BULLETIN №082Last updated · 03 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 27 Jan 2021 | Istituto Comprensivo Villanova D’AstiIstituto Comprensivo Villanova D’Asti was fined EUR 4,000 by the Garante for publishing personal data online. The disclosed information could reveal health status and economic-social conditions, breaching data minimization and transparency principles. | IT | Garante | GDPR | €4,000 | ↗ |
| 27 Jan 2021 | Comune di Cesano BosconeThe Municipality of Cesano Boscone was fined EUR 2,000 by the Garante for publishing personal data related to a disciplinary sanction on its website. The authority found a breach of the principles of lawfulness, fairness, and transparency. | IT | Garante | GDPR | €2,000 | ↗ |
| 27 Jan 2021 | Roma CapitaleRoma Capitale was fined EUR 10,000 by the Garante for publishing the personal data of a minor and the minor’s mother on its official website without a proper legal basis. The authority found a breach of the principles of lawfulness, fairness, and transparency. | IT | Garante | GDPR | €10,000 | ↗ |
| 27 Jan 2021 | Powerplay S.r.l.Powerplay S.r.l. was fined by the Garante for making unsolicited promotional calls despite the recipient's clear request not to receive further communications. The company failed to place the number on a blacklist, which breached data protection rules. | IT | Garante | GDPR | €20,000 | ↗ |
| 27 Jan 2021 | Azienda USL della RomagnaAzienda USL della Romagna was fined by the Garante 50,000 EUR for failing to implement procedures to prevent unauthorized disclosure of patients' health information. The authority found a breach of GDPR Article 9 on special categories of personal data. | IT | Garante | GDPR | €50,000 | ↗ |
| 27 Jan 2021 | Vodafone España, S.A.U.Vodafone España, S.A.U. was fined by the AEPD 100,000 EUR for making a commercial call to a number registered on the Robinson list. The authority found that this breached data protection and direct marketing opt-out requirements. | ES | AEPD | GDPR | €100,000 | ↗ |
| 27 Jan 2021 | STOCKHUNTERS, S.L.STOCKHUNTERS, S.L. was fined EUR 4,000 by the AEPD for failing to comply with GDPR Article 13. The authority found that the website privacy policy did not meet the required information standards. | ES | AEPD | GDPR | €4,000 | ↗ |
| 27 Jan 2021 | De Nationale Dienst voor Promotie van Kinderartikelen, NVThe company was fined for unlawfully sharing personal data of (expectant) mothers with third parties for direct marketing without valid consent. The authority found breaches of GDPR transparency and information obligations. | BE | APD | GDPR | €50,000 | ↗ |
| 28 Jan 2021 | TRES-F-NETWORK, S.A.UTRES-F-NETWORK, S.A.U was fined by the AEPD 4,000 EUR for sending commercial SMS messages without the recipient's consent and without an existing commercial relationship. The authority found this conduct breached Article 21 of the LSSI. | ES | AEPD | ePrivacy | €4,000 | ↗ |
| 30 Jan 2021 | DEGOM, S.A.DEGOM, S.A. was fined EUR 3,000 by the AEPD for failing to display cookie warnings and data protection acceptance checkboxes on its website. The case concerned deficiencies in online transparency and user consent requirements. | ES | AEPD | ePrivacy | €3,000 | ↗ |
| 03 Feb 2021 | Cyberbook ASCyberbook AS was fined 200,000 NOK by Datatilsynet for unlawfully forwarding a former employee's emails without informing them. The authority found breaches of GDPR requirements on legal basis, information duties, and data deletion. | NO | Datatilsynet | GDPR | €19,316 | ↗ |
| 03 Feb 2021 | ASESORÍA MUNIZ SOLÁN, S.L.ASESORÍA MUNIZ SOLÁN, S.L. was fined by the AEPD 2,000 EUR for breaching confidentiality after sending a debt certificate relating to a third party instead of the correct document. The authority also noted inadequate security measures under GDPR Article 32. | ES | AEPD | GDPR | €2,000 | ↗ |
| 03 Feb 2021 | NBQ TECHNOLOGY, S.A.U.NBQ TECHNOLOGY, S.A.U. was fined by the AEPD 40,000 EUR for processing personal data without a legal basis. The case was linked to a denied financial operation following an identity theft incident. | ES | AEPD | GDPR | €40,000 | ↗ |
| 03 Feb 2021 | MERCADONA S.A.MERCADONA S.A. was fined EUR 170,000 by the AEPD for failing to respond to a data access request within the required timeframe and for deleting security camera footage. The authority found that these actions breached GDPR obligations, including Articles 12 and 6. | ES | AEPD | GDPR | €170,000 | ↗ |
| 05 Feb 2021 | NEXTSTEPAGENCY, S.L.NEXTSTEPAGENCY, S.L. was fined by the AEPD in the amount of 1,000 EUR for failing to provide reliable ownership information and details about data transfers to China on its website. The authority found a breach of the information obligations under Article 13 GDPR. | ES | AEPD | GDPR | €1,000 | ↗ |
| 10 Feb 2021 | Polismyndigheten, Clearview AIThe Swedish Police Authority was fined for using the Clearview AI application. The authority found that the processing of personal data violated the Swedish Criminal Data Act. | SE | IMY | ePrivacy | €248,000 | ↗ |
| 10 Feb 2021 | CEYLLE SOLUTIONS & DEVELOPMENT S.L.CEYLLE SOLUTIONS & DEVELOPMENT S.L. was fined by the AEPD in the amount of 2,000 EUR for disclosing personal data in emails sent to commercial partners. The authority found a breach of data protection rules. | ES | AEPD | GDPR | €2,000 | ↗ |
| 11 Feb 2021 | Istituto Superiore Statale "Pitagora"Istituto Superiore Statale "Pitagora" was fined by the Garante 5,000 EUR for unlawful processing of personal data. The authority found failures to ensure data minimization and transparency toward data subjects. | IT | Garante | GDPR | €5,000 | ↗ |
| 11 Feb 2021 | Stichting OLVGStichting OLVG was fined by the AP 440,000 EUR for failing to implement two-factor authentication and for not regularly reviewing log files. The authority found that the organization did not maintain appropriate security measures required under Article 32 GDPR. | NL | AP | GDPR | €440,000 | ↗ |
| 11 Feb 2021 | Istituti ospedalieri bergamaschiThe Garante fined Istituti ospedalieri bergamaschi EUR 45,000 for a data protection breach. Online medical reports were accessible to other patients, exposing sensitive personal data. | IT | Garante | GDPR | €45,000 | ↗ |