BULLETIN №083Last updated · 05 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -22.5%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 29 Apr 2021 | LA ROCA NETWORKS, S.L.LA ROCA NETWORKS, S.L. was fined by the AEPD €1,000 for sending commercial emails to an individual whose email address was included in the Robinson List. The conduct breached Spanish data protection rules governing unsolicited marketing communications. | ES | AEPD | ePrivacy | €1,000 | ↗ |
| 29 Apr 2021 | Comune di TriesteComune di Trieste was fined for the unauthorized disclosure of personal data relating to individuals involved in accidents, including names, damage details, and compensation amounts. The data was improperly accessible, constituting a breach of GDPR requirements. | IT | Garante | GDPR | €45,000 | ↗ |
| 29 Apr 2021 | Azienda Socio Sanitaria Territoriale Dei Sette LaghiAzienda Socio Sanitaria Territoriale Dei Sette Laghi was fined by the Garante in the amount of 4,000 EUR for breaching data protection principles. The authority found violations of lawfulness, fairness, transparency, and data minimization because personal data remained accessible online for an extended period. | IT | Garante | GDPR | €4,000 | ↗ |
| 29 Apr 2021 | Comune di Santa NinfaComune di Santa Ninfa was fined by the Garante 2,000 EUR for publishing a complainant’s personal data online. The publication also included detailed references to enforcement proceedings, which breached GDPR requirements. | IT | Garante | GDPR | €2,000 | ↗ |
| 29 Apr 2021 | Azienda socio sanitaria territoriale Melegnano e della MartesanaAzienda socio sanitaria territoriale Melegnano e della Martesana was fined by the Garante €6,000 for a data breach involving the loss of health data. The case concerned special-category personal data and indicates insufficient organizational or technical safeguards. | IT | Garante | GDPR | €6,000 | ↗ |
| 29 Apr 2021 | CRIQUET PUBLICIDAD, S.L.CRIQUET PUBLICIDAD, S.L. was fined by the AEPD in the amount of 1,000 EUR for sending unsolicited commercial emails. The recipient’s address was registered on the Robinson List, which constitutes a breach of Article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €1,000 | ↗ |
| 29 Apr 2021 | Gemeente EnschedeThe municipality of Enschede was fined by AP for processing personal data of mobile device owners and users without a legal basis. The authority found violations of GDPR Articles 5 and 6. | NL | AP | GDPR | €600,000 | ↗ |
| 29 Apr 2021 | FederpolFederpol was fined 5,000 EUR by the Garante for improperly sharing members’ personal information with other associates. The authority found that this breached data protection rules and required a valid legal basis and appropriate safeguards. | IT | Garante | GDPR | €5,000 | ↗ |
| 04 May 2021 | CLUB GIMNASIA RÍTMICA SAN ANTONIOThe club was fined by the AEPD for publishing images of minors on social media without proper consent. The authority found a breach of GDPR Article 6 on lawful processing. | ES | AEPD | GDPR | €5,000 | ↗ |
| 05 May 2021 | Disqus IncThe Norwegian DPA, Datatilsynet, intends to fine Disqus Inc NOK 25 million. The case concerns a breach of accountability, lack of a legal basis, and failure to inform users about tracking and sharing personal data. | NO | Datatilsynet | GDPR | €2,503,000 | ↗ |
| 05 May 2021 | Munkavállalói e-mail fiókok és munkaeszközök használatával és azok ellenőrzésével összefüggő adatkezelésThe controller did not provide the data subject with adequate prior information about the processing of work email and computer usage. The authority found this to breach the principles of fairness and accountability in data processing. | HU | NAIH | GDPR | €5,560 | ↗ |
| 05 May 2021 | Ítélet a NAIH-3644-9/2021. sz. ügyben (Fővárosi Törvényszék 105.K.704.512/2021/21)The supervisory authority found that the controller had not implemented adequate technical and organizational measures to protect personal data. Employees were also not properly informed about processing related to email accounts and devices, and personal email was accessed without proper justification. | HU | NAIH | GDPR | €5,560 | ↗ |
| 06 May 2021 | Ferde ASThe Norwegian DPA notified Ferde AS of a NOK 5 million fine for unlawfully transferring personal data of Norwegian motorists to China without a valid legal basis. The case concerns non-compliant processing and cross-border transfer of personal data outside the EEA. | NO | Datatilsynet | GDPR | €497,000 | ↗ |
| 06 May 2021 | YThe APD Litigation Chamber imposed a 50,000 EUR fine on Y. The authority found that the privacy policy lacked transparency and breached several GDPR provisions. | BE | APD | GDPR | €50,000 | ↗ |
| 07 May 2021 | B.B.B.The entity was fined for improperly directing surveillance cameras toward public transit areas and the complainant's home entrance. This conduct breached data protection rules. | ES | AEPD | GDPR | €1,500 | ↗ |
| 10 May 2021 | VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD for processing personal data without proper consent, in breach of Article 6(1) GDPR. The penalty was set at EUR 70,000, with reductions available for early payment and acknowledgment of responsibility. | ES | AEPD | GDPR | €70,000 | ↗ |
| 11 May 2021 | Érintetti jog és tájékoztatási kötelezettség megsértéseThe case concerned unlawful processing of personal data in connection with debt collection. The entity failed to respond to data subject requests and unlawfully transferred personal data. | HU | NAIH | GDPR | €1,395 | ↗ |
| 11 May 2021 | Stichting Ondersteuning Provinciale Fractie Overijssel Partij voor de Vrijheid (PVV Overijssel)PVV Overijssel was fined by the AP EUR 7,500 for failing to report a personal data breach within the required 72-hour period. The case concerns a delayed notification to the supervisory authority about a security incident. | NL | AP | GDPR | €7,500 | ↗ |
| 11 May 2021 | Norges idrettsforbundThe Norwegian DPA fined Norges idrettsforbund 1,250,000 NOK for insufficient security measures during testing. As a result, personal data of 3.2 million individuals was exposed online for 87 days. | NO | Datatilsynet | GDPR | €124,000 | ↗ |
| 12 May 2021 | A. EPILOGI IDIOTIKI KEFALAIOUCHIKI ETAIREIAThe company was fined by the HDPA 5,000 EUR for sending unsolicited promotional emails without consent. The authority also found that it failed to respond to data subject access requests and did not provide a valid opt-out address for communications. | GR | HDPA | GDPR | €5,000 | ↗ |