BULLETIN №082Last updated · 03 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 10 Jun 2024 | KAFFA KOFFEE ORGANISATION, S.L.KAFFA KOFFEE ORGANISATION, S.L. was fined by the AEPD EUR 2,000 for sending an email to more than 400 recipients without using BCC. This exposed other recipients’ email addresses and breached GDPR Articles 5(1)(f) and 32. | ES | AEPD | GDPR | €2,000 | ↗ |
| 01 Jan 2015 | JYCTEL ESPAÑA SLJYCTEL ESPAÑA SL was fined by the AEPD in the amount of 3,000 EUR for sending unsolicited SMS and WhatsApp messages. The company did not provide information on how to exercise the right to object, which breaches Article 21 of the LSSI. | ES | AEPD | ePrivacy | €3,000 | ↗ |
| 01 Jan 2020 | JUST LANDED, S.L.JUST LANDED, S.L. was fined EUR 3,000 by the AEPD for failing to provide a privacy policy and a cookie policy on its website. The authority cited a breach of GDPR Article 13 and LSSI Article 22.2. | ES | AEPD | ePrivacy | €3,000 | ↗ |
| 28 Jul 2016 | Jurica PavicJurica Pavic was fined by the Garante for failing to provide adequate information to data subjects about video surveillance. The authority found this to be a breach of privacy regulations. | IT | Garante | GDPR | €2,400 | ↗ |
| 13 Mar 2023 | JUNTA MAYOR DE COFRADÍAS Y HERMANDADES DE LA SEMANA SANTA DE ELCHEThe organization did not inform participants about the processing of their personal data during the “Gymkhana Cofrade” event, which constitutes a breach of Article 13 GDPR. The AEPD imposed a fine of 1,000 EUR. | ES | AEPD | GDPR | €1,000 | ↗ |
| 13 Jun 2023 | JUNTA DE CONSERVACION SECTOR RESIDENCIAL ELORDIGAN SATThe entity was fined by the AEPD for installing a video surveillance system with inadequate signage. The notices did not identify the data controller or provide contact details for exercising data subject rights, breaching Article 13 GDPR. | ES | AEPD | GDPR | €500 | ↗ |
| 15 Mar 2022 | JUNTA ADMINISTRADORA A.A.A.The entity was fined for displaying complainants’ personal data on a public notice board. This breached data protection rules and created a risk of unauthorized disclosure of personal information. | ES | AEPD | GDPR | €2,000 | ↗ |
| 17 Jul 2025 | Juna S.r.l.Juna S.r.l. was fined €25,000 by the Garante for making repeated unwanted and fraudulent promotional calls to individuals. The conduct breached data protection principles, including lawful and fair processing requirements. | IT | Garante | GDPR | €25,000 | ↗ |
| 13 Sept 2017 | Jump 3000 s.r.l.Jump 3000 s.r.l. was fined by the Garante 14,800 EUR for providing clients with inadequate data protection information. The authority found that the privacy notices did not properly identify the data controller. | IT | Garante | GDPR | €14,800 | ↗ |
| 01 Jan 2021 | JUBASER DE CONTROL, S.L.JUBASER DE CONTROL, S.L. was fined by the AEPD 5,000 EUR for unlawful processing of personal data. The case concerned improper handling of a customer's ID and personal information, which later appeared on an adult contact website. | ES | AEPD | GDPR | €5,000 | ↗ |
| 18 Mar 2025 | JRSY Laser LimitedThe Jersey Data Protection Authority fined JRSY Laser Limited 500 GBP following an investigation opened on 27 March 2024. The case concerned a breach of data protection requirements by the data controller. | JE | JOIC | GDPR | €594 | ↗ |
| 05 May 2022 | JOYPAZAR, S.A.JOYPAZAR, S.A. was fined by the AEPD for reinstalling a surveillance camera that captured images of a public children's park. The authority found this to be a breach of data protection rules. | ES | AEPD | GDPR | €2,000 | ↗ |
| 20 Dec 2025 | JOMAFRAN 2013, S. LJOMAFRAN 2013, S. L was fined by the AEPD EUR 1,400 for sending unsolicited commercial emails without prior consent. The authority found this conduct breached Article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €1,400 | ↗ |
| 09 Sept 2022 | JOLY DIGITAL, S.L.U.JOLY DIGITAL, S.L.U. was fined by the AEPD EUR 20,000 for publishing the complainant’s private Instagram photo without consent. The authority found a breach of Article 6 GDPR because there was no lawful basis for processing the personal data. | ES | AEPD | GDPR | €20,000 | ↗ |
| 29 Oct 2019 | JOKER PREMIUM INVEX, S.L.JOKER PREMIUM INVEX, S.L. was fined by the AEPD EUR 10,000 for sending unsolicited commercial communications. The company used personal data taken from public sources without the individuals’ consent. | ES | AEPD | GDPR | €10,000 | ↗ |
| 14 Apr 2023 | Join the Triboo LimitedBetween 1 August 2019 and 19 August 2020, Join the Triboo Limited sent a confirmed total of 107 million direct marketing messages, of which 437,324 were received by distinct individuals. On average, each person received 244 emails during the period, and the messages contained direct marketing material without valid subscriber consent. | GB | ICO | GDPR | €146,000 | ↗ |
| 07 Apr 2021 | Jogellenes adatkezelés, adattakarékosság és megfelelő tájékoztatási kötelezettség megsértéseThe authority found that the controller unlawfully processed personal data related to debt collection. It held that the principles of data minimization and transparency were breached, together with the duty to provide proper information to data subjects. | HU | NAIH | GDPR | €2,780 | ↗ |
| 20 Mar 2026 | Jogalap nélküli hozzáférés az EESZT rendszeréhez és hozzáférési kérelem nemteljesítéseThe supervisory authority imposed a fine for processing personal data without a lawful basis, including health data. It also found failure to comply with an access request, which breaches GDPR obligations. | HU | NAIH | GDPR | €1,275 | ↗ |
| 22 Oct 2020 | Jogalap nélküli adattovábbítás mobilparkolási szolgáltatás kapcsánThe controller transferred the complainant's personal data to the complainant's employer without a valid legal basis. This breached the purpose limitation principle and the complainant's right of access. | HU | NAIH | GDPR | €5,480 | ↗ |
| 15 May 2020 | JobTeam A/SJobTeam A/S was reported to the police, and Datatilsynet recommended a fine of 50,000 DKK for breaching GDPR principles. The company deleted personal data after a data subject access request, which hindered the exercise of the individual's rights. | DK | Datatilsynet | GDPR | €6,705 | ↗ |