BULLETIN №082Last updated · 04 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 13 May 2015 | HellastatHellastat was fined by the HDPA EUR 5,000 for the illegal collection and use of data. The case concerned a breach of data protection laws. | GR | HDPA | GDPR | €5,000 | ↗ |
| 13 May 2015 | HellastatHellastat was fined EUR 3,000 by the HDPA for failing to inform data subjects. The authority found a breach of data protection rules requiring transparent notice to individuals. | GR | HDPA | GDPR | €3,000 | ↗ |
| 03 May 2022 | HEI – Medical TravelHEI – Medical Travel was fined ISK 1,500,000 by Persónuvernd for unlawfully collecting, recording, storing, and using email addresses without consent. The company also mishandled an access request by deleting personal data after the request had been made. | IS | Persónuvernd | GDPR | €10,905 | ↗ |
| 17 Feb 2025 | Heilsugæsla höfuðborgarsvæðisinsHeilsugæsla höfuðborgarsvæðisins was fined ISK 5,000,000 by Persónuvernd. The authority found that the organization unlawfully merged its medical records system with those of other entities, breaching GDPR requirements on lawful data processing. | IS | Persónuvernd | GDPR | €34,050 | ↗ |
| 20 Aug 2024 | HEBERGEUR DE SITE WEB (procédure simplifiée)The CNIL imposed an administrative fine of 8,000 EUR on HEBERGEUR DE SITE WEB under a simplified procedure. The decision concerns a confirmed breach of rules supervised by the CNIL. | FR | CNIL | GDPR | €8,000 | ↗ |
| 23 Oct 2025 | Hearst Magazines Italia S.p.A.Hearst Magazines Italia S.p.A. was fined EUR 20,000 by the Garante for publishing personal data relating to an individual's health without a legal basis. The authority found a breach of the principles of lawfulness and fairness in processing. | IT | Garante | GDPR | €20,000 | ↗ |
| 09 May 2024 | HEADBLUE MARKETING, S.L.HEADBLUE MARKETING, S.L. was fined by the AEPD in the amount of 1,000 EUR for sending unsolicited commercial electronic communications without consent. The authority also found a failure to respond to access requests. | ES | AEPD | ePrivacy | €1,000 | ↗ |
| 15 Apr 2021 | HAZTEOIR.ORGThe association HazteOir.Org was fined EUR 5,000 by the AEPD for including images and names of individuals in a pamphlet without their consent. The authority found this to be a breach of data protection rules. | ES | AEPD | GDPR | €5,000 | ↗ |
| 20 Dec 2022 | HAYS PERSONNEL SERVICE ESPAÑA, S.A.HAYS PERSONNEL SERVICE ESPAÑA, S.A. was fined by the AEPD 5,000 EUR for sending marketing emails without the recipient’s consent. The conduct breached Article 21 of the LSSI, which requires prior consent for such communications. | ES | AEPD | ePrivacy | €5,000 | ↗ |
| 12 Mar 2015 | Hayat KhizerHayat Khizer was fined EUR 3,000 by the Garante for improper registration of SIM cards. The cards were used by persons other than the formal registrants in connection with a criminal investigation into drug trafficking. | IT | Garante | GDPR | €3,000 | ↗ |
| 06 Sept 2023 | Háskóli ÍslandsThe University of Iceland was fined for inadequate signage and insufficient information about electronic surveillance on its premises. The authority found a breach of GDPR transparency and information obligations. | IS | Persónuvernd | GDPR | €10,425 | ↗ |
| 08 Mar 2022 | Harpa tónlistar- og ráðstefnuhús ohf.Harpa tónlistar- og ráðstefnuhús ohf. was fined by Persónuvernd for collecting personal identification numbers and birth dates without necessity. The authority found breaches of GDPR principles of lawfulness, fairness, transparency, and data minimization. | IS | Persónuvernd | GDPR | €6,850 | ↗ |
| 01 Jan 2016 | HAPPY SOCIAL MEDIA, LTDHAPPY SOCIAL MEDIA, LTD was fined by the AEPD EUR 3,400 for sending unsolicited marketing emails. The authority found that the messages did not include a simple opt-out mechanism, which breached the LSSI. | ES | AEPD | ePrivacy | €3,400 | ↗ |
| 25 Apr 2016 | HAPPY SOCIAL MEDIA LTDHAPPY SOCIAL MEDIA LTD was fined by the AEPD in the amount of 1,400 EUR. The case concerned unsolicited marketing emails sent without a simple opt-out mechanism, in breach of the LSSI. | ES | AEPD | ePrivacy | €1,400 | ↗ |
| 25 Apr 2016 | HAPPY SOCIAL MEDIA LTDHAPPY SOCIAL MEDIA LTD was fined EUR 1,400 by the AEPD. The case concerned sending unsolicited commercial emails without providing a simple and free opt-out mechanism, in breach of the LSSI. | ES | AEPD | ePrivacy | €1,400 | ↗ |
| 01 Jan 2017 | Happy Social Media LTD.Happy Social Media LTD. was fined by the AEPD EUR 2,000 for sending advertising emails to individuals who had opted out of receiving them. The case concerned Article 21.1 of the LSSI and the obligation to respect objections to marketing communications. | ES | AEPD | ePrivacy | €2,000 | ↗ |
| 02 Apr 2020 | HAPPY FRIDAY, S.L.HAPPY FRIDAY, S.L. was fined by the AEPD in the amount of 2,500 EUR for failing to comply with data protection rules on the use of cookies. The authority found that the company did not provide the required information or obtain user consent. | ES | AEPD | ePrivacy | €2,500 | ↗ |
| 11 Sept 2014 | Happy Fit s.r.l.Happy Fit s.r.l. was fined by the Garante in the amount of EUR 16,400 for making an unsolicited promotional phone call. The company did not provide the required information or obtain consent, breaching data protection rules. | IT | Garante | GDPR | €16,400 | ↗ |
| 17 Dec 2025 | HAN University of Applied SciencesThe Autoriteit Persoonsgegevens announced on 17 December 2025 that it had imposed a fine on HAN University of Applied Sciences. According to the notice, the university was hacked in September 2021, resulting in a data breach, and HAN will not object to the decision. | NL | Autoriteit Persoonsgegevens | GDPR | €100,000 | ↗ |
| 04 Feb 2016 | Hans Christoph Josef DietrichHans Christoph Josef Dietrich was fined EUR 4,000 by the Garante. The case concerned the public display of a list of patients who had not paid for medical services, which amounted to unauthorized disclosure of personal data. | IT | Garante | GDPR | €4,000 | ↗ |