BULLETIN №083Last updated · 06 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -22.8%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 16 Dec 2021 | Progetto Udire S.r.l.Progetto Udire S.r.l. was fined by the Garante 30,000 EUR. The authority found that the company sent unsolicited marketing communications without proper consent and failed to provide information on the origin of personal data when requested by the data subject. | IT | Garante | GDPR | €30,000 | ↗ |
| 16 Dec 2021 | Enel Energia S.p.a.Enel Energia S.p.a. was investigated for improper promotional contacts, including contacts to individuals with reserved numbers or registered in the ROP. The authority also challenged making access to online services conditional on consent to marketing and profiling. | IT | Garante | GDPR | €26,513,000 | ↗ |
| 16 Dec 2021 | Centro di Medicina preventiva s.r.l.Centro di Medicina preventiva s.r.l. was fined by the Garante 10,000 EUR for failing to implement adequate measures to prevent unauthorized access to personal data. The deficiency resulted in a data breach. | IT | Garante | GDPR | €10,000 | ↗ |
| 16 Dec 2021 | Sindicato Intersectorial Trabajadores/as Provincia de AlicanteThe labor union was fined by the AEPD for breaching data protection rules. The case concerned the publication of committee meeting minutes containing signatures on a union notice board and in a WhatsApp group. | ES | AEPD | GDPR | €2,000 | ↗ |
| 16 Dec 2021 | ASL LatinaASL Latina was fined for violations of data protection rules. The authority found inadequate measures to prevent data breaches involving health data. | IT | Garante | GDPR | €10,000 | ↗ |
| 16 Dec 2021 | LiikennevakuutuskeskusThe entity was fined for collecting patient data excessively for insurance claim resolution. The authority found breaches of data minimization and fairness principles. | FI | TSV | GDPR | €52,000 | ↗ |
| 16 Dec 2021 | Università Telematica Internazionale UninettunoUniversità Telematica Internazionale Uninettuno was fined EUR 1,000 by the Italian supervisory authority Garante. The authority found breaches of lawfulness, fairness, transparency, and data minimization principles. | IT | Garante | GDPR | €1,000 | ↗ |
| 16 Dec 2021 | 1000 Luci Round a BarThe establishment 1000 Luci Round a Bar was fined EUR 1,000 by the Italian authority Garante. The sanction concerned a video surveillance system that did not meet the information requirements of Article 13 GDPR. | IT | Garante | GDPR | €1,000 | ↗ |
| 17 Dec 2021 | Kormánytisztviselő jogviszonyának megszűnésével összefüggésben egészségügyi adat kezelése, és erre irányuló hozzáférés megtagadásaThe authority found that the controller unlawfully denied access to personal data and failed to provide complete information about data processed in connection with the termination of employment. This breached GDPR Articles 12, 14, and 15. | HU | NAIH | GDPR | €1,632 | ↗ |
| 20 Dec 2021 | B.B.B.A video recording showing an individual being assaulted was shared via WhatsApp without that person's consent. The AEPD found a breach of Article 6(1) GDPR. | ES | AEPD | GDPR | €2,000 | ↗ |
| 20 Dec 2021 | INSEKT FOOD S.L.INSEKT FOOD S.L. was fined by the AEPD EUR 4,000 for sharing an individual's personal data in WhatsApp group chats without consent. The authority found that the processing lacked a lawful basis under Article 6 of the GDPR. | ES | AEPD | GDPR | €4,000 | ↗ |
| 22 Dec 2021 | wyżej wymienionąA financial penalty was imposed on an individual conducting business activity for failing to ensure that the President of the Personal Data Protection Office had access to personal data and information necessary to perform his duties. The case concerned obstruction of the supervisory authority’s powers. | PL | UODO | GDPR | €982 | ↗ |
| 22 Dec 2021 | SOS Leukémiás Gyermekekért AlapítványSOS Leukémiás Gyermekekért Alapítvány was fined by NAIH 500,000 HUF for processing personal data without a valid legal basis. The authority also found failures to provide transparent information and to facilitate data subject access rights. | HU | NAIH | GDPR | €1,355 | ↗ |
| 23 Dec 2021 | wyżej wymienionąAn administrative fine was imposed on an individual conducting business activity. The violation consisted of failing to provide the President of the Personal Data Protection Office with access to personal data and information necessary to perform his duties. | PL | UODO | GDPR | €983 | ↗ |
| 23 Dec 2021 | Federación Estatal de Servicios, Movilidad y Consumo de la UGT (FESMC-UGT)FESMC-UGT was fined 2,000 EUR by the AEPD for sending emails to employees’ corporate addresses without proper authorization. The authority found this to be a breach of data protection rules. | ES | AEPD | GDPR | €2,000 | ↗ |
| 31 Dec 2021 | Dane anonimowe (S. Spółka z o.o. z siedzibą w W. przy ul.)The President of UODO imposed an administrative fine of PLN 18,192 on the company. The sanction resulted from failing to provide access to personal data and other information necessary for the authority to perform its duties. | PL | UODO | GDPR | €3,957 | ↗ |
| 01 Jan 2022 | B.B.B.B.B.B. was fined 1,000 EUR by the AEPD. The authority found that the company shared individuals’ personal data in a WhatsApp group without consent, in breach of data protection rules. | ES | AEPD | GDPR | €1,000 | ↗ |
| 01 Jan 2022 | ALPA 57 PRODUCCIONES, S.L.ALPA 57 PRODUCCIONES, S.L. was fined by the AEPD 10,000 EUR for processing personal data without a legal basis. The company impersonated another energy provider and used personal data without consent. | ES | AEPD | GDPR | €10,000 | ↗ |
| 01 Jan 2022 | BOOKSY INTERNATIONAL SPOLKA, S.L.BOOKSY INTERNATIONAL SPOLKA, S.L. was fined by the AEPD €500 for sending unsolicited commercial SMS messages. The recipient was registered on the Robinson List, which constituted a breach of Article 21 of the LSSI. | ES | AEPD | ePrivacy | €500 | ↗ |
| 01 Jan 2022 | CAIXABANK S.A.CaixaBank was fined EUR 25,000 by the AEPD for failing to update a customer's address despite repeated requests. The authority found this to be a breach of the GDPR right to rectification. | ES | AEPD | GDPR | €25,000 | ↗ |