BULLETIN №083Last updated · 05 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -22.5%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 21 Apr 2021 | ParkkiPateThe Finnish Data Protection Ombudsman fined ParkkiPate EUR 70,000 for GDPR violations. The case concerned data minimization, identification of data subjects, and the handling of access rights. | FI | TSV | GDPR | €70,000 | ↗ |
| 22 Apr 2021 | DKN.5130.3114.2020StatusnieprawomocnaTytuUODO imposed an administrative fine of PLN 1,136,975. The authority found that the entity failed to implement appropriate technical and organizational measures to secure personal data processed in cooperation with a courier service provider. | PL | UODO | GDPR | €249,000 | ↗ |
| 22 Apr 2021 | Magyar ÁllamkincstárThe Hungarian National Authority for Data Protection and Freedom of Information (NAIH) fined Magyar Államkincstár HUF 1,000,000. The authority found a breach of GDPR lawfulness and data minimization principles because personal data were transferred without a proper legal basis. | HU | NAIH | GDPR | €2,750 | ↗ |
| 23 Apr 2021 | Vodafone España, S.A.U.Vodafone España, S.A.U. was fined by the AEPD 70,000 EUR for processing personal data without proper consent. The case involved a call to a customer about a service package that the customer had not authorized. | ES | AEPD | GDPR | €70,000 | ↗ |
| 23 Apr 2021 | Vodafone España, S.A.U.The AEPD fined Vodafone España, S.A.U. EUR 70,000 for failing to adequately prevent identity theft. As a result, unauthorized phone line contracts were entered into using a customer's personal data. | ES | AEPD | GDPR | €70,000 | ↗ |
| 23 Apr 2021 | VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD 50,000 EUR for changing a customer's mobile line ownership without consent. The company also charged the customer's account amounts related to a third party's phone line. | ES | AEPD | GDPR | €50,000 | ↗ |
| 23 Apr 2021 | FRIGORIFICA BOTANA, S.L.FRIGORIFICA BOTANA, S.L. was fined by the AEPD EUR 4,000 for disproportionate audio/video recording in a meeting room without a justified cause or proper notice. The authority found this breached data protection principles. | ES | AEPD | GDPR | €4,000 | ↗ |
| 23 Apr 2021 | VODAFONE SERVICIOS, S.L.U.Vodafone Servicios, S.L.U. was fined by the AEPD 50,000 EUR for failing to verify a customer's identity. The lapse enabled identity fraud and the unauthorized creation of an account. | ES | AEPD | GDPR | €50,000 | ↗ |
| 23 Apr 2021 | B.B.B.The entity was fined for operating a video surveillance system at the workplace without informing employees through the required informational signage. The authority found this to be a breach of Article 13 GDPR. | ES | AEPD | GDPR | €1,000 | ↗ |
| 23 Apr 2021 | Vodafone España, S.A.U.Vodafone España, S.A.U. was fined by the AEPD EUR 70,000 for allowing unauthorized access to a customer's personal data. The data was then used to fraudulently contract mobile lines without the customer's consent. | ES | AEPD | GDPR | €70,000 | ↗ |
| 23 Apr 2021 | VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD 50,000 EUR for changing a customer's tariff without consent. The case involved identity impersonation and improper processing of personal data under the GDPR. | ES | AEPD | GDPR | €50,000 | ↗ |
| 23 Apr 2021 | Vodafone España, S.A.U.Vodafone España, S.A.U. was fined EUR 70,000 by the AEPD after a third party gained unauthorized access to a customer account. The incident led to changes in personal data and services without the customer’s consent. | ES | AEPD | GDPR | €70,000 | ↗ |
| 27 Apr 2021 | Diszpécseri munkakört betöltő munkavállalóval folytatott telefonhívás rögzítéseThe decision concerned the unlawful recording and use of phone calls without a proper legal basis and without adequate transparency. The authority found breaches of GDPR accountability, lawful processing, and transparency principles. | HU | NAIH | GDPR | €1,380 | ↗ |
| 27 Apr 2021 | Dane anonimowe (K. Spółkę Akcyjną z siedzibą w N. przy ul.)The President of UODO imposed an administrative fine of PLN 22,739 on the company. The sanction resulted from failure to cooperate with the supervisory authority and from not providing information necessary to resolve the case. | PL | UODO | GDPR | €4,982 | ↗ |
| 27 Apr 2021 | XFERA MÓVILES, S.A.XFERA MÓVILES, S.A. was fined by the AEPD EUR 3,000 for sending commercial emails without the recipient’s consent. The authority found a breach of Article 21 of the LSSI, despite the recipient’s attempts to unsubscribe. | ES | AEPD | ePrivacy | €3,000 | ↗ |
| 27 Apr 2021 | B.B.B.B.B.B. was fined 500 EUR by the AEPD for installing a surveillance camera. The camera captured common areas and a neighbor's parking space, which breached data protection rules. | ES | AEPD | GDPR | €500 | ↗ |
| 29 Apr 2021 | Comune di PutifigariComune di Putifigari was fined EUR 3,000 by the Garante for publishing special-category personal data online. The disclosed information could reveal individuals' health status, which breached GDPR requirements on data protection and privacy. | IT | Garante | GDPR | €3,000 | ↗ |
| 29 Apr 2021 | Azienda Usl di BolognaThe Garante fined Azienda Usl di Bologna EUR 30,000 for violations related to the processing of personal data in the electronic health record. The case resulted in a data breach, indicating deficiencies in the protection or handling of patient data. | IT | Garante | GDPR | €30,000 | ↗ |
| 29 Apr 2021 | Azienda Ospedaliero Universitaria PisanaAzienda Ospedaliero Universitaria Pisana was fined by the Garante EUR 4,000 for breaches of the principles of lawfulness, fairness, transparency, integrity, and confidentiality in data processing. The case concerned improper handling of personal data under GDPR requirements. | IT | Garante | GDPR | €4,000 | ↗ |
| 29 Apr 2021 | Alfa Shipyard s.r.l.Alfa Shipyard s.r.l. was fined by the Garante in the amount of €5,000 for failing to respond to a data subject's request for information. The authority found this to be a breach of GDPR obligations. | IT | Garante | GDPR | €5,000 | ↗ |