BULLETIN №083Last updated · 05 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -22.5%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 06 Jun 2021 | FLY FUT, S.L.FLY FUT, S.L. was fined by the AEPD in the amount of 3,000 EUR for recording a minor during football matches without prior consent. The case concerns a breach of data protection rules and the requirement to obtain consent before processing a child’s image. | ES | AEPD | GDPR | €3,000 | ↗ |
| 07 Jun 2021 | Voice Integrate Nordic ABVoice Integrate Nordic AB exposed audio files of recorded calls to 1177 Vårdguiden on the internet, including personal data. IMY found that the company failed to implement adequate safeguards under Article 32 GDPR and imposed a fine of SEK 650,000. | SE | IMY | GDPR | €64,643 | ↗ |
| 07 Jun 2021 | CLUB NÁUTICO EL ESTACIOThe entity published personal data on its website without access restrictions. This breached confidentiality and data security principles. | ES | AEPD | GDPR | €3,000 | ↗ |
| 07 Jun 2021 | EFS MANTENIMIENTO Y SERVICIOS TÉCNICOS, S.L.EFS MANTENIMIENTO Y SERVICIOS TÉCNICOS, S.L. was fined EUR 1,000 by the AEPD for improperly sharing an employee’s personal data with the company committee. The authority found a breach of data protection rules. | ES | AEPD | GDPR | €1,000 | ↗ |
| 07 Jun 2021 | Regionstyrelsen Region VärmlandRegionstyrelsen Region Värmland was fined by IMY 250,000 SEK for failing to inform patients calling the 1177 healthcare line that their phone numbers and community IDs were being collected. The authority found this to be a breach of GDPR transparency requirements. | SE | IMY | GDPR | €24,863 | ↗ |
| 07 Jun 2021 | Hälso- och sjukvårdsnämnden Region StockholmHälso- och sjukvårdsnämnden Region Stockholm was fined by IMY for failing to inform callers to the 1177 service about the collection of phone numbers and communication IDs. The authority found a breach of GDPR transparency obligations. | SE | IMY | GDPR | €49,725 | ↗ |
| 07 Jun 2021 | MedHelp Sjukvårdsrådgivning ABMedHelp Sjukvårdsrådgivning AB was fined by IMY for failing to adequately protect 2.7 million recorded calls to the 1177 healthcare advice line. The files were left accessible on the internet without proper safeguards, breaching GDPR requirements on data security and lawful processing. | SE | IMY | GDPR | €1,193,000 | ↗ |
| 07 Jun 2021 | Regionstyrelsen Region SörmlandRegionstyrelsen Region Sörmland was fined by IMY 250,000 SEK for failing to inform callers to the 1177 healthcare line that their phone numbers and community IDs were being collected. The authority found a breach of GDPR transparency requirements. | SE | IMY | GDPR | €24,863 | ↗ |
| 08 Jun 2021 | BAR DA VINCI (SHUANGFENG ZHOU)BAR DA VINCI (SHUANGFENG ZHOU) was fined 500 EUR by the AEPD for operating a surveillance system without proper signage. The authority also found that the system captured excessive footage of public areas, constituting a GDPR breach. | ES | AEPD | GDPR | €500 | ↗ |
| 08 Jun 2021 | DKN.5131.10.2020StatusnieprawomocnaTytuThe President of UODO imposed a fine of PLN 100,000 for failing to notify data breaches within the required deadline. The case concerns the obligation to report personal data breaches to the supervisory authority on time. | PL | UODO | GDPR | €22,372 | ↗ |
| 08 Jun 2021 | IMAGINA FRAN SPORT, S.L.IMAGINA FRAN SPORT, S.L. was fined 2,000 EUR by the AEPD for not having an updated privacy policy on its website. The authority found a breach of the information obligations under GDPR Article 13. | ES | AEPD | GDPR | €2,000 | ↗ |
| 09 Jun 2021 | Räddningstjänsten Östra SkaraborgIMY found that Räddningstjänsten Östra Skaraborg breached the GDPR by improperly using surveillance cameras in changing areas. The authority also identified excessive personal data processing and inadequate security measures. | SE | IMY | GDPR | €34,794 | ↗ |
| 09 Jun 2021 | S.C.The operator was fined by ANSPDCP for failing to provide requested information to the supervisory authority. This constituted a breach of GDPR requirements. | RO | ANSPDCP | GDPR | €2,000 | ↗ |
| 09 Jun 2021 | INMOPISO ZARAGOZA, S.L.INMOPISO ZARAGOZA, S.L. was fined EUR 2,000 by the AEPD for failing to provide data protection information to a customer who made a deposit for a property purchase. The case concerns a breach of the transparency and information duty owed to the data subject. | ES | AEPD | GDPR | €2,000 | ↗ |
| 10 Jun 2021 | MARIA & DESPOINA KOUSATHANA O.E.The company was fined by the HDPA 5,000 EUR for operating a video surveillance system without proper notification and for unlawful camera use in kitchen areas. The authority also found that data subjects were not informed about the processing of their personal data. | GR | HDPA | GDPR | €5,000 | ↗ |
| 10 Jun 2021 | dott. MariniThe Garante imposed a EUR 20,000 fine on dott. Marini for unlawfully collecting information about patients' HIV status. The authority found a breach of the principles of necessity and proportionality in personal data processing. | IT | Garante | GDPR | €20,000 | ↗ |
| 10 Jun 2021 | orthodontiepraktijkThe entity failed to implement appropriate technical and organizational measures to secure personal data, which constitutes a breach of Article 32 GDPR. Sensitive data on the website was not transmitted over encrypted connections, increasing the risk of disclosure. | NL | AP | GDPR | €12,000 | ↗ |
| 10 Jun 2021 | Ministero dell’InternoThe Italian Data Protection Authority fined Ministero dell’Interno EUR 75,000 for posting videos on social media that breached data protection rules. The footage related to a criminal case was shared by the police and contained violent content, which was found inconsistent with data protection principles. | IT | Garante | GDPR | €75,000 | ↗ |
| 10 Jun 2021 | aiComply S.r.l.aiComply S.r.l. was fined by the Garante in the amount of EUR 20,000 for failing to implement adequate security measures. In particular, it did not use a secure network protocol, which created a risk to the confidentiality and integrity of personal data. | IT | Garante | GDPR | €20,000 | ↗ |
| 10 Jun 2021 | Foodinho s.r.l.Foodinho s.r.l. was fined by the Garante EUR 2,600,000 for violations in the processing of riders’ personal data. The authority cited insufficient data minimization, inadequate privacy by design measures, and automated decision-making without proper human intervention. | IT | Garante | GDPR | €2,600,000 | ↗ |