the company published employees’ personal data on its website without consent, breaching Article 6(1) of the GDPR. | ES | AEPD | GDPR | €5,000 | ↗ |
| 03 Mar 2022 | AUTOMOVILES FERSAN, S.A.AUTOMOVILES FERSAN, S.A. used personal data without consent to include it in a vehicle purchase contract. The AEPD imposed a fine of EUR 5,000 for breaching data protection rules. | ES | AEPD | GDPR | €5,000 | ↗ |
| 14 Jun 2024 | GESCONSULT, S.A. S.G.I.I.C.GESCONSULT, S.A. S.G.I.I.C. was fined by the AEPD 5,000 EUR for processing personal data without a legal basis. The case involved recording a meeting and sharing the recording without proper consent. | ES | AEPD | GDPR | €5,000 | ↗ |
| 29 Dec 2025 | SOCIETE EXERCANT UNE ACTIVITE D'EDITION DE JOURNAUX (procédure simplifiée)The CNIL imposed an administrative fine of 5,000 EUR on SOCIETE EXERCANT UNE ACTIVITE D'EDITION DE JOURNAUX. The case was handled under a simplified procedure. | FR | CNIL | GDPR | €5,000 | ↗ |
| 23 Jul 2025 | Agricola International SAAgricola International SA was fined EUR 5,000 by ANSPDCP for a data security breach. The incident was reported by the company itself, indicating an internally detected event that required compliance review. | RO | ANSPDCP | GDPR | €5,000 | ↗ |
| 21 Jul 2022 | Comune di GinosaComune di Ginosa was fined EUR 5,000 by the Garante for violations related to the processing of personal data in the whistleblowing context. The authority found that an adequately high level of confidentiality and protection for the data subjects was not ensured. | IT | Garante | GDPR | €5,000 | ↗ |
| 16 Mar 2017 | ABELHAS.PT LIMITEDABELHAS.PT LIMITED was fined EUR 5,000 by the AEPD for failing to provide the required information and procedures to reject data processing on its website. The authority found a breach of Article 22.2 of the LSSI. | ES | AEPD | ePrivacy | €5,000 | ↗ |
| 14 Apr 2023 | ESTUDIO VILLALBA ANTIQUE, S.L.ESTUDIO VILLALBA ANTIQUE, S.L. was fined by the AEPD for processing personal data without consent. The authority found a breach of the lawfulness principle under Article 6(1) GDPR. | ES | AEPD | GDPR | €5,000 | ↗ |
| 26 Mar 2026 | Esselunga S.p.A.Esselunga S.p.A. was fined EUR 5,000 by the Italian supervisory authority, Garante. The case concerned a failure to respond to a data access request under Article 15 GDPR, including access to employee attendance records. | IT | Garante | GDPR | €5,000 | ↗ |
| 12 Jun 2026 | Compania Națională Poșta RomânăCompania Națională Poșta Română was fined by ANSPDCP in the amount of EUR 5,000 for GDPR violations. The case concerned non-compliance with personal data protection requirements. | RO | ANSPDCP | GDPR | €5,000 | ↗ |
| 22 Apr 2022 | CÍTRICOS TANTA, S.L.CÍTRICOS TANTA, S.L. was fined by the AEPD for processing personal data without consent. The case involved registering an individual in the Social Security system without their knowledge or agreement. | ES | AEPD | GDPR | €5,000 | ↗ |
| 11 Jan 2024 | Comune di SiracusaThe Garante fined Comune di Siracusa €5,000 for breaches of data protection obligations under Article 37 GDPR. The case concerned failures related to the appointment and management of the data protection officer requirement. | IT | Garante | GDPR | €5,000 | ↗ |
| 09 Jul 2020 | YThe Litigation Chamber imposed a fine of 5,000 EUR for unlawful processing of personal data through surveillance cameras in a residential building. The responsible party failed to establish a legal basis for the processing and did not share access with co-owners. | BE | APD | GDPR | €5,000 | ↗ |
| 08 Feb 2023 | COMMUNE (procédure simplifiée)CNIL imposed a EUR 5,000 fine on COMMUNE under a simplified procedure and issued an injunction. The case concerned a confirmed breach requiring corrective action. | FR | CNIL | GDPR | €5,000 | ↗ |
| 07 Sept 2021 | B.B.B.The entity was fined by the AEPD 5,000 EUR for publicly disseminating surveillance footage without justification. The authority found that this conduct breached data protection principles. | ES | AEPD | GDPR | €5,000 | ↗ |
| 01 Jan 2020 | Caja Rural San José de Nules S. Cooperativa de Crédito de la Comunidad ValencianaCaja Rural San José de Nules was fined by the AEPD 5,000 EUR for publicly displaying individuals’ personal data on a notice board. The conduct breached data protection principles by exposing their economic status. | ES | AEPD | GDPR | €5,000 | ↗ |
| 06 Mar 2023 | B.B.B.The entity was fined by the AEPD €5,000 for publishing radio amateurs’ personal data on a Telegram channel. The breach involved linking call signs to personal information, which violated data protection rules. | ES | AEPD | GDPR | €5,000 | ↗ |
| 21 Sept 2022 | Αρχή Ηλεκτρισμού ΚύπρουThe Cyprus DPA fined the Cyprus Electricity Authority €5,000 for a personal data breach involving unauthorized disclosure to a third party. The authority found violations of GDPR Articles 5(1)(f), 24(1), and 32. | CY | CyDPC | GDPR | €5,000 | ↗ |