BULLETIN №083Last updated · 06 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -22.8%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 01 Jan 2022 | MUXERS CONCEPT, S.L.MUXERS CONCEPT, S.L. was fined EUR 20,000 by the AEPD for installing an unauthorized audio recording system in employee areas. The authority found this conduct to be in breach of Article 6 of the GDPR. | ES | AEPD | GDPR | €20,000 | ↗ |
| 01 Jan 2022 | DIGI SPAIN TELECOM, S.L.DIGI SPAIN TELECOM, S.L. was fined by the AEPD 70,000 EUR for unlawfully duplicating a customer's SIM card without consent. The incident led to unauthorized access to the customer's personal and banking data. | ES | AEPD | GDPR | €70,000 | ↗ |
| 01 Jan 2022 | RIANLU EUROPA S.L.RIANLU EUROPA S.L. was fined EUR 30,010 by the AEPD for sending commercial SMS messages without providing recipients with an opt-out mechanism. This conduct breached Article 21 of the LSSI. | ES | AEPD | ePrivacy | €30,010 | ↗ |
| 01 Jan 2022 | INMOBILIARIA MESLLOC, S.L.INMOBILIARIA MESLLOC, S.L. was fined by the AEPD for unlawfully sharing tenants’ personal data with third-party companies without authorization. The authority found this conduct violated Article 6(1) of the GDPR. | ES | AEPD | GDPR | €40,000 | ↗ |
| 04 Jan 2022 | BEAUTY & AESTHETIC BALEARIC, SL.BEAUTY & AESTHETIC BALEARIC, SL. was fined by the AEPD €1,000 for sending marketing emails without an opt-out mechanism. The authority found this to be a breach of Article 21 of the LSSI. | ES | AEPD | ePrivacy | €1,000 | ↗ |
| 05 Jan 2022 | Egnatia Odos S.A.Egnatia Odos S.A. was fined by the HDPA EUR 1,000 for failing to provide the complainant with access to personal data related to a toll violation. The authority found a breach of the right of access under the GDPR. | GR | HDPA | GDPR | €1,000 | ↗ |
| 05 Jan 2022 | CONTIMAG INVEST, S.L.CONTIMAG INVEST, S.L. was fined by the AEPD 1,200 EUR for operating a video surveillance system without the required informational signage. The authority found a breach of Article 13 GDPR on transparency and information duties. | ES | AEPD | GDPR | €1,200 | ↗ |
| 05 Jan 2022 | B.B.B.A camera was installed in a vehicle parked in a community garage and recorded communal areas. The community was not informed and no required signage was displayed, resulting in a breach of data protection rules. | ES | AEPD | GDPR | €1,500 | ↗ |
| 05 Jan 2022 | CARTERA VIVANTA, S.L.U.CARTERA VIVANTA, S.L.U. was fined by the AEPD in the amount of EUR 5,000 for sending commercial SMS messages without the recipient’s consent. The conduct breached Article 21 of the LSSI, which governs unsolicited electronic marketing. | ES | AEPD | ePrivacy | €5,000 | ↗ |
| 06 Jan 2022 | B.B.B.A fine was imposed for the mass dissemination of a video recorded without the victim’s consent on social media and via WhatsApp. The authority found a breach of Article 6(1) GDPR. | ES | AEPD | GDPR | €10,000 | ↗ |
| 07 Jan 2022 | Elektro & Automasjon Systemer ASElektro & Automasjon Systemer AS was fined NOK 200,000 by Datatilsynet for conducting a credit assessment of an individual without a legal basis. The company checked a co-owner of another company despite having no business relationship or justification for the credit check. | NO | Datatilsynet | GDPR | €19,942 | ↗ |
| 07 Jan 2022 | CAIXABANK PAYMENTS & CONSUMER EFC, EP, S.A.U.CAIXABANK PAYMENTS & CONSUMER EFC, EP, S.A.U. was fined by the AEPD EUR 70,000 for including personal data in credit information systems without a proper legal basis. The authority found a breach of Article 6(1) GDPR. | ES | AEPD | GDPR | €70,000 | ↗ |
| 09 Jan 2022 | DIGI SPAIN TELECOM, S.L.DIGI SPAIN TELECOM, S.L. was fined by the AEPD 70,000 EUR for issuing a duplicate SIM card without proper authorization. The incident enabled unauthorized access to a customer's bank account. | ES | AEPD | GDPR | €70,000 | ↗ |
| 13 Jan 2022 | Villa Masi Residenza per anzianiVilla Masi Residenza per anziani was fined EUR 1,000 by the Garante for a video surveillance system that did not comply with GDPR Article 13. The authority found that the required information notices for monitored individuals were not properly provided. | IT | Garante | GDPR | €1,000 | ↗ |
| 13 Jan 2022 | Azienda Sanitaria Locale FrosinoneAzienda Sanitaria Locale Frosinone was fined by the Italian supervisory authority, Garante, in the amount of EUR 7,500. The case concerned breaches of transparency and information duties in personal data processing under GDPR Articles 12 and 13. | IT | Garante | GDPR | €7,500 | ↗ |
| 13 Jan 2022 | Medicina & Lavoro s.r.l.Medicina & Lavoro s.r.l. was fined by the Garante 4,000 EUR for failing to provide an adequate response to a data subject’s request for access to personal data. The authority found a breach of GDPR Article 15. | IT | Garante | GDPR | €4,000 | ↗ |
| 13 Jan 2022 | IBERDROLA CLIENTES, S.A.U.IBERDROLA CLIENTES, S.A.U. was fined EUR 70,000 by the AEPD for changing an electricity supply contract without the customer's knowledge or consent. The authority found that this conduct breached data protection rules. | ES | AEPD | GDPR | €70,000 | ↗ |
| 13 Jan 2022 | ADVANS BROKERS CORREDURIA DE SEGUROS S.L.ADVANS BROKERS CORREDURIA DE SEGUROS S.L. was fined by the AEPD EUR 80,000 for a data breach affecting 55,000 individuals, including minors. The authority found that the incident was reported to the AEPD with delay. | ES | AEPD | GDPR | €80,000 | ↗ |
| 13 Jan 2022 | A.S.L. Napoli 1 CentroA.S.L. Napoli 1 Centro was fined EUR 6,000 by the Garante for breaches of data protection principles. The authority found improper processing of personal data in violation of lawfulness, fairness, transparency, and data minimization requirements. | IT | Garante | GDPR | €6,000 | ↗ |
| 13 Jan 2022 | Azienda sanitaria unica regionale MarcheAzienda sanitaria unica regionale Marche was fined EUR 14,000 by the Garante for inadequate data protection measures. The breach involved health data and was linked to QR code generation; improved security measures were later implemented. | IT | Garante | GDPR | €14,000 | ↗ |