BULLETIN №082Last updated · 31 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.4%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 23 Mar 2023 | B.B.B.B.B.B. was fined by the AEPD in the amount of 2,000 EUR for sending unsolicited commercial emails after a request for data deletion. The conduct breached Article 21 of the LSSI on marketing communications without consent. | ES | AEPD | ePrivacy | €2,000 | ↗ |
| 23 Mar 2023 | La Risorsa Umana.it s.r.l.La Risorsa Umana.it s.r.l. was fined EUR 40,000 by the Garante for monitoring employee email communications without providing proper information to employees. The authority found that this conduct breached GDPR requirements on transparency of processing and data security. | IT | Garante | GDPR | €40,000 | ↗ |
| 23 Mar 2023 | CAAF CGIL Lombardia s.r.l.CAAF CGIL Lombardia s.r.l. was fined EUR 30,000 by the Garante for unlawful processing of personal data. The company sent promotional emails despite a prior request to delete the data. | IT | Garante | GDPR | €30,000 | ↗ |
| 23 Mar 2023 | Gruppo SAE S.p.A.The Garante fined Gruppo SAE S.p.A. 10,000 EUR for publishing sensitive personal data, including medical information, in an article without proper consent. The case concerns unlawful processing of special-category personal data. | IT | Garante | GDPR | €10,000 | ↗ |
| 23 Mar 2023 | Ministero dell’InternoMinistero dell’Interno was fined EUR 4,000 by the Garante for unlawfully communicating personal data, including health information, to the police without proper justification. The case concerned a breach of lawfulness and purpose limitation requirements. | IT | Garante | GDPR | €4,000 | ↗ |
| 22 Mar 2023 | GRUPO MASSIMO DUTTI, S.A.The AEPD fined GRUPO MASSIMO DUTTI, S.A. EUR 5,000 for failing to provide sufficient information and adequate options regarding cookie consent on its website. The authority found a breach of Article 22.2 of the LSSI. | ES | AEPD | ePrivacy | €5,000 | ↗ |
| 18 Mar 2023 | TOTALENERGIES CLIENTES, S.A.TOTALENERGIES CLIENTES, S.A. was fined EUR 200,000 by the AEPD for linking a customer’s personal data to a third party during gas supply service registration. The authority found this breached data protection principles. | ES | AEPD | GDPR | €200,000 | ↗ |
| 17 Mar 2023 | ORANGE ESPAGNE, S.A.U.ORANGE ESPAGNE, S.A.U. was fined EUR 70,000 by the AEPD for activating a call forwarding service without the user's consent. This led to unauthorized access to the user's bank accounts and transactions. | ES | AEPD | GDPR | €70,000 | ↗ |
| 17 Mar 2023 | TELEFÓNICA MÓVILES ESPAÑA, S.A.The AEPD fined TELEFÓNICA MÓVILES ESPAÑA, S.A. 70,000 EUR for changing a customer's mobile tariff without consent. The authority found that the action breached Article 6(1) GDPR because there was no valid legal basis for the change. | ES | AEPD | GDPR | €70,000 | ↗ |
| 17 Mar 2023 | PLAY FUL KIDS, S.L.PLAY FUL KIDS, S.L. was fined by the AEPD EUR 3,000 for breaching Article 6(1) of the GDPR, which requires a lawful basis for processing personal data. The infringement was classified as very serious. | ES | AEPD | GDPR | €3,000 | ↗ |
| 16 Mar 2023 | VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD 200,000 EUR for failing to implement adequate security measures. A SIM card duplication enabled unauthorized access to a customer’s personal data and financial accounts. | ES | AEPD | GDPR | €200,000 | ↗ |
| 16 Mar 2023 | Argon Medical DevicesArgon Medical Devices was fined NOK 2.5 million by the Norwegian Data Protection Authority, Datatilsynet. The company failed to report a personal data breach involving European employees within the 72-hour deadline required by GDPR Article 33. | NO | Datatilsynet | GDPR | €218,000 | ↗ |
| 16 Mar 2023 | PRODALVIN, S.L.PRODALVIN, S.L. was fined by the AEPD in the amount of 500 EUR for failing to properly inform individuals about the data controller and the address for exercising data subject rights in its video surveillance system. The authority found this to be a breach of Article 13 GDPR. | ES | AEPD | GDPR | €500 | ↗ |
| 16 Mar 2023 | Sancțiuni pentru încălcarea RGPDA healthcare operator was fined for unauthorized disclosure and access to personal data. The case concerned data confidentiality and breaches of GDPR obligations. | RO | ANSPDCP | GDPR | €1,000 | ↗ |
| 16 Mar 2023 | B.B.B.B.B.B. was fined by the AEPD in the amount of EUR 300 for failing to provide adequate information about video surveillance. The authority found a breach of Article 13 GDPR because the affected individuals did not receive the required information. | ES | AEPD | GDPR | €300 | ↗ |
| 16 Mar 2023 | SOCIETE DE LOCATION DE SCOOTERS ELECTRIQUES EN LIBRE-SERVICEThe CNIL imposed a fine of EUR 125,000 on SOCIETE DE LOCATION DE SCOOTERS ELECTRIQUES EN LIBRE-SERVICE. The case concerns a confirmed breach of rules supervised by the data protection authority. | FR | CNIL | GDPR | €125,000 | ↗ |
| 16 Mar 2023 | Sancțiuni pentru încălcarea RGPDA healthcare operator was fined for failing to implement adequate security measures, which led to unauthorized access to personal data. The case indicates a breach of data protection obligations under the GDPR. | RO | ANSPDCP | GDPR | €3,000 | ↗ |
| 15 Mar 2023 | BANKINTER CONSUMER FINANCE E.F.C., S.A.Bankinter Consumer Finance issued a duplicate card without the customer's consent and sent it to an incorrect address. This led to unauthorized transactions and indicated a failure in data protection and payment security controls. | ES | AEPD | GDPR | €70,000 | ↗ |
| 15 Mar 2023 | Partidul Uniunea Salvați RomâniaThe fine was imposed for a data security breach involving the loss of confidentiality and integrity of data stored on a server. The incident resulted from a phishing attack that compromised the system. | RO | ANSPDCP | GDPR | €4,000 | ↗ |
| 15 Mar 2023 | Alianța pentru Unirea RomânilorThe fine was imposed for collecting personal data through a website without informing the data subjects and without meeting the conditions for lawful processing. The breach affected a significant number of individuals and indicates non-compliance with basic transparency and legality requirements. | RO | ANSPDCP | GDPR | €10,000 | ↗ |