BULLETIN №083Last updated · 06 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -22.8%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 29 Sept 2021 | dott.ssa Manuela MazzoliThe Garante imposed a fine of 2,000 EUR on dott.ssa Manuela Mazzoli for breaches of data protection rules. The case concerned the processing of personal data in the healthcare sector, including the principles of lawfulness, fairness, and transparency. | IT | Garante | GDPR | €2,000 | ↗ |
| 29 Sept 2021 | Solera Italia s.r.l.Solera Italia s.r.l. was fined EUR 10,000 by the Garante for continuing to use an employee's email account after the employment ended. The authority found that the company did not provide proper information about this processing. | IT | Garante | GDPR | €10,000 | ↗ |
| 29 Sept 2021 | Kræftens BekæmpelseKræftens Bekæmpelse was fined by Datatilsynet 75,000 DKK for inadequate protection of sensitive health data. The incident affected at least 1,448 individuals and resulted from missing security measures that allowed unauthorized access to personal data. | DK | Datatilsynet | GDPR | €10,086 | ↗ |
| 29 Sept 2021 | GEDI News Network S.p.A.GEDI News Network S.p.A. was fined 30,000 EUR by the Garante for publishing personal data and detailed information about an individual involved in a workplace accident. The authority found a breach of data protection rules. | IT | Garante | GDPR | €30,000 | ↗ |
| 29 Sept 2021 | K-city srlK-city srl was fined by the Italian Garante in the amount of 5,000 EUR for breaching data protection principles. The case concerned the management of a paid parking service for the Municipality of Formia, where compliance with lawfulness, fairness, and transparency was not ensured. | IT | Garante | GDPR | €5,000 | ↗ |
| 29 Sept 2021 | Prefettura - Ufficio Territoriale del Governo di GenovaPrefettura - Ufficio Territoriale del Governo di Genova was fined by the Garante for publishing personal data on its institutional website. The conduct breached GDPR requirements on lawful processing and protection of personal data. | IT | Garante | GDPR | €11,000 | ↗ |
| 29 Sept 2021 | Comune di FormiaComune di Formia was fined for processing personal data linked to parking subscription services without providing adequate information to data subjects. The authority also found excessive data collection and a failure to clearly define the role of the external data processor. | IT | Garante | GDPR | €30,000 | ↗ |
| 04 Oct 2021 | AD735 DATA MEDIA ADVERTISING S.L.The entity was fined by the AEPD for breaching data protection rules. It continued sending commercial emails despite repeated requests from the complainant to delete their data. | ES | AEPD | ePrivacy | €6,000 | ↗ |
| 04 Oct 2021 | LA ÚLTIMA HORA NOTICIAS, S.L.LA ÚLTIMA HORA NOTICIAS, S.L. was fined by the AEPD EUR 2,000 for installing cookies on users’ devices without prior consent. The authority also found that the website did not provide adequate information about the cookies used. | ES | AEPD | ePrivacy | €2,000 | ↗ |
| 04 Oct 2021 | ENDESA ENERGÍA, S.A.U.ENDESA ENERGÍA, S.A.U. was fined by the AEPD 50,000 EUR for breaching GDPR data accuracy principles. The case involved identity theft and false documentation in a request to transfer an electricity contract. | ES | AEPD | GDPR | €50,000 | ↗ |
| 04 Oct 2021 | SAKBO SPAIN, S.L.SAKBO SPAIN, S.L. was fined by the AEPD in the amount of 5,000 EUR for sending unsolicited commercial emails without recipient consent. The conduct breached Article 21 of the LSSI governing electronic marketing communications. | ES | AEPD | ePrivacy | €5,000 | ↗ |
| 06 Oct 2021 | Telefónica de España, S.A.U.Telefónica de España, S.A.U. was fined by the AEPD EUR 15,000 for sending commercial emails without meeting the requirements of Article 21 of the LSSI. The authority noted that the messages were sent despite the recipient's objection. | ES | AEPD | ePrivacy | €15,000 | ↗ |
| 06 Oct 2021 | Anonymisé (CNPD decision-35-fr-2021)The company was fined by the CNPD in the amount of 5,300 EUR for breaching GDPR requirements. The authority found that it failed to provide adequate information to data subjects and did not comply with the data minimization principle. | LU | CNPD | GDPR | €5,300 | ↗ |
| 13 Oct 2021 | Anonymisé (CNPD decision-36-fr-2021)The company did not involve the Data Protection Officer in all matters related to personal data protection. CNPD found this breached GDPR Articles 38(1) and 39(1) and imposed a EUR 23,400 fine. | LU | CNPD | GDPR | €23,400 | ↗ |
| 14 Oct 2021 | Azienda per la Tutela della Salute (ATS) della SardegnaAzienda per la Tutela della Salute (ATS) della Sardegna was fined EUR 8,000 by the Garante for improper processing of personal data, including health data. The authority found breaches of GDPR Articles 5 and 9. | IT | Garante | GDPR | €8,000 | ↗ |
| 14 Oct 2021 | Dane anonimowe (Bank Z. S.A.)The Polish DPA (UODO) imposed an administrative fine of PLN 363,832 on Bank Z. S.A. The authority found that the bank failed to notify the supervisory authority of a personal data breach and did not inform the affected individuals. | PL | UODO | GDPR | €79,625 | ↗ |
| 20 Oct 2021 | PLUSVECINOS, S.L.PLUSVECINOS, S.L. was fined by the AEPD in the amount of 3,000 EUR for sending commercial emails without prior consent from recipients. The conduct breached Article 21 of the LSSI. | ES | AEPD | ePrivacy | €3,000 | ↗ |
| 25 Oct 2021 | Anonymizováno (ÚOOÚ UOOU-00288/20-21)The entity was fined by the UOOU for sending unsolicited commercial communications by email without prior recipient consent. The conduct breached Czech rules on information society services. | CZ | UOOU | ePrivacy | €1,166 | ↗ |
| 26 Oct 2021 | ЧСИ2The Commission fined the private bailiff ЧСИ2 for unlawfully processing personal data by accessing bank account information after the enforcement proceeding had ended. The authority found a breach of the purpose limitation principle under Article 5 GDPR. | BG | CPDP | GDPR | €383 | ↗ |
| 26 Oct 2021 | AMAZON ROAD TRANSPORT SPAIN, S.LAmazon Road Transport Spain, S.L was fined 3,300,000 EUR by the AEPD for requiring job candidates to provide a criminal record certificate and consent for data transfers outside the EEA. The authority found that these practices breached GDPR and LOPDGDD rules on lawful processing and data transfer safeguards. | ES | AEPD | GDPR | €3,300,000 | ↗ |