BULLETIN №083Last updated · 06 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -22.8%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 13 Nov 2021 | IMPERIUM C.B.IMPERIUM C.B. was fined by the AEPD in the amount of 1,500 EUR for failing to provide informational signage about its video surveillance system. The authority found a breach of Article 13 GDPR because individuals on the premises were not given the required notice. | ES | AEPD | GDPR | €1,500 | ↗ |
| 19 Nov 2021 | MEETING PUERTO C.B.MEETING PUERTO C.B. was fined by the AEPD EUR 2,000 for unlawful processing of personal data. The breach involved posting images and comments on social media without the consent of the data subjects, contrary to Article 6(1) of the GDPR. | ES | AEPD | GDPR | €2,000 | ↗ |
| 19 Nov 2021 | Working Capital Management España, S.L.Working Capital Management España, S.L. was fined by the AEPD 40,000 EUR for unlawfully processing personal data. The company included an individual's data in a credit information system without a valid contract, in connection with an identity theft case. | ES | AEPD | GDPR | €40,000 | ↗ |
| 22 Nov 2021 | SCF ZHU, S.L.SCF ZHU, S.L. was fined by the AEPD 1,000 EUR for failing to display visible information signs for its video surveillance system and for not maintaining a record of processing activities. The case reflects deficiencies in basic transparency and documentation obligations under data protection rules. | ES | AEPD | GDPR | €1,000 | ↗ |
| 22 Nov 2021 | B.B.B.The entity installed a surveillance camera in a shared stairway without the consent of the affected persons. The camera captured an excessive area, including private spaces, which breached data protection principles. | ES | AEPD | GDPR | €2,000 | ↗ |
| 22 Nov 2021 | COMUNIDAD DE PROPIETARIOS R.R.R.The entity was fined by the AEPD for operating a video surveillance system that recorded public transit areas without a justified basis. The authority found a breach of data protection principles. | ES | AEPD | GDPR | €3,000 | ↗ |
| 23 Nov 2021 | atvinnuvega- og nýsköpunarráðuneytiðThe Icelandic DPA, Persónuvernd, fined atvinnuvega- og nýsköpunarráðuneytið for processing personal data in breach of core GDPR principles, including transparency and security. The case concerned the Ferðagjöf app, where the authority found deficiencies in data protection compliance. | IS | Persónuvernd | GDPR | €50,850 | ↗ |
| 24 Nov 2021 | FRUTAS Y VERDURAS LOS CAMPEONES, S.L.The company was fined by the AEPD EUR 1,500 for installing surveillance cameras without the required informational signage. The case concerned Article 13 GDPR, which requires data subjects to be informed about the processing. | ES | AEPD | GDPR | €1,500 | ↗ |
| 25 Nov 2021 | Azienda Ospedaliera di Rilievo Nazionale “Antonio Cardarelli"The hospital was fined by the Garante 50,000 EUR for unlawfully publishing on its website the personal data of participants in a competitive procedure, including health data. The authority found a breach of data protection principles. | IT | Garante | GDPR | €50,000 | ↗ |
| 25 Nov 2021 | Ordinanza ingiunzione - 25 novembre 2021 [9733002]A healthcare professional was fined by the Garante EUR 30,000 for unlawfully disclosing a patient's personal data, including unpaid medical bills and health information, to third parties. The authority found that the processing lacked a legal basis and breached the principles of lawfulness, fairness, and transparency. | IT | Garante | GDPR | €30,000 | ↗ |
| 25 Nov 2021 | Società H San Raffaele Resnati s.r.l.The Garante imposed a fine of EUR 6,000 on Società H San Raffaele Resnati s.r.l. for violations of data protection rules in the health sector. The case involved a data breach incident, which triggered supervisory action. | IT | Garante | GDPR | €6,000 | ↗ |
| 26 Nov 2021 | Valoris Center S.R.L.Valoris Center S.R.L. was fined by ANSPDCP EUR 2,000 for a personal data processing security breach. The incident was caused by a call center employee. | RO | ANSPDCP | GDPR | €2,000 | ↗ |
| 28 Nov 2021 | INCOPROSOL, S.L.INCOPROSOL, S.L. was fined EUR 5,000 by the AEPD for recording a customer's phone conversation without informing them. The authority treated this as a breach of data protection principles. | ES | AEPD | GDPR | €5,000 | ↗ |
| 01 Dec 2021 | GrindrThe Norwegian DPA, Datatilsynet, fined Grindr NOK 65 million for sharing user data with third parties for marketing purposes without a legal basis. The authority found a breach of GDPR consent requirements. | NO | Datatilsynet | GDPR | €6,360,000 | ↗ |
| 01 Dec 2021 | Dane anonimowe (P. Sp. z o.o. z siedzibą we W. przy ul.)The UODO imposed an administrative fine of PLN 18,192 on P. Sp. z o.o. The case concerned a breach of applicable rules that resulted in an administrative sanction. | PL | UODO | GDPR | €3,931 | ↗ |
| 02 Dec 2021 | Casa di cura Fondazione Gaetano e Piera Borghi s.r.l.The Garante imposed a EUR 30,000 fine on Casa di cura Fondazione Gaetano e Piera Borghi s.r.l. for inadequate data protection measures. The authority found insufficient password security and no HTTPS protocol, affecting patient health data. | IT | Garante | GDPR | €30,000 | ↗ |
| 02 Dec 2021 | Teaching CouncilThe Irish DPC fined Teaching Council EUR 60,000 in inquiry IN-20-4-1. The fine has been collected. | IE | DPC | GDPR | €60,000 | ↗ |
| 02 Dec 2021 | Società Med Store Saronno s.r.l.The Garante fined Società Med Store Saronno s.r.l. EUR 7,000 for inadequate data protection measures. The authority found insufficient password security and no HTTPS protocol, affecting personal health data. | IT | Garante | GDPR | €7,000 | ↗ |
| 02 Dec 2021 | La Duomo S.r.l.s.La Duomo S.r.l.s. was fined EUR 20,000 by the Garante for sending unsolicited promotional SMS messages without valid consent. The authority found that the company’s conduct breached data protection rules. | IT | Garante | GDPR | €20,000 | ↗ |
| 02 Dec 2021 | Ica s.r.l.Ica s.r.l. was fined by the Garante EUR 30,000 for failing to implement adequate security measures in its online traffic-fine payment service. The weakness allowed unauthorized access to the personal data of fined citizens. | IT | Garante | GDPR | €30,000 | ↗ |