BULLETIN №082Last updated · 30 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.2%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 05 Apr 2024 | PALANCAMAR, S.L.PALANCAMAR, S.L. was fined EUR 5,000 by the AEPD for failing to inform a customer about the processing of their personal data during a vehicle purchase. The authority treated this as a breach of Article 13 GDPR. | ES | AEPD | GDPR | €5,000 | ↗ |
| 04 Dec 2019 | VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined 5,000 EUR by the AEPD for failing to provide requested information. The case concerned a breach of obligations under data protection rules. | ES | AEPD | GDPR | €5,000 | ↗ |
| 04 Feb 2020 | XFERA MÓVILES, S.A.XFERA MÓVILES, S.A. was fined by the Spanish data protection authority, AEPD, in the amount of 5,000 EUR. The sanction concerned obstruction of the authority’s inspection function, which breaches Article 58(1) GDPR. | ES | AEPD | GDPR | €5,000 | ↗ |
| 04 Jun 2025 | Comune di ReccoThe Garante fined Comune di Recco EUR 5,000 for inadequate data protection measures linked to video surveillance used to monitor waste disposal. The authority found breaches of the principles of lawfulness, fairness, and transparency. | IT | Garante | GDPR | €5,000 | ↗ |
| 01 Jan 2015 | ENDESA ENERGÍA S.A.ENDESA ENERGÍA S.A. was fined by the AEPD EUR 5,000 for sending unsolicited commercial SMS messages to a complainant who had previously opted out of such communications. The authority found a breach of Article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €5,000 | ↗ |
| 13 Jun 2022 | AMADEUS IT GROUP, S.A.AMADEUS IT GROUP, S.A. was fined by the AEPD EUR 5,000 for failing to properly handle a data subject's requests to access and delete personal data. The authority found a breach of Article 12 GDPR because the company did not provide an adequate response. | ES | AEPD | GDPR | €5,000 | ↗ |
| 30 Oct 2024 | Untold SRLUntold SRL was fined EUR 5,000 by ANSPDCP for violations of GDPR provisions. The case concerned non-compliance with personal data protection requirements. | RO | ANSPDCP | GDPR | €5,000 | ↗ |
| 26 Mar 2015 | Lo.Ma. S.r.l.Lo.Ma. S.r.l. was fined EUR 5,000 by the Italian data protection authority, Garante. The sanction concerned the activation of SIM cards without the knowledge of the individuals concerned, which breached data protection rules. | IT | Garante | GDPR | €5,000 | ↗ |
| 29 Apr 2021 | Alfa Shipyard s.r.l.Alfa Shipyard s.r.l. was fined by the Garante in the amount of €5,000 for failing to respond to a data subject's request for information. The authority found this to be a breach of GDPR obligations. | IT | Garante | GDPR | €5,000 | ↗ |
| 27 Mar 2025 | Azienda sanitaria territoriale di MacerataAzienda sanitaria territoriale di Macerata was fined 5,000 EUR by the Garante for failing to comply with data access requests and for breaches of data protection rules. The case concerned the processing of health data and inadequate security measures. | IT | Garante | GDPR | €5,000 | ↗ |
| 24 Jul 2019 | НОИThe National Social Security Institute (НОИ) was fined for failing to implement adequate technical and organizational measures to prevent employees from accessing personal data without authorization. The authority found this to be a breach of GDPR Article 25. | BG | CPDP | GDPR | €2,557 | ↗ |
| 06 Oct 2014 | MANGO-ON LINE, S.A.MANGO-ON LINE, S.A. was fined by the AEPD €5,000 for continuing to send newsletters to a complainant despite multiple unsubscribe requests. The authority found this breached Article 21 of the LSSI on unsolicited commercial communications. | ES | AEPD | ePrivacy | €5,000 | ↗ |
| 05 Feb 2025 | FARMEC SAThe National Supervisory Authority for Personal Data Processing completed an investigation in December 2024 at FARMEC SA and found a GDPR violation. As a result, the company was fined EUR 5,000. | RO | ANSPDCP | GDPR | €5,000 | ↗ |
| 07 Oct 2020 | UST GLOBAL ESPAÑA, S.A.UST Global España, S.A. was fined by the AEPD EUR 5,000 for improperly sharing employees’ personal data in a group email. The disclosed data included names, email addresses, and DNI numbers, which breached data protection principles. | ES | AEPD | GDPR | €5,000 | ↗ |
| 24 Jul 2024 | MONUMENTAL FORMA SPORT, S.L.MONUMENTAL FORMA SPORT, S.L. was fined EUR 5,000 by the AEPD for sending unsolicited commercial SMS messages without recipient consent. The case concerned Article 21 of the LSSI, which requires prior consent for electronic marketing communications. | ES | AEPD | ePrivacy | €5,000 | ↗ |
| 06 Dec 2021 | Telekom România Communications SAANSPDCP completed an investigation into Telekom România Communications SA in November 2021. As a result, a fine of EUR 5,000 was imposed for GDPR violations. | RO | ANSPDCP | GDPR | €5,000 | ↗ |
| 28 Sept 2023 | Giuseppe AnzaloneThe Garante imposed a EUR 5,000 fine on Giuseppe Anzalone for breaches of personal data processing rules. The case concerned patient data and involved failures to comply with lawfulness, fairness, transparency, data minimization, integrity, and confidentiality principles. | IT | Garante | GDPR | €5,000 | ↗ |
| 13 May 2015 | HellastatHellastat was fined by the HDPA EUR 5,000 for the illegal collection and use of data. The case concerned a breach of data protection laws. | GR | HDPA | GDPR | €5,000 | ↗ |
| 10 Jun 2021 | MARIA & DESPOINA KOUSATHANA O.E.The company was fined by the HDPA 5,000 EUR for operating a video surveillance system without proper notification and for unlawful camera use in kitchen areas. The authority also found that data subjects were not informed about the processing of their personal data. | GR | HDPA | GDPR | €5,000 | ↗ |
| 25 Nov 2024 | XFERA CONSUMER FINANCE ESTABLECIMIENTO FINANCIERO DE CRÉDITO, S.A.The AEPD fined XFERA Consumer Finance 5,000 EUR for sending a customer unsolicited advertising SMS messages. The messages were sent after the customer had asked to stop receiving such communications, indicating a breach of marketing communication rules. | ES | AEPD | ePrivacy | €5,000 | ↗ |