BULLETIN №082Last updated · 31 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.4%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 13 Apr 2023 | Azienda Ospedaliera Universitaria di CagliariAzienda Ospedaliera Universitaria di Cagliari was fined EUR 8,000 by the Garante for unlawfully publishing personal data related to a disciplinary procedure online. The authority found breaches of data minimization and transparency principles. | IT | Garante | GDPR | €8,000 | ↗ |
| 13 Apr 2023 | Retimedia S.r.l.Retimedia S.r.l. was fined 2,500 EUR by the Garante for publishing detailed health data of an individual without consent. The conduct breached GDPR Article 9 on special categories of personal data. | IT | Garante | GDPR | €2,500 | ↗ |
| 13 Apr 2023 | Comune di Cogollo del CengioThe Garante fined Comune di Cogollo del Cengio EUR 3,000 for breaches of GDPR Articles 5, 6 and 9, as well as Articles 2-ter and 2-septies of the Italian Privacy Code. The case concerned the processing of an employee’s personal data without an adequate legal basis and in breach of data protection rules. | IT | Garante | GDPR | €3,000 | ↗ |
| 12 Apr 2023 | Česká republika – Ministerstvo vnitraThe Czech Ministry of Interior was fined CZK 975,000 by the UOOU for violations of personal data processing rules during COVID-19 measures. The authority found, among other issues, a failure to conduct data protection impact assessments and improper disclosure of processing purposes. | CZ | UOOU | GDPR | €41,633 | ↗ |
| 11 Apr 2023 | CORPORACION DE MEDIOS DE EXTREMADURA, S.A.The entity published a video containing personal data of 56 women registered as victims of gender-based violence. The authority found a breach of the data minimization principle and imposed a 150,000 EUR fine. | ES | AEPD | GDPR | €150,000 | ↗ |
| 11 Apr 2023 | CAIXABANK, S.A.CAIXABANK, S.A. was fined by the AEPD EUR 200,000 for failing to remove personal data from a credit information system after the debt was sold. The authority found that the continued processing of the data was not compliant with data protection rules. | ES | AEPD | GDPR | €200,000 | ↗ |
| 11 Apr 2023 | SOCIEDAD VASCONGADA DE PUBLICACIONES, S.A.The entity published a video containing personal data of 56 women registered as victims of gender-based violence. AEPD found that this breached the data minimization principle. | ES | AEPD | GDPR | €150,000 | ↗ |
| 10 Apr 2023 | BIROU GAS, S.L.BIROU GAS, S.L. was fined EUR 60,000 by the AEPD for breaching Article 58(1) of the GDPR. The company did not respond to information requests from the supervisory authority. | ES | AEPD | GDPR | €60,000 | ↗ |
| 10 Apr 2023 | COLEGIO OFICIAL DE ARQUITECTOS DE GRANADACOLEGIO OFICIAL DE ARQUITECTOS DE GRANADA was fined €14,000 by the AEPD for data protection breaches. The authority found a conflict of interest in the appointment of the Data Protection Officer, missing required information on data processing in complaint forms, and the use of third-party cookies without user consent. | ES | AEPD | ePrivacy | €14,000 | ↗ |
| 06 Apr 2023 | К. Л. НK. L. N was fined for unlawfully processing voters' personal data. The case involved forwarding an email containing scanned voting lists to a personal email address, in breach of GDPR Article 6. | BG | CPDP | GDPR | €767 | ↗ |
| 04 Apr 2023 | Tensa Art Design SRLThe company was fined for sending commercial messages to individuals by phone and email despite their requests to stop contact. The case concerned failure to respect opt-out requests against further marketing communication. | RO | ANSPDCP | GDPR | €3,000 | ↗ |
| 04 Apr 2023 | B.B.B.A neighbor installed a digital peephole with video recording capabilities without the consent of the homeowners' association. AEPD found that personal data were processed without a lawful basis, in breach of Article 6(1) GDPR. | ES | AEPD | GDPR | €300 | ↗ |
| 03 Apr 2023 | HM HOSPITALES 1989, S.A.HM HOSPITALES 1989, S.A. was fined EUR 200,000 by the AEPD for insufficient security measures in its hospital information system. The authority found a breach of Article 32 GDPR, which requires appropriate technical and organizational safeguards. | ES | AEPD | GDPR | €200,000 | ↗ |
| 03 Apr 2023 | Banca Transilvania SABanca Transilvania SA was fined EUR 2,000 by ANSPDCP for a GDPR breach. The case concerned improperly restricting access to an account in the mobile banking application despite the client's explicit request. | RO | ANSPDCP | GDPR | €2,000 | ↗ |
| 03 Apr 2023 | CAIXABANK PAYMENTS & CONSUMER EFC, EP, S.A.U.CAIXABANK PAYMENTS & CONSUMER EFC, EP, S.A.U. was fined by the AEPD 200,000 EUR for unlawfully including an individual's data in a creditworthiness file without a lawful basis. The authority found this conduct violated Article 6 of the GDPR. | ES | AEPD | GDPR | €200,000 | ↗ |
| 01 Apr 2023 | TikTokTikTok is appealing a UK data-protection fine of GBP 12.7 million imposed by the Information Commissioner's Office. The record states that in April 2023 the platform was found to have breached the UK GDPR by failing to process children's personal data lawfully. | GB | Information Commissioner's Office | GDPR | €14,444,000 | ↗ |
| 31 Mar 2023 | LODEJU, S.L.LODEJU, S.L. was fined by the AEPD EUR 3,000 for improperly directing surveillance cameras toward public spaces without authorization. The authority also found inadequate informational signage, in breach of GDPR Articles 5(1)(c) and 13. | ES | AEPD | GDPR | €3,000 | ↗ |
| 31 Mar 2023 | APOLLONIA TOPCO, S.L.APOLLONIA TOPCO, S.L. was fined by the AEPD EUR 30,000 for improperly requesting copies of clients’ ID documents. The authority also noted a failure to respond to a data protection complaint, in breach of data minimization and purpose limitation principles. | ES | AEPD | GDPR | €30,000 | ↗ |
| 30 Mar 2023 | Vodafone-PanafonVodafone-Panafon was fined by the HDPA for processing personal data for direct marketing without proper consent and transparency. The authority found breaches of lawfulness, fairness, and purpose limitation. | GR | HDPA | GDPR | €10,000 | ↗ |
| 30 Mar 2023 | XCOM DIGITAL LAB, S.L.XCOM DIGITAL LAB, S.L. was fined by the AEPD EUR 800 for sending unsolicited commercial emails. The company failed to comply with Article 21 of the LSSI despite repeated requests from the recipient to unsubscribe. | ES | AEPD | ePrivacy | €800 | ↗ |