BULLETIN №083Last updated · 06 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -22.8%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 02 Dec 2021 | Azienda USL di ParmaAzienda USL di Parma was fined by the Garante for a data breach involving the unauthorized disclosure of health data. The incident affected one individual and did not result in significant harm, but it was still treated as a GDPR violation. | IT | Garante | GDPR | €5,000 | ↗ |
| 02 Dec 2021 | Omnia 24 S.r.l.Omnia 24 S.r.l. was fined EUR 100,000 by the Garante for sending unsolicited promotional SMS messages without proper consent. The authority found that the company’s conduct breached data protection rules. | IT | Garante | GDPR | €100,000 | ↗ |
| 03 Dec 2021 | MEDIOS DE PREVENCIÓN EXTERNOS, S.L.The entity was fined for sending unsolicited advertising emails despite requests to cancel the subscription. This conduct breached rules on electronic commercial communications. | ES | AEPD | ePrivacy | €2,000 | ↗ |
| 03 Dec 2021 | Bűnügyi személyes adatok kezelése magánvádló általThe controller unlawfully transferred the complainant's criminal personal data, breaching the principles of lawful and fair processing and purpose limitation. The authority also found no legal basis for processing under the GDPR. | HU | NAIH | GDPR | €825 | ↗ |
| 03 Dec 2021 | GARLEX SOLUTIONS, S.L.GARLEX SOLUTIONS, S.L. was fined by the AEPD 15,000 EUR for processing personal data without consent. The case concerned an unsolicited contract offer for electricity supply. | ES | AEPD | GDPR | €15,000 | ↗ |
| 06 Dec 2021 | Telekom România Communications SAANSPDCP completed an investigation into Telekom România Communications SA in November 2021 and imposed a fine for GDPR violations. The case concerned deficiencies identified during the supervisory authority’s review. | RO | ANSPDCP | GDPR | €1,000 | ↗ |
| 06 Dec 2021 | Telekom România Communications SAANSPDCP completed an investigation into Telekom România Communications SA in November 2021. As a result, a fine of EUR 5,000 was imposed for GDPR violations. | RO | ANSPDCP | GDPR | €5,000 | ↗ |
| 06 Dec 2021 | Societatea Civilă Medicală Policlinica TommedANSPDCP completed an investigation at Societatea Civilă Medicală Policlinica Tommed and found breaches of GDPR provisions. The operator was fined and required to align data collection and processing activities with data protection requirements to prevent unauthorized disclosure of personal data. | RO | ANSPDCP | GDPR | €2,000 | ↗ |
| 07 Dec 2021 | Minister van FinanciënThe Dutch Data Protection Authority imposed a fine on the Minister of Finance for unlawfully processing the nationality data of Dutch citizens in the Toeslagen system without a legal basis. The conduct breached the GDPR and national data protection laws. | NL | AP | GDPR | €2,750,000 | ↗ |
| 09 Dec 2021 | RESTAURANTE FUENTEBRO, S.C.The entity was fined for operating a video surveillance system without the required informational signage. The authority found this to be a breach of Article 13 GDPR. | ES | AEPD | GDPR | €1,500 | ↗ |
| 09 Dec 2021 | ***COMUNIDAD.1The entity installed surveillance cameras in a community property without proper authorization from all owners. The authority found this to be a breach of data protection rules. | ES | AEPD | GDPR | €1,500 | ↗ |
| 09 Dec 2021 | Limerick City and County CouncilThe Irish DPC imposed a fine of EUR 110,000 on Limerick City and County Council in inquiry 03/SIU/2018. The penalty has been collected. | IE | DPC | GDPR | €110,000 | ↗ |
| 13 Dec 2021 | SC Nobiotic Pharma SRLSC Nobiotic Pharma SRL was fined €2,000 by ANSPDCP for failing to respond to information requests. The authority treated this as a breach of GDPR obligations. | RO | ANSPDCP | GDPR | €2,000 | ↗ |
| 14 Dec 2021 | MALAGATROM, S.L.UMALAGATROM, S.L.U was fined by the AEPD in the amount of EUR 1,000 for failing to comply with a prior decision. That decision required the removal of comments containing personal data from its Amazon page and the implementation of measures to prevent similar incidents in the future. | ES | AEPD | GDPR | €1,000 | ↗ |
| 15 Dec 2021 | Anonymisé (CNPD decision-48-fr-2021)The company did not comply with GDPR requirements on data minimization and on providing information to data subjects, including employees and third parties, in connection with its video surveillance system. CNPD imposed a fine of 11,600 EUR. | LU | CNPD | GDPR | €11,600 | ↗ |
| 15 Dec 2021 | Anonymizováno (ÚOOÚ UOOU-01071/21-30)The entity was fined by the UOOU for repeatedly sending unsolicited commercial communications to electronic contacts without prior consent. The messages also failed to clearly identify the sender or label the content as commercial. | CZ | UOOU | ePrivacy | €11,871 | ↗ |
| 15 Dec 2021 | GrindrNorway's Datatilsynet imposed an administrative fine of NOK 65 million on Grindr on 15.12.2021. The case concerned violations of the GDPR consent requirements. | NO | Datatilsynet | GDPR | €6,355,000 | ↗ |
| 16 Dec 2021 | FCA Italy s.p.a.FCA Italy s.p.a. was fined 20,000 EUR by the Garante for breaching GDPR provisions on the right of access and transparency obligations. The case arose from a complaint by an English citizen about the handling of their personal data. | IT | Garante | GDPR | €20,000 | ↗ |
| 16 Dec 2021 | Ubi Banca S.p.a., ora Intesa Sanpaolo S.p.a.Ubi Banca S.p.a., now Intesa Sanpaolo S.p.a., was fined EUR 100,000 by the Italian Garante. The breach involved sending a letter with the phrase “credito anomalo Chieti” visible on the envelope, which could disclose the recipient’s financial information to third parties. | IT | Garante | GDPR | €100,000 | ↗ |
| 16 Dec 2021 | Frederiksberg KommuneFrederiksberg Kommune was fined by Datatilsynet for failing to implement adequate security measures in a self-service solution. This led to unauthorized access to protected personal data. | DK | Datatilsynet | GDPR | €6,724 | ↗ |