BULLETIN №083Last updated · 05 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -22.5%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 17 May 2021 | TELEFÓNICA DE ESPAÑA, S.A.U.Telefónica de España, S.A.U. was fined by the AEPD for using personal data to contract a service without the data subject’s consent and for listing the complainant in credit information files for a debt that was not recognized. The case concerns processing without a valid legal basis and improper reporting of alleged debt. | ES | AEPD | GDPR | €75,000 | ↗ |
| 19 May 2021 | CP&A B.V.CP&A B.V. was fined by the AP in the amount of EUR 15,000 for processing employees' health data without a legal basis. The authority also found that adequate security measures were not implemented for this processing. | NL | AP | GDPR | €15,000 | ↗ |
| 19 May 2021 | Asociație de Proprietari din municipiul IașiThe association was fined EUR 500 by ANSPDCP for failing to provide requested information to the supervisory authority. The breach concerned obligations under the GDPR. | RO | ANSPDCP | GDPR | €500 | ↗ |
| 19 May 2021 | TNT EXPRESS WORLDWIDE SPAIN, S.L.TNT Express Worldwide Spain, S.L. was fined by the AEPD €10,000 for incorrectly linking a personal delivery service to a corporate account. This resulted in the unauthorized sharing of personal data with the complainant’s employer. | ES | AEPD | GDPR | €10,000 | ↗ |
| 20 May 2021 | B.B.B.The entity did not provide the complainant with information about data processing or the ability to exercise rights after receiving a CV via WhatsApp in response to a job offer. AEPD imposed a fine of EUR 2,000 for breaching transparency obligations. | ES | AEPD | GDPR | €2,000 | ↗ |
| 21 May 2021 | COOPERA RC SERVICES, S.L.COOPERA RC SERVICES, S.L. was fined by the AEPD 2,000 EUR for failing to provide the contact details needed to exercise data protection rights. The authority found a breach of the information obligations under Article 13 GDPR. | ES | AEPD | GDPR | €2,000 | ↗ |
| 26 May 2021 | VODAFONE ESPAÑA, S.A.U.The AEPD fined VODAFONE ESPAÑA, S.A.U. 50,000 EUR for sending SMS messages about an alleged debt for services not contracted by the complainant. The case involved incorrect processing of personal data and the use of inaccurate contact details. | ES | AEPD | GDPR | €50,000 | ↗ |
| 27 May 2021 | Azienda Usl della RomagnaAzienda Usl della Romagna was fined by the Garante in the amount of EUR 120,000 for violations related to the processing of a patient's health data in the gynecology department. The case also involved issues with electronic health records and data breaches. | IT | Garante | GDPR | €120,000 | ↗ |
| 27 May 2021 | Poste Italiane S.p.a.Poste Italiane S.p.a. was fined by the Garante 10,000 EUR for unlawfully communicating a customer's financial data related to a Postepay card to an unauthorized third party. The case concerns a breach of personal data protection and financial confidentiality requirements. | IT | Garante | GDPR | €10,000 | ↗ |
| 27 May 2021 | Società e Salute S.p.a.Società e Salute S.p.a. was fined by the Garante EUR 10,000 for a data breach involving the mishandling of personal data, including health information. The authority found violations of GDPR Articles 5 and 9. | IT | Garante | GDPR | €10,000 | ↗ |
| 27 May 2021 | Società Cavourese S.p.A.Società Cavourese S.p.A. was fined EUR 4,000 by the Italian data protection authority, Garante. The case concerned improper handling of personal data related to employee disciplinary proceedings, in breach of the GDPR and national privacy rules. | IT | Garante | GDPR | €4,000 | ↗ |
| 27 May 2021 | Tempocasa S.p.A.Tempocasa S.p.A. was fined €120,000 by the Italian Garante. The authority found that the company made unsolicited promotional calls without the required consent, breaching GDPR rules on data processing and consent. | IT | Garante | GDPR | €120,000 | ↗ |
| 27 May 2021 | Intesa Sanpaolo s.p.a.Intesa Sanpaolo s.p.a. was fined by the Garante in the amount of 200,000 EUR for unlawfully communicating banking data to an unauthorized third party. The case concerned breaches of data protection principles, including lawfulness and restricted access to information. | IT | Garante | GDPR | €200,000 | ↗ |
| 31 May 2021 | AUTOMECANICA JÉREZ, S.L.AUTOMECANICA JÉREZ, S.L. was fined EUR 4,000 by the AEPD. The authority found that the company sent a mass email without masking personal data and sent commercial emails and SMS messages without consent. | ES | AEPD | ePrivacy | €4,000 | ↗ |
| 31 May 2021 | Anonymizováno (ÚOOÚ UOOU-03580/20-23)The entity was fined for continuing to process personal data for marketing purposes despite the data subject's objection and request for erasure. The authority found this to be a breach of GDPR Article 21. | CZ | UOOU | GDPR | €79 | ↗ |
| 01 Jun 2021 | RADIO POPULAR S.A.RADIO POPULAR S.A. was fined EUR 2,000 by the AEPD for not providing users with the option to reject cookies on its website. The authority found this practice non-compliant with data protection rules and consent requirements. | ES | AEPD | ePrivacy | €2,000 | ↗ |
| 02 Jun 2021 | VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD for improper handling of personal data. A complaint revealed discrepancies in the data linked to a customer's identity, and the penalty was reduced due to early payment. | ES | AEPD | GDPR | €50,000 | ↗ |
| 02 Jun 2021 | TENTEA ENERGY, S.L.TENTEA ENERGY, S.L. was fined by the AEPD EUR 5,000 for using personal data and a signature without consent in connection with energy service contracts. The authority also found a refusal to provide access to personal data in relation to a cancellation request. | ES | AEPD | GDPR | €5,000 | ↗ |
| 04 Jun 2021 | FINCAS MIGUEL GARCÍA, S.LFINCAS MIGUEL GARCÍA, S.L was fined 2,000 EUR by the AEPD for failing to provide the complainant with its privacy policy before collecting personal data. The authority found this to be a breach of the information duty under Article 13 GDPR. | ES | AEPD | GDPR | €2,000 | ↗ |
| 04 Jun 2021 | INTERSUMI S.C.INTERSUMI S.C. was fined EUR 2,000 by the AEPD for not having an adequate privacy policy on its website. The authority found this to be a breach of Article 13 of the GDPR. | ES | AEPD | GDPR | €2,000 | ↗ |