BULLETIN №083Last updated · 05 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -22.5%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 10 Jun 2021 | Aeroporto Guglielmo Marconi di Bologna S.p.a.Aeroporto Guglielmo Marconi di Bologna S.p.a. was fined by the Garante EUR 40,000 for violations related to the protection of whistleblower identities. The case indicates insufficient personal data safeguards in the handling of reports. | IT | Garante | GDPR | €40,000 | ↗ |
| 11 Jun 2021 | BRAbank ASABRAbank ASA was fined NOK 400,000 by Datatilsynet for failing to perform risk assessments and testing before launching a customer portal. The deficiency led to a data breach in which customers could view other customers’ loan information. | NO | Datatilsynet | GDPR | €39,672 | ↗ |
| 11 Jun 2021 | Anonymisé (CNPD decision-21-fr-2021)The company did not comply with the data minimization principle and failed to adequately inform employees and third parties about data processing activities. CNPD found these practices to breach GDPR Articles 5(1)(c) and 13. | LU | CNPD | GDPR | €7,600 | ↗ |
| 11 Jun 2021 | Anonymisé (CNPD decision-20-fr-2021)The company was fined EUR 15,000 by the CNPD for failing to properly involve the Data Protection Officer in matters related to personal data protection. The authority also found that the DPO's autonomy was not ensured and that the advisory and monitoring functions were not adequately supported. | LU | CNPD | GDPR | €15,000 | ↗ |
| 11 Jun 2021 | Anonymisé (CNPD decision-22-fr-2021)The company failed to comply with GDPR requirements on data minimization and transparency. It also did not adequately inform individuals about video surveillance and geolocation systems, breaching Articles 5(1)(c), 5(1)(e), 13, and 32(1) of the GDPR. | LU | CNPD | GDPR | €7,200 | ↗ |
| 12 Jun 2021 | MERCEDES GERENCIA, S.L.MERCEDES GERENCIA, S.L. was fined by the AEPD in the amount of 3,000 EUR for breaching Article 58.1 of the GDPR. The case concerned non-compliance with obligations related to the supervisory authority’s powers. | ES | AEPD | GDPR | €3,000 | ↗ |
| 14 Jun 2021 | SIA "Andy corporation"A monetary fine of EUR 491.18 was imposed on SIA "Andy corporation" by the DVI. The decision is final and has entered into force. | LV | DVI | GDPR | €491 | ↗ |
| 14 Jun 2021 | B.B.B.The entity was fined by the AEPD EUR 3,000 for publicly disseminating surveillance footage without justification. The conduct breached data protection principles. | ES | AEPD | GDPR | €3,000 | ↗ |
| 15 Jun 2021 | VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined 50,000 EUR by the AEPD for continuing to pursue a debt that had already been settled. The authority treated this as a breach of data protection rules. | ES | AEPD | GDPR | €50,000 | ↗ |
| 15 Jun 2021 | Huppuís ehf.Huppuís ehf. was fined 5,000,000 ISK by Persónuvernd for unlawful electronic surveillance in an ice cream shop. The authority found breaches of transparency and proportionality requirements and noted that employees, including minors, were not informed about the surveillance. | IS | Persónuvernd | GDPR | €33,950 | ↗ |
| 16 Jun 2021 | Vejle KommuneVejle Kommune was fined by Datatilsynet for failing to implement appropriate security measures, which led to the unintended disclosure of personal data, including children's addresses. The authority also found no assessment of whether such disclosures were necessary. | DK | Datatilsynet | GDPR | €13,447 | ↗ |
| 16 Jun 2021 | MARBELLA RESORTS, S.L.MARBELLA RESORTS, S.L. was fined EUR 7,000 by the AEPD for non-compliance with data protection rules. The breaches concerned the handling of personal data and the website cookie policy. | ES | AEPD | ePrivacy | €7,000 | ↗ |
| 18 Jun 2021 | DESPACHO TEJEDOR INFANTES CONSULTORES ASESORES, S.L.The entity unlawfully disclosed personal data to a third party, breaching the confidentiality principle under GDPR. The AEPD imposed a fine of 2,000 EUR. | ES | AEPD | GDPR | €2,000 | ↗ |
| 18 Jun 2021 | Kiskorúra vonatkozó egészségügyi adatok közlése országos híradásbanThe authority found that the respondent disclosed the complainant’s personal data and special-category health data without a lawful basis. Several GDPR provisions were breached, and a fine of HUF 5,000,000 was imposed. | HU | NAIH | GDPR | €14,050 | ↗ |
| 18 Jun 2021 | STAROFSERVICE SASSTAROFSERVICE SAS was fined by the AEPD 3,000 EUR for sending advertising emails without the recipient's consent. This conduct breached Article 21 of the LSSI. | ES | AEPD | ePrivacy | €3,000 | ↗ |
| 18 Jun 2021 | IZA OBRAS Y PROMOCIONES, S.A.IZA OBRAS Y PROMOCIONES, S.A. was fined by the AEPD 50,000 EUR for disclosing an employee’s health data and personal email address without consent. The authority treated this as a breach of data protection rules. | ES | AEPD | GDPR | €50,000 | ↗ |
| 18 Jun 2021 | Magyar Telekom Nyrt.The Hungarian data protection authority fined Magyar Telekom Nyrt. for unlawful processing of personal data. The case involved failure to delete an email address and improper handling of data subject rights. | HU | NAIH | GDPR | €28,100 | ↗ |
| 21 Jun 2021 | GSMA LTD.GSMA LTD. was fined by the AEPD for requiring biometric data, including passport details and photos, for facial recognition at the Mobile World Congress without a valid legal basis. The authority found a breach of data protection rules. | ES | AEPD | GDPR | €200,000 | ↗ |
| 21 Jun 2021 | DKN.5131.3.2021StatusprawomocnaTytuUODO imposed an administrative fine of PLN 159,176 on an insurance company. The authority found that the company failed to notify the President of UODO of a personal data breach within the required timeframe. | PL | UODO | GDPR | €35,116 | ↗ |
| 21 Jun 2021 | Storstockholms Lokaltrafik, SLStorstockholms Lokaltrafik, SL was fined by IMY for using body-worn cameras without a legal basis. The authority found breaches of the GDPR principles of lawfulness, transparency, and data minimization. | SE | IMY | GDPR | €1,566,000 | ↗ |