BULLETIN №082Last updated · 04 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 15 Nov 2019 | HM HOSPITALES 1989, S.A.HM HOSPITALES 1989, S.A. was fined by the AEPD 60,000 EUR for sending a patient's medical report to an insurance company without proper consent. The case concerns a breach of data protection rules and the special protection applicable to health data. | ES | AEPD | GDPR | €60,000 | ↗ |
| 02 Mar 2023 | H&M Hennes & Mauritz s.r.l.H&M Hennes & Mauritz s.r.l. was fined EUR 50,000 by the Garante for violations related to installing surveillance systems without the required authorization. Employees were informed about the systems, but this did not cure the underlying compliance breach. | IT | Garante | GDPR | €50,000 | ↗ |
| 17 Oct 2023 | H&M Hennes & MauritzH&M Hennes & Mauritz GBC AB was fined for processing personal data for direct marketing without a lawful basis. The authority also found that the company failed to stop processing after objections were raised, breaching GDPR Articles 6, 12, and 21. | SE | IMY | GDPR | €30,356 | ↗ |
| 18 Apr 2024 | H&M Hennes & MauritzH&M Hennes & Mauritz GBC AB was fined for conducting camera surveillance without a legal basis and for failing to provide required information to data subjects. The authority found breaches of GDPR Articles 6(1) and 13. | SE | IMY | GDPR | €25,779 | ↗ |
| 18 Sept 2014 | History s.a.s.History s.a.s. was fined EUR 2,400 by the Italian data protection authority, Garante. The case concerned failure to provide the required information notice under Article 13 of the Italian Privacy Code when operating a video surveillance system. | IT | Garante | GDPR | €2,400 | ↗ |
| 22 Dec 2023 | HISPAPOST, S.A.HISPAPOST, S.A. was fined EUR 60,000 by the AEPD for failing to properly safeguard and handle personal data. The incident resulted in the abandonment of 1,404 letters containing personal information, indicating inadequate data protection procedures. | ES | AEPD | GDPR | €60,000 | ↗ |
| 11 Jul 2022 | Hírlevekkel kapcsolatos adatkezelésThe entity was fined by NAIH in the amount of HUF 500,000 for processing personal data for direct marketing purposes without a legal basis. The authority also found a lack of transparent information and delayed handling of data subject requests. | HU | NAIH | GDPR | €1,225 | ↗ |
| 05 Jun 2023 | HIPER STORE, S.L.HIPER STORE, S.L. was fined EUR 500 by the AEPD for not properly signposting its video surveillance system. The authority also found that the company failed to provide customers with the required data protection information under Article 13 GDPR. | ES | AEPD | GDPR | €500 | ↗ |
| 19 Dec 2023 | HIPERBAZAR YONGFA 2018 SLHIPERBAZAR YONGFA 2018 SL was fined by the AEPD 5,000 EUR for breaching data protection rules. The case involved the improper sharing of surveillance footage, which was later posted on Facebook, undermining confidentiality and data security requirements. | ES | AEPD | GDPR | €5,000 | ↗ |
| 01 Jan 2024 | HIGHCLIFFE ESTATES MARBELLA, S.L.HIGHCLIFFE ESTATES MARBELLA, S.L. was fined by the AEPD 8,500 EUR for publishing personal data, including names and images, on its website without the data subjects’ consent. The authority found this to be a breach of Article 6(1) GDPR. | ES | AEPD | GDPR | €8,500 | ↗ |
| 12 Feb 2021 | HIGHCLIFFE ESTATES MARBELLA, S.L.The company was fined by the AEPD for not providing a legal notice, privacy policy, or consent checkbox on its website. The authority also found that it used an individual's image without consent, breaching GDPR Articles 13 and 6(1). | ES | AEPD | GDPR | €8,000 | ↗ |
| 19 Feb 2015 | HHHH was fined EUR 2,400 by the Garante for failing to provide an adequate simplified privacy notice for its video surveillance system. The authority found a breach of the Italian Data Protection Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 07 Dec 2023 | H**** Gemeinnützige Wohnungs AGThe entity was fined for failing to cooperate with the Data Protection Authority during a complaint procedure. It did not respond to requests for statements, which constitutes a breach of Article 31 GDPR. | AT | DSB | GDPR | €10,000 | ↗ |
| 26 Sept 2022 | HERON CITY VALENCIA MANAGEMENT S.L.HERON CITY VALENCIA MANAGEMENT S.L. was fined by the AEPD in the amount of 10,000 EUR for refusing to provide access to surveillance footage. This conduct breached the data subject’s rights, in particular the right of access under Article 15 of the GDPR. | ES | AEPD | GDPR | €10,000 | ↗ |
| 21 Oct 2020 | HEREDAD DE UREÑA, S.L.HEREDAD DE UREÑA, S.L. was fined by the AEPD EUR 4,000 for not having a privacy policy on its website, lacking a cookies policy, and sending unsolicited marketing emails without consent. The case indicates failures in basic transparency obligations and consent requirements for electronic communications. | ES | AEPD | GDPR | €4,000 | ↗ |
| 28 Oct 2013 | HERBORISTERÍA TRÉBOL-HIDROLINFA C.B.HERBORISTERÍA TRÉBOL-HIDROLINFA C.B. was fined EUR 600 by the AEPD for sending a commercial email without providing a valid electronic address for recipients to object to the processing of their data for advertising purposes. The authority found a breach of Article 21.2 of the LSSI. | ES | AEPD | ePrivacy | €600 | ↗ |
| 17 Jul 2024 | Hera Comm S.p.A.Hera Comm S.p.A. was fined by the Garante 5,000,000 EUR for processing inaccurate and outdated personal data of customers. This led to the activation of unsolicited energy contracts and insurance policies with forged signatures. | IT | Garante | GDPR | €5,000,000 | ↗ |
| 13 Jun 2025 | HEP - Toplinarstvo d.o.o.HEP - Toplinarstvo d.o.o. was fined EUR 320,000 for failing to implement appropriate technical and organizational measures to protect data in its “Moj račun” application. The authority also found a lack of cooperation with the supervisory authority, including refusal to provide required information. | HR | AZOP | GDPR | €320,000 | ↗ |
| 19 Dec 2025 | HelsaMiNorway’s digital accessibility regulator found 119 accessibility errors at HelsaMi, with 64 issues still unresolved after the initial remediation deadline. The operator was ordered to fix the problems by 2025-12-19 or face a daily penalty of NOK 50,000 until compliance is achieved. | NO | Tilsynet for universell utforming av IKT | EAA | €4,197 | ↗ |
| 28 Feb 2024 | Hellenic Post S.A.Hellenic Post S.A. was fined by the HDPA for insufficient technical and organizational measures to protect data. The deficiencies led to unauthorized access and a data breach. | GR | HDPA | GDPR | €2,995,000 | ↗ |