BULLETIN №083Last updated · 06 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -22.5%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 22 Jun 2021 | VirksomhetenThe Norwegian DPA fined Virksomheten NOK 150,000 for accessing a former employee’s email account without a legal basis and for failing to close the account. The authority found breaches of GDPR rules on information duties, data deletion, and handling objections. | NO | Datatilsynet | GDPR | €14,678 | ↗ |
| 23 Jun 2021 | Lakcímadat helyesbítése szolgáltató általThe NAIH imposed a fine of HUF 1,000,000 for breaching the accuracy principle and the right to rectification. The controller failed to correct inaccurate personal data despite a request from the data subject. | HU | NAIH | GDPR | €2,860 | ↗ |
| 24 Jun 2021 | NEXTGEN FINANCIAL SERVICES S.L.NEXTGEN FINANCIAL SERVICES S.L. failed to update the address in a loan contract and did not correct inaccurate data in a credit file. The AEPD found this to be a breach of the right to data rectification and imposed a fine of 50,000 EUR. | ES | AEPD | GDPR | €50,000 | ↗ |
| 24 Jun 2021 | Comune di FiscianoComune di Fisciano was fined EUR 1,000 by the Garante for improper handling of personal data. The data were removed after the complaint, and the case concerned transparency and data protection obligations. | IT | Garante | GDPR | €1,000 | ↗ |
| 24 Jun 2021 | B.B.B.The entity was fined by the AEPD EUR 1,000 for installing a surveillance camera in a hair salon without informing individuals about the video surveillance area. The authority found this to be a breach of Article 13 of the GDPR. | ES | AEPD | GDPR | €1,000 | ↗ |
| 24 Jun 2021 | BAZTANDIS, S.L.BAZTANDIS, S.L. was fined EUR 1,000 by the AEPD for deficiencies in signage related to video surveillance. The authority found a breach of Article 13 GDPR concerning the information duties owed to individuals under surveillance. | ES | AEPD | GDPR | €1,000 | ↗ |
| 24 Jun 2021 | Comune di Cogollo del CengioThe Municipality of Comune di Cogollo del Cengio was fined by the Garante 1,000 EUR for unlawfully publishing personal data related to a disciplinary procedure. The authority found no legal basis for the disclosure and held that it breached the principles of lawfulness, fairness, and transparency. | IT | Garante | GDPR | €1,000 | ↗ |
| 24 Jun 2021 | Moss kommuneMoss kommune was fined 500,000 NOK by Datatilsynet for insufficiently securing personal data during the merger of IT systems after the merger of Rygge and Moss municipalities. The violations included incorrect vaccine registrations and unauthorized access to patient data. | NO | Datatilsynet | GDPR | €49,145 | ↗ |
| 24 Jun 2021 | Istituto Professionale per i servizi commerciali e turistici “G. Ravizza” di NovaraThe Istituto Professionale per i servizi commerciali e turistici “G. Ravizza” in Novara was fined by the Garante EUR 2,000. The authority found breaches of data protection principles, including lawfulness, fairness, transparency, and data minimization. | IT | Garante | GDPR | €2,000 | ↗ |
| 24 Jun 2021 | Soluzione Tasse S.p.A.Soluzione Tasse S.p.A. was fined by the Garante 30,000 EUR for sending unsolicited emails without proper consent. The case concerned GDPR principles on data processing and transparency. | IT | Garante | GDPR | €30,000 | ↗ |
| 24 Jun 2021 | Ospedale Pediatrico Bambino GesùOspedale Pediatrico Bambino Gesù was fined by the Garante 15,000 EUR for breaches involving a data incident and improper handling of patient health data. The authority cited violations of GDPR Articles 5 and 32 on lawful processing and security of personal data. | IT | Garante | GDPR | €15,000 | ↗ |
| 28 Jun 2021 | ELEGA ENERGÍA, S.L.ELEGA ENERGÍA, S.L. was fined EUR 2,000 by the AEPD for failing to provide information about cookies and for not obtaining user consent before placing them. The authority found a breach of Article 22.2 of the LSSI. | ES | AEPD | ePrivacy | €2,000 | ↗ |
| 29 Jun 2021 | Anonymisé (CNPD decision-24-fr-2021)The company was fined EUR 17,000 by the CNPD for breaching the data minimization principle and for failing to provide adequate information to data subjects. The deficiencies concerned employees and third parties in relation to processing activities. | LU | CNPD | GDPR | €17,000 | ↗ |
| 30 Jun 2021 | Dane anonimowe (Fundację)UODO imposed a PLN 13,644 administrative fine on the Foundation for failing to report a personal data breach without undue delay. The Foundation also did not notify the affected individuals about the incident, breaching controller obligations. | PL | UODO | GDPR | €3,018 | ↗ |
| 01 Jul 2021 | A.A.A.The entity was fined by the AEPD 1,000 EUR for operating a video surveillance system without proper informational signage and customer information forms. The authority found this to be a breach of Article 13 of the GDPR. | ES | AEPD | GDPR | €1,000 | ↗ |
| 01 Jul 2021 | UNIVERSIDAD A DISTANCIA DE MADRID, S.A.UNIVERSIDAD A DISTANCIA DE MADRID, S.A. was fined by the AEPD for failing to comply with a request to delete personal data. As a result, the individual received unsolicited marketing emails, indicating a breach of data protection obligations. | ES | AEPD | GDPR | €5,000 | ↗ |
| 02 Jul 2021 | PODEMOS PARTIDO POLÍTICOPODEMOS PARTIDO POLÍTICO was fined by the AEPD for irregularities in its video surveillance system. The cameras excessively captured public space without justification, and proper signage was missing. | ES | AEPD | GDPR | €4,000 | ↗ |
| 04 Jul 2021 | VODAFONE ESPAÑA, S.A.U.The AEPD fined VODAFONE ESPAÑA, S.A.U. EUR 70,000 for allowing a third party to contract phone numbers using another individual's identity. The case concerns a breach of data protection rules and inadequate identity verification. | ES | AEPD | GDPR | €70,000 | ↗ |
| 05 Jul 2021 | Anonymisoitu (TSV 943)The controller unlawfully processed employees' location data, breaching the GDPR principles of data minimization and lawfulness. The case concerned processing that went beyond what was necessary for the stated purpose. | FI | TSV | GDPR | €25,000 | ↗ |
| 05 Jul 2021 | FUTURE VINLINE SLFUTURE VINLINE SL was fined by the AEPD EUR 10,000 for not having an adequate privacy policy on its website. The authority found that the company failed to provide clear and complete information about data processing under Article 13 GDPR. | ES | AEPD | GDPR | €10,000 | ↗ |