BULLETIN №082Last updated · 03 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 11 Feb 2021 | ZCALL LEVANTE, S.L.ZCALL LEVANTE, S.L. was fined by the AEPD 20,000 EUR for making a commercial call to a number registered on the Robinson List. This conduct breached telecommunications and consumer protection rules. | ES | AEPD | GDPR | €20,000 | ↗ |
| 11 Feb 2021 | Arma dei carabinieriArma dei carabinieri was fined by the Garante for improperly handling sensitive and judicial data without adequate safeguards against unauthorized access. The authority found breaches of the GDPR and the Italian Privacy Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 11 Feb 2021 | Comando generale del Corpo delle Capitanerie di porto-Guardia CostieraThe Garante imposed a €5,000 fine on the Comando generale del Corpo delle Capitanerie di porto-Guardia Costiera for inadequate data protection measures. The breach resulted in the unlawful disclosure of personal data on its website. | IT | Garante | GDPR | €5,000 | ↗ |
| 11 Feb 2021 | Azienda Unità Sanitaria Locale di ParmaAzienda Unità Sanitaria Locale di Parma was fined by the Garante €10,000 for improper handling of sensitive personal data. The violation was linked to an occasional malfunction of its IT system, which led to improper data processing. | IT | Garante | GDPR | €10,000 | ↗ |
| 11 Feb 2021 | Политическа партия „Д.П.Б.“Political party “D.P.B.” was fined 1,000 BGN by CPDP for processing personal data without the consent of the data subjects. The breach occurred during the registration of election commission members and violated Article 6 GDPR. | BG | CPDP | GDPR | €511 | ↗ |
| 11 Feb 2021 | Bonatti S.p.ABonatti S.p.A was fined EUR 40,000 by the Garante for violating data protection rules. The company improperly shared an employee's medical data with a third party. | IT | Garante | GDPR | €40,000 | ↗ |
| 11 Feb 2021 | Roma Servizi per La Mobilita S.r.l.Roma Servizi per La Mobilita S.r.l. was fined EUR 60,000 by the Garante for inadequate security measures. The weakness led to unauthorized access to personal data related to ZTL permits. | IT | Garante | GDPR | €60,000 | ↗ |
| 11 Feb 2021 | Azienda Sanitaria Locale n. 2 Lanciano-Vasto-ChietiAzienda Sanitaria Locale n. 2 Lanciano-Vasto-Chieti was fined by the Garante 6,500 EUR for violations related to the processing of health data. The нарушения led to a data breach incident. | IT | Garante | GDPR | €6,500 | ↗ |
| 11 Feb 2021 | Fondazione di religione e di culto “Casa sollievo della sofferenza” Opera di San Pio da PietrelcinaThe foundation was fined by the Garante 5,000 EUR for processing personal data in breach of the principles of lawfulness, fairness, transparency, integrity, and confidentiality. The case concerned in particular the handling of health data. | IT | Garante | GDPR | €5,000 | ↗ |
| 11 Feb 2021 | Liceo Pepe CalamoLiceo Pepe Calamo was fined EUR 5,000 by the Garante for publishing teachers' personal data in public rankings on its institutional website. The authority found a breach of data minimization and transparency principles. | IT | Garante | GDPR | €5,000 | ↗ |
| 11 Feb 2021 | Krajową Szkołę Sądownictwa i Prokuratury z siedzibą w Z.,UODO imposed a PLN 100,000 administrative fine on the National School of Judiciary and Public Prosecution. The authority found that the entity failed to implement appropriate technical and organizational measures to ensure the ongoing confidentiality of processing services and breached GDPR Article 28(3). | PL | UODO | GDPR | €22,235 | ↗ |
| 11 Feb 2021 | Roma CapitaleRoma Capitale was fined EUR 350,000 by the Garante for breaches of GDPR principles, including data minimization and security. The violations resulted in unauthorized access to personal data over an extended period. | IT | Garante | GDPR | €350,000 | ↗ |
| 11 Feb 2021 | Ministero dello Sviluppo EconomicoThe Ministry of Economic Development was fined by the Garante for publishing personal data, including managers' CVs, on its institutional website without a proper legal basis. The authority found this conduct to be in breach of GDPR requirements. | IT | Garante | GDPR | €75,000 | ↗ |
| 12 Feb 2021 | A*** GmbHA*** GmbH was fined by the Austrian Data Protection Authority for failing to cooperate in three separate complaint procedures. The authority found a breach of Article 31 GDPR, which requires cooperation with the supervisory authority. | AT | DSB | GDPR | €3,000 | ↗ |
| 12 Feb 2021 | KUKIMBIA S.L.KUKIMBIA S.L. was fined EUR 3,000 by the AEPD for leaving documents containing personal data unattended. The authority found this to be a breach of data security obligations under Article 32(1) of the GDPR. | ES | AEPD | GDPR | €3,000 | ↗ |
| 12 Feb 2021 | HIGHCLIFFE ESTATES MARBELLA, S.L.The company was fined by the AEPD for not providing a legal notice, privacy policy, or consent checkbox on its website. The authority also found that it used an individual's image without consent, breaching GDPR Articles 13 and 6(1). | ES | AEPD | GDPR | €8,000 | ↗ |
| 12 Feb 2021 | ELECTROTECNIA BASTIDA, S.L.ELECTROTECNIA BASTIDA, S.L. was fined by the AEPD 3,000 EUR for leaving employees’ confidential medical information abandoned in a field. The incident constituted a breach of data protection rules and required supervisory action. | ES | AEPD | GDPR | €3,000 | ↗ |
| 15 Feb 2021 | KHR-be való adattovábbítás (létre nem jött szerződés esetén)The controller unlawfully transferred personal data to the Central Credit Information System (KHR) even though no contract had been concluded. The authority found a breach of Article 6 GDPR and imposed a fine of 1,500,000 HUF. | HU | NAIH | GDPR | €4,185 | ↗ |
| 15 Feb 2021 | ANYTIME FITNESS IBERIA, S.L.ANYTIME FITNESS IBERIA, S.L. was fined by the AEPD 15,000 EUR for failing to delete personal data after a request and for sending promotional SMS messages without consent. The case concerns non-compliance with data subject rights and rules on direct marketing. | ES | AEPD | ePrivacy | €15,000 | ↗ |
| 17 Feb 2021 | VODAFONE ONO, S.A.U.VODAFONE ONO, S.A.U. was fined by the AEPD 10,000 EUR for sending an unsolicited commercial SMS to a complainant without prior consent. The authority found that the message was sent without the required authorization. | ES | AEPD | ePrivacy | €10,000 | ↗ |