BULLETIN №082Last updated · 02 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 16 Feb 2022 | Anonymisé (CNPD decision-04-fr-2022)The CNPD found that the companies failed to meet the Article 13 GDPR information obligation toward data subjects, including employees and third parties. The breach concerned the lack of proper notice about data processing activities. | LU | CNPD | GDPR | €3,100 | ↗ |
| 15 Feb 2022 | ASOCIACIÓN DE AFICIONADOS Y PEQUEÑOS ACCIONISTAS UNIDAD HERCULANAThe organization was fined by the AEPD 3,000 EUR for failing to provide a privacy policy compliant with Article 13 of the GDPR on its website. It collected personal data through various forms but did not provide the required information to data subjects. | ES | AEPD | GDPR | €3,000 | ↗ |
| 15 Feb 2022 | EMPRESA.1The company was fined EUR 300 by the AEPD for improperly orienting surveillance cameras toward public spaces without prior authorization. The conduct breached data protection rules. | ES | AEPD | GDPR | €300 | ↗ |
| 15 Feb 2022 | Organismos Limenos Irakleiou A.E.Organismos Limenos Irakleiou A.E. was fined 30,000 EUR by the HDPA for breaching the data subject’s right of access. The company failed to provide requested video footage and incorrectly claimed that the data had been deleted. | GR | HDPA | GDPR | €30,000 | ↗ |
| 14 Feb 2022 | COMERCIALIZADORA REGULADA, GAS & POWER, S.A.The company sent a customer's electricity supply contract containing personal data to an incorrect address. This breached data protection principles and led to a fine by the AEPD. | ES | AEPD | GDPR | €100,000 | ↗ |
| 12 Feb 2022 | VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined 70,000 EUR by the AEPD for a data protection breach involving unauthorized SIM card duplication and an attempted line takeover. The authority found a violation of GDPR Article 6(1). | ES | AEPD | GDPR | €70,000 | ↗ |
| 11 Feb 2022 | Etterforsker1 Gruppen ASEtterforsker1 Gruppen AS was fined NOK 50,000 by Datatilsynet for conducting a credit assessment of an individual without a legal basis. The assessment was carried out on behalf of a client who claimed to have a compensation claim against the complainant. | NO | Datatilsynet | GDPR | €4,964 | ↗ |
| 11 Feb 2022 | MOVALIA TRASLADOS, S.L.U.MOVALIA TRASLADOS, S.L.U. was fined EUR 2,000 by the AEPD for failing to allow users to give free and voluntary consent for data processing. The authority also found that the company did not properly inform affected individuals about the processing of their data, in breach of GDPR and LOPDGDD requirements. | ES | AEPD | GDPR | €2,000 | ↗ |
| 10 Feb 2022 | Istituto Nazionale di StatisticaIstituto Nazionale di Statistica was fined €6,000 by the Garante for breaches of data protection rules. The case concerned inadequate security measures and data processing practices that did not meet compliance requirements. | IT | Garante | GDPR | €6,000 | ↗ |
| 10 Feb 2022 | Regione ToscanaRegione Toscana was fined by the Garante EUR 10,000 for failing to implement adequate security measures, which resulted in a data breach. The breach was mitigated by the region’s prompt response to reduce the negative effects on affected individuals. | IT | Garante | GDPR | €10,000 | ↗ |
| 10 Feb 2022 | Costampress S.p.A.Costampress S.p.A. was fined EUR 10,000 by the Garante for failing to take required steps after employment ended. The company did not delete the former employee’s email account or transfer the phone number, which breached GDPR requirements. | IT | Garante | GDPR | €10,000 | ↗ |
| 10 Feb 2022 | Comune di GuidizzoloComune di Guidizzolo was fined for publishing a complainant’s personal data, including name and professional qualification, in a public document without proper justification. The authority found a breach of the principles of lawfulness, fairness, and transparency. | IT | Garante | GDPR | €2,000 | ↗ |
| 10 Feb 2022 | Név2.The controller unlawfully processed and published personal data, including images, without consent, breaching multiple GDPR provisions. NAIH imposed a fine of 10,000,000 HUF. | HU | NAIH | GDPR | €28,200 | ↗ |
| 09 Feb 2022 | BANCO BILBAO VIZCAYA ARGENTARIA, S.A.The bank was fined by the AEPD for unlawfully processing personal data and for failing to provide access to personal data requested by a former client. The case concerns non-compliance with data protection obligations. | ES | AEPD | GDPR | €140,000 | ↗ |
| 08 Feb 2022 | Budapest Bank Zrt.Budapest Bank Zrt. was fined by NAIH for improper personal data processing related to the analysis of recorded phone conversations. The authority found violations of several GDPR provisions. | HU | NAIH | GDPR | €707,000 | ↗ |
| 07 Feb 2022 | JIMBO NETWORKS, S.L.JIMBO NETWORKS, S.L. was fined by the AEPD for unlawful processing of personal data obtained from emails and for cookie policy violations on its website. The authority found that users were not properly informed and that valid consent was not obtained where required. | ES | AEPD | GDPR | €15,000 | ↗ |
| 07 Feb 2022 | IBERIA LÍNEAS AÉREAS DE ESPAÑA, S.A.Iberia was fined €30,000 by the AEPD for using non-essential cookies on its website without obtaining prior user consent. The case concerns non-compliance with cookie consent rules and related user information requirements. | ES | AEPD | ePrivacy | €30,000 | ↗ |
| 07 Feb 2022 | DESPACHO IBERFORO MADRID SLPDESPACHO IBERFORO MADRID SLP was fined EUR 1,000 by the AEPD for failing to comply with a decision concerning the right to erasure. The authority found a breach of Article 58(2) GDPR. | ES | AEPD | GDPR | €1,000 | ↗ |
| 04 Feb 2022 | CORON ISLAND SLUCORON ISLAND SLU was fined by the AEPD 2,000 EUR for requiring a customer’s phone number when issuing an invoice. The authority found that the data was not necessary for invoicing, which breached the data minimization principle. | ES | AEPD | GDPR | €2,000 | ↗ |
| 03 Feb 2022 | B.B.B.The entity was fined by the AEPD 600 EUR for operating a surveillance camera system that excessively recorded private and public areas. The authority found that this infringed personal and family privacy. | ES | AEPD | GDPR | €600 | ↗ |