BULLETIN №083Last updated · 05 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -22.5%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 12 May 2021 | Anonymisé (CNPD decision-17-fr-2021)The CNPD found that the company breached GDPR principles by failing to comply with data minimization and retention limits in its video surveillance practices. A fine of EUR 1,900 was imposed. | LU | CNPD | GDPR | €1,900 | ↗ |
| 12 May 2021 | Locatefamily.comLocatefamily.com was fined for failing to appoint an EU representative, in breach of GDPR Article 27. The authority also imposed a penalty payment because the violation remained unresolved. | NL | AP | GDPR | €525,000 | ↗ |
| 12 May 2021 | xy d.o.o.The company xy d.o.o. was fined by AZOP for failing to implement appropriate technical security measures. This resulted in unauthorized processing of personal data of 28,085 data subjects, indicating a data protection compliance failure. | HR | AZOP | GDPR | €30,553 | ↗ |
| 12 May 2021 | E4LEGAL ANALYTICS, S.L. (EMÉRITA LEGAL)E4LEGAL ANALYTICS, S.L. was fined by the AEPD EUR 3,100,000 for processing personal data from judicial sentences without proper authorization. The case concerned the reuse of data in a way that may have breached data protection rules and restrictions on further use. | ES | AEPD | GDPR | €3,100,000 | ↗ |
| 12 May 2021 | Anonymisé (CNPD decision-14-fr-2021)The company was fined by the CNPD in the amount of 2,600 EUR for breaching GDPR requirements on data minimization, data retention, and information obligations. The case concerned non-compliant personal data processing and a failure to provide the required information to data subjects. | LU | CNPD | GDPR | €2,600 | ↗ |
| 12 May 2021 | KARIERA A.E.The company was fined for failing to comply with data subjects' requests to delete personal data. As a result, unsolicited email communications continued. | GR | HDPA | GDPR | €5,000 | ↗ |
| 12 May 2021 | Anonymisé (CNPD decision-16-fr-2021)The company was fined for failing to comply with the data minimization principle and for not providing adequate information to data subjects under GDPR Articles 5(1)(c) and 13. The CNPD decision indicates deficiencies in the company’s processing practices and privacy disclosures. | LU | CNPD | GDPR | €1,000 | ↗ |
| 12 May 2021 | Anonymisé (CNPD decision-15-fr-2021)The CNPD imposed a EUR 2,900 fine for breaching the data minimization principle in connection with video surveillance. The camera’s field of view covered areas that were not necessary for the processing purpose, contrary to Article 5(1)(c) GDPR. | LU | CNPD | GDPR | €2,900 | ↗ |
| 13 May 2021 | Comune di BolzanoThe Municipality of Bolzano was fined 84,000 EUR by the Garante for improper handling of employee internet navigation data. The authority found that personal data were systematically collected without adequate safeguards and in breach of data protection principles. | IT | Garante | GDPR | €84,000 | ↗ |
| 13 May 2021 | Brico Rida s.r.l.Brico Rida s.r.l. was fined by the Garante in the amount of 2,000 EUR for operating a video surveillance system without the required information notice to data subjects. The authority found a breach of Article 13 GDPR. | IT | Garante | GDPR | €2,000 | ↗ |
| 13 May 2021 | Artemisia s.p.a.Artemisia s.p.a. was fined EUR 100,000 by the Garante for GDPR breaches in data processing. The violations concerned consent, information notices, and the handling of health data. | IT | Garante | GDPR | €100,000 | ↗ |
| 13 May 2021 | Synlab Med srlSynlab Med srl was fined EUR 20,000 by the Garante. The authority found that personal data were improperly transmitted to an entity not competent to process them, breaching the principles of data minimization and integrity. | IT | Garante | GDPR | €20,000 | ↗ |
| 13 May 2021 | ATS di Bergamo, Agenzia di Tutela della saluteATS di Bergamo was fined by the Garante 20,000 EUR for violations involving the improper handling of sensitive health data. The case concerned the use of email to transmit data, which did not provide an adequate level of protection. | IT | Garante | GDPR | €20,000 | ↗ |
| 13 May 2021 | Iren Mercato S.p.A.Iren Mercato S.p.A. was fined by the Garante for processing personal data for marketing purposes without proper consent. The company also contacted individuals listed in the public opposition register. | IT | Garante | GDPR | €2,856,000 | ↗ |
| 13 May 2021 | Agenzia di Tutela della Salute della Città metropolitana di MilanoAgenzia di Tutela della Salute della Città metropolitana di Milano was fined by the Garante 80,000 EUR for violations linked to data processing during an emergency. The authority found inadequate data protection measures and a failure to provide required information to data subjects. | IT | Garante | GDPR | €80,000 | ↗ |
| 14 May 2021 | persoană fizicăA natural person was fined EUR 200 by ANSPDCP for violating GDPR requirements. The case concerned breaches related to the processing of personal data. | RO | ANSPDCP | GDPR | €200 | ↗ |
| 14 May 2021 | SIA "SS"DVI imposed a fine of EUR 100,000 on SIA "SS". According to the record, the sanction was later annulled. | LV | DVI | GDPR | €100,000 | ↗ |
| 17 May 2021 | VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined 5,000 EUR by the AEPD for failing to provide requested information. The case concerns a breach of obligations under data protection rules. | ES | AEPD | GDPR | €5,000 | ↗ |
| 17 May 2021 | Vodafone Servicios, S.L.U.The AEPD fined Vodafone Servicios, S.L.U. 50,000 EUR for processing personal data without proper consent. The breach led to unauthorized charges on a customer's bank account. | ES | AEPD | GDPR | €50,000 | ↗ |
| 17 May 2021 | VODAFONE ESPAÑA, S.A.U.Vodafone España, S.A.U. was fined by the AEPD 80,000 EUR for processing personal data without proper consent. The case involved linking phone lines to incorrect data and enrolling a customer in services without authorization. | ES | AEPD | GDPR | €80,000 | ↗ |