BULLETIN №082Last updated · 03 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 26 Oct 2020 | ESTILO 1221, S.C.ESTILO 1221, S.C. was fined by the AEPD EUR 1,500 for sending unsolicited commercial emails without recipient consent. The conduct breached Article 21.1 of the LSSI, which prohibits this type of marketing communication without prior consent. | ES | AEPD | ePrivacy | €1,500 | ↗ |
| 27 Oct 2020 | VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined 50,000 EUR by the AEPD for requesting payment for services contracted without the complainant’s consent. The case concerns a data protection breach linked to processing and debt collection without a valid legal basis. | ES | AEPD | GDPR | €50,000 | ↗ |
| 29 Oct 2020 | Ministero dell’InternoThe Italian Data Protection Authority fined the Ministry of the Interior EUR 50,000 for the incorrect disclosure of personal data to a limited number of organizations. It also ordered the Ministry to consider training initiatives to improve data accuracy. | IT | Garante | GDPR | €50,000 | ↗ |
| 29 Oct 2020 | Città Metropolitana di NapoliCittà Metropolitana di Napoli was fined EUR 8,000 by the Garante for improper handling of personal data. The authority found that a disciplinary document was not marked as confidential, which allowed unauthorized access within the administration. | IT | Garante | GDPR | €8,000 | ↗ |
| 29 Oct 2020 | Borgo Fonte Scura s.r.l.Borgo Fonte Scura s.r.l. was fined by the Garante 4,000 EUR for failing to provide proper data protection information to individuals, including employees, about the use of a video surveillance system at its premises. The authority found that the required privacy notice obligations were not met. | IT | Garante | GDPR | €4,000 | ↗ |
| 29 Oct 2020 | Gaypa s.r.l.Gaypa s.r.l. was fined EUR 20,000 by the Garante for continuing to use a personalized email account of a former employee after the employment ended. The authority found this conduct inconsistent with GDPR principles of lawfulness and purpose limitation. | IT | Garante | GDPR | €20,000 | ↗ |
| 03 Nov 2020 | CANARYCLICK CONSULTING SLCANARYCLICK CONSULTING SL was fined EUR 8,000 by the AEPD for improper management of its cookie policy on its websites. The authority also found that user consent was collected in a generic manner, in breach of data protection rules. | ES | AEPD | GDPR | €8,000 | ↗ |
| 03 Nov 2020 | LOSADA ADVOCATS S.L.LOSADA ADVOCATS S.L. was fined by the AEPD EUR 10,000 for sending an email without using BCC. This exposed recipients’ email addresses and breached data protection principles. | ES | AEPD | GDPR | €10,000 | ↗ |
| 04 Nov 2020 | VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD 70,000 EUR for processing a fraudulent phone number portability request without the data subject's consent. The authority found a breach of GDPR Article 6(1). | ES | AEPD | GDPR | €70,000 | ↗ |
| 04 Nov 2020 | VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined EUR 60,000 by the AEPD after a contract was entered into using another person's identity. The case concerns a breach of data protection rules and insufficient identity verification. | ES | AEPD | GDPR | €60,000 | ↗ |
| 05 Nov 2020 | B.B.B.The entity was fined by the AEPD EUR 2,000 for using security cameras that recorded public spaces extensively without justification. The authority found that this breached data protection principles. | ES | AEPD | GDPR | €2,000 | ↗ |
| 05 Nov 2020 | DR MARÍN CIRUGIA PLÁSTICA, S.L.P.DR MARÍN CIRUGIA PLÁSTICA, S.L.P. was fined EUR 4,000 by the AEPD. The authority found that the company failed to provide a privacy policy on its website and used personal data for marketing purposes without consent. | ES | AEPD | ePrivacy | €4,000 | ↗ |
| 07 Nov 2020 | B.B.B.B.B.B. was fined by the AEPD EUR 2,000 for operating a video surveillance system directed toward public space. The measure affected the rights of third parties without justified cause and raised data protection compliance concerns. | ES | AEPD | GDPR | €2,000 | ↗ |
| 12 Nov 2020 | VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD EUR 70,000 for continuing to send billing emails to a complainant despite an arbitration ruling. The ruling required the company to stop all services and delete the complainant’s data, which it failed to do. | ES | AEPD | GDPR | €70,000 | ↗ |
| 12 Nov 2020 | Vodafone Italia S.p.A.Vodafone Italia S.p.A. was fined by the Garante 12,251,601 EUR for making unauthorized promotional calls and sending messages. The authority also found that effective measures to ensure data processing security and GDPR compliance were not in place. | IT | Garante | GDPR | €12,251,000 | ↗ |
| 13 Nov 2020 | Y HuisvestingsmaatschappijThe social housing company was fined for breaching GDPR principles, including lawfulness and transparency in personal data processing. The authority also identified deficiencies in access rights handling and privacy policy transparency. | BE | APD | GDPR | €528,000 | ↗ |
| 13 Nov 2020 | B.B.B.The entity was fined EUR 1,500 by the AEPD for improperly installing a surveillance camera. The camera captured images of a public transit area without justified cause, which breached data protection rules. | ES | AEPD | GDPR | €1,500 | ↗ |
| 17 Nov 2020 | PEDROSO Y GÓMEZ ASESORÍA DE EMPRESAS, S.L.The company was fined by the AEPD in the amount of 6,000 EUR for sending emails without the recipients' consent. The authority also noted the absence of contact information for exercising data protection rights. | ES | AEPD | GDPR | €6,000 | ↗ |
| 19 Nov 2020 | ALTERNA OPERADOR INTEGRAL, S.L.ALTERNA OPERADOR INTEGRAL, S.L. was fined by the AEPD EUR 50,000 for changing an electricity provider without the customer's consent. The authority found that the processing lacked a valid legal basis under Article 6(1)(b) GDPR. | ES | AEPD | GDPR | €50,000 | ↗ |
| 23 Nov 2020 | Utbildningsnämnden i Stockholms stad, SkolplattformenThe Education Committee of Stockholm City was fined by IMY 4,000,000 SEK for processing personal data in breach of GDPR Articles 5 and 32. The authority cited inadequate security measures and failure to conduct impact assessments for systems handling sensitive student data. | SE | IMY | GDPR | €391,000 | ↗ |