BULLETIN №082Last updated · 31 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.4%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 14 Mar 2023 | Tinmar Energy SATinmar Energy SA was fined EUR 3,000 by ANSPDCP after unauthorized access to its email server. The incident resulted in a personal data breach. | RO | ANSPDCP | GDPR | €3,000 | ↗ |
| 14 Mar 2023 | DIGIMAN ALICANTE, S.L.DIGIMAN ALICANTE, S.L. was fined 2,000 EUR by the AEPD for failing to remove an ex-employee’s image from its YouTube channel despite repeated requests. The authority found a breach of GDPR Article 6(1) regarding the lawful basis for processing personal data. | ES | AEPD | GDPR | €2,000 | ↗ |
| 14 Mar 2023 | Dane anonimowe (Prokuraturę Rejonową w G. z siedzibą w G. przy ul.)UODO imposed an administrative fine of PLN 20,000 on the District Prosecutor's Office in G. The authority found that the entity failed to notify the supervisory authority of a personal data breach without undue delay and did not inform the affected individuals without undue delay. | PL | UODO | GDPR | €4,266 | ↗ |
| 13 Mar 2023 | JUNTA MAYOR DE COFRADÍAS Y HERMANDADES DE LA SEMANA SANTA DE ELCHEThe organization did not inform participants about the processing of their personal data during the “Gymkhana Cofrade” event, which constitutes a breach of Article 13 GDPR. The AEPD imposed a fine of 1,000 EUR. | ES | AEPD | GDPR | €1,000 | ↗ |
| 13 Mar 2023 | Modaone SRLModaone SRL was fined by ANSPDCP EUR 2,000 for sending commercial emails to a data subject after the person had objected. The authority found a breach of the GDPR right to object. | RO | ANSPDCP | GDPR | €2,000 | ↗ |
| 10 Mar 2023 | DIGI SPAIN TELECOM, S.L.DIGI SPAIN TELECOM, S.L. was fined by the AEPD 200,000 EUR for issuing a duplicate SIM card to a third party without the customer's consent. The action enabled unauthorized bank transactions, indicating a serious breach of data protection and authentication security. | ES | AEPD | GDPR | €200,000 | ↗ |
| 09 Mar 2023 | EASYJET AIRLINE COMPANY LIMITEDEasyJet Airline Company Limited was fined by the AEPD 10,000 EUR for failing to provide timely access to personal data requested by an individual. The authority found a breach of Article 15 GDPR, which governs the right of access. | ES | AEPD | GDPR | €10,000 | ↗ |
| 09 Mar 2023 | B.B.B.A camera was installed in a community garage without prior authorization and without proper signage. The AEPD found this to be a breach of Article 13 GDPR and imposed a EUR 300 fine. | ES | AEPD | GDPR | €300 | ↗ |
| 09 Mar 2023 | INTERURBANA DE AUTOBUSES, S.A.INTERURBANA DE AUTOBUSES, S.A. was fined by the AEPD 70,000 EUR for publishing employees’ personal data without consent. The breach involved exposing unnecessary information on notice boards accessible to others, contrary to data minimization requirements. | ES | AEPD | GDPR | €70,000 | ↗ |
| 09 Mar 2023 | Banca Cambiano 1884 S.p.A.Banca Cambiano 1884 S.p.A. was fined by the Garante 10,000 EUR for failing to respond within the required timeframe to a data subject's request for access to personal data. The authority found a breach of GDPR Articles 15 and 12. | IT | Garante | GDPR | €10,000 | ↗ |
| 09 Mar 2023 | B.B.B.B.B.B. was fined by the AEPD EUR 600 for failing to implement corrective measures regarding improperly oriented surveillance cameras. The authority also found a failure to provide the required information under the GDPR. | ES | AEPD | GDPR | €600 | ↗ |
| 09 Mar 2023 | Aesse S.r.l.s.Aesse S.r.l.s. was fined by the Italian Garante in the amount of €3,000. The case concerned unsolicited telemarketing calls made without consent and insufficient information provided about the source of personal data. | IT | Garante | GDPR | €3,000 | ↗ |
| 09 Mar 2023 | Stefano MolenaThe Garante imposed a EUR 3,000 fine on Stefano Molena for operating a surveillance camera without the required informational signage. The breach concerned privacy rules and the duty to properly inform individuals subject to monitoring. | IT | Garante | GDPR | €3,000 | ↗ |
| 09 Mar 2023 | Deca s.r.l.Deca s.r.l. was fined EUR 1,600 by the Garante. The authority found that the company failed to respond to requests for access to personal data relating to work attendance and unlawfully processed data through an incomplete video surveillance system. | IT | Garante | GDPR | €1,600 | ↗ |
| 09 Mar 2023 | Consorzio Concessioni Reti Gas S.c.a.r.l.The Garante fined Consorzio Concessioni Reti Gas S.c.a.r.l. EUR 2,000 for GDPR breaches linked to the improper handling of email accounts and the failure to provide data processing information after an internship ended. The case highlights deficiencies in information duties and access control over personal data. | IT | Garante | GDPR | €2,000 | ↗ |
| 08 Mar 2023 | RING RING CLIN S.L.RING RING CLIN S.L. was fined 500 EUR by the Spanish Data Protection Agency (AEPD). The case concerned the failure to provide requested information, which breaches Article 58.1 of the GDPR. | ES | AEPD | GDPR | €500 | ↗ |
| 08 Mar 2023 | ALTERNATIVA CORELLANA INDEPENDIENTE (ACI)The organization published a court ruling on its blog without anonymizing the personal data of the individuals involved. The AEPD found a breach of the data minimization principle and imposed a 500 EUR fine. | ES | AEPD | GDPR | €500 | ↗ |
| 07 Mar 2023 | SIA "Euronics Latvia"The DVI imposed a fine of EUR 20,000 on SIA "Euronics Latvia". The decision entered into force on 7 March 2023. | LV | DVI | GDPR | €20,000 | ↗ |
| 06 Mar 2023 | B.B.B.The entity was fined by the AEPD €5,000 for publishing radio amateurs’ personal data on a Telegram channel. The breach involved linking call signs to personal information, which violated data protection rules. | ES | AEPD | GDPR | €5,000 | ↗ |
| 06 Mar 2023 | Integral Collection SRLIntegral Collection SRL was fined EUR 3,000 by ANSPDCP after a ransomware incident. The attack led to unauthorized access and loss of integrity and availability of personal data. | RO | ANSPDCP | GDPR | €3,000 | ↗ |