BULLETIN №082Last updated · 03 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 01 Jan 2021 | Dña. B.B.B.The entity was fined for publishing personal images and contact numbers on a dating website without proper consent. The authority found a breach of Article 6(1) of the GDPR. | ES | AEPD | GDPR | €2,000 | ↗ |
| 01 Jan 2021 | RODALI GESTIÓN INMOBILIARIA, S.L.RODALI GESTIÓN INMOBILIARIA, S.L. was fined by the AEPD 5,000 EUR for failing to provide clients with information about the processing of their personal data. The authority found a breach of Article 13 of the GDPR. | ES | AEPD | GDPR | €5,000 | ↗ |
| 01 Jan 2021 | ASOCIACIÓN ESPAÑOLA PARA LA ENSEÑANZA ONLINEThe entity was fined by the AEPD for sending advertising emails without the recipients’ consent. It also failed to comply with a request to delete personal data from its databases. | ES | AEPD | ePrivacy | €5,000 | ↗ |
| 01 Jan 2021 | ORANGE ESPAGNE, S.A.U.ORANGE ESPAGNE, S.A.U. was fined 100,000 EUR by the AEPD for requiring customers to submit photographs of both sides of their ID cards as a condition for package delivery. The authority found that this practice breached data protection principles. | ES | AEPD | GDPR | €100,000 | ↗ |
| 01 Jan 2021 | ORANGE ESPAÑA VIRTUAL, S.L.SIMYO was fined for failing to adequately protect personal data, which enabled unauthorized SIM card duplication. The incident led to fraudulent bank transactions and indicates significant security shortcomings. | ES | AEPD | GDPR | €70,000 | ↗ |
| 01 Jan 2021 | CLUB DEPORTIVO RITMO DE ANDALUCÍAThe club was fined by the AEPD 4,000 EUR for failing to adequately inform users about the processing of their personal data. The authority also found that users were not given the opportunity to provide free and voluntary consent for each specific processing purpose. | ES | AEPD | GDPR | €4,000 | ↗ |
| 01 Jan 2021 | Município de LisboaThe Portuguese data protection authority fined Município de Lisboa EUR 1,250,000 in 2021. The sanction concerned the unlawful transfer of protesters’ personal data to the Russian Embassy in breach of the GDPR. | PT | Comissão Nacional de Proteção de Dados | GDPR | €1,250,000 | ↗ |
| 01 Jan 2021 | ASM PRATASM PRAT was fined EUR 5,000 by the AEPD for requiring recipients to submit photos of their ID cards without consent. The company also failed to provide information about the data processing, which breached data protection rules. | ES | AEPD | GDPR | €5,000 | ↗ |
| 04 Jan 2021 | MACASVER S.L.MACASVER S.L. was fined €8,000 by the AEPD for incorrectly identifying the driver of a vehicle involved in a traffic violation. The authority found a breach of the GDPR data accuracy principle. | ES | AEPD | GDPR | €8,000 | ↗ |
| 04 Jan 2021 | Innovasjon NorgeThe Norwegian DPA notified Innovasjon Norge of a planned NOK 1,000,000 fine for conducting four credit assessments of an individual and his sole proprietorship without a legal basis. The case indicates a breach of the lawfulness principle for personal data processing. | NO | Datatilsynet | GDPR | €95,750 | ↗ |
| 05 Jan 2021 | Dane anonimowe (M. Sp. z o.o. z siedzibą w Z. przy)The President of UODO imposed an administrative fine of PLN 21,397 on M. Sp. z o.o. The company failed to cooperate with the authority and did not provide information needed to assess a complaint concerning personal data processing. | PL | UODO | GDPR | €4,705 | ↗ |
| 05 Jan 2021 | Dane anonimowe (Panią M. Z. prowadzącą działalność gospodarczą pod firmą K.)The President of UODO imposed a fine of PLN 85,588 on an individual conducting business under the name K. The authority found that an order contained in an administrative decision on personal data protection had not been complied with. | PL | UODO | GDPR | €18,822 | ↗ |
| 05 Jan 2021 | DKN.5131.6.2020StatusprawomocnaTytuUODO imposed a fine of PLN 25,000 on the University for failing to report a personal data breach to the President of UODO. The institution also did not notify the affected individuals about the breach. | PL | UODO | GDPR | €5,498 | ↗ |
| 08 Jan 2021 | C.C.C.C.C.C. was fined EUR 2,000 by the AEPD. The authority found that the company failed to provide a written contract and did not inform the complainant about the processing of personal data, in breach of Article 13 GDPR. | ES | AEPD | GDPR | €2,000 | ↗ |
| 11 Jan 2021 | RIPOBRUNA 2007, S.L.RIPOBRUNA 2007, S.L. was fined by the AEPD 2,000 EUR for installing surveillance cameras directed toward public spaces without justified cause. The authority found this processing to be contrary to data protection principles. | ES | AEPD | GDPR | €2,000 | ↗ |
| 11 Jan 2021 | Dane anonimowe (M. S.A. z siedzibą w Z. przy ul.)The President of UODO imposed an administrative fine of PLN 136,437 on M. S.A. The penalty was issued because the company did not report a personal data breach to the supervisory authority without undue delay. | PL | UODO | GDPR | €30,123 | ↗ |
| 12 Jan 2021 | ASOCIACIÓN CULTURAL ***ASOCIACIÓN.1The association was fined for sharing images of a minor in WeChat groups without parental consent. The authority found a breach of GDPR Article 6(1)(a). | ES | AEPD | GDPR | €3,000 | ↗ |
| 14 Jan 2021 | Agenzia regionale protezione ambientale Campania (ARPAC)ARPAC was fined by the Garante EUR 8,000 for violations concerning data security measures and data breach notification obligations. The case involved non-compliance with GDPR Articles 5 and 32. | IT | Garante | GDPR | €8,000 | ↗ |
| 14 Jan 2021 | Coop Finnmark SAThe Norwegian DPA fined Coop Finnmark SA 400,000 NOK for unlawfully sharing a surveillance video from a store. The store manager recorded the footage with a mobile phone and shared it without a legal basis, breaching GDPR principles. | NO | Datatilsynet | GDPR | €38,796 | ↗ |
| 14 Jan 2021 | IDFINANCE SPAIN, S.L.IDFINANCE SPAIN, S.L. was fined by the AEPD EUR 5,000 after an incident in which a user could access another customer's personal data and loan information through a faulty email link. The authority found breaches of GDPR Articles 5(1)(f) and 32 relating to security and confidentiality. | ES | AEPD | GDPR | €5,000 | ↗ |