BULLETIN №082Last updated · 02 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 22 Dec 2021 | wyżej wymienionąA financial penalty was imposed on an individual conducting business activity for failing to ensure that the President of the Personal Data Protection Office had access to personal data and information necessary to perform his duties. The case concerned obstruction of the supervisory authority’s powers. | PL | UODO | GDPR | €982 | ↗ |
| 22 Dec 2021 | SOS Leukémiás Gyermekekért AlapítványSOS Leukémiás Gyermekekért Alapítvány was fined by NAIH 500,000 HUF for processing personal data without a valid legal basis. The authority also found failures to provide transparent information and to facilitate data subject access rights. | HU | NAIH | GDPR | €1,355 | ↗ |
| 20 Dec 2021 | B.B.B.A video recording showing an individual being assaulted was shared via WhatsApp without that person's consent. The AEPD found a breach of Article 6(1) GDPR. | ES | AEPD | GDPR | €2,000 | ↗ |
| 20 Dec 2021 | INSEKT FOOD S.L.INSEKT FOOD S.L. was fined by the AEPD EUR 4,000 for sharing an individual's personal data in WhatsApp group chats without consent. The authority found that the processing lacked a lawful basis under Article 6 of the GDPR. | ES | AEPD | GDPR | €4,000 | ↗ |
| 17 Dec 2021 | Kormánytisztviselő jogviszonyának megszűnésével összefüggésben egészségügyi adat kezelése, és erre irányuló hozzáférés megtagadásaThe authority found that the controller unlawfully denied access to personal data and failed to provide complete information about data processed in connection with the termination of employment. This breached GDPR Articles 12, 14, and 15. | HU | NAIH | GDPR | €1,632 | ↗ |
| 16 Dec 2021 | FCA Italy s.p.a.FCA Italy s.p.a. was fined 20,000 EUR by the Garante for breaching GDPR provisions on the right of access and transparency obligations. The case arose from a complaint by an English citizen about the handling of their personal data. | IT | Garante | GDPR | €20,000 | ↗ |
| 16 Dec 2021 | Ubi Banca S.p.a., ora Intesa Sanpaolo S.p.a.Ubi Banca S.p.a., now Intesa Sanpaolo S.p.a., was fined EUR 100,000 by the Italian Garante. The breach involved sending a letter with the phrase “credito anomalo Chieti” visible on the envelope, which could disclose the recipient’s financial information to third parties. | IT | Garante | GDPR | €100,000 | ↗ |
| 16 Dec 2021 | Frederiksberg KommuneFrederiksberg Kommune was fined by Datatilsynet for failing to implement adequate security measures in a self-service solution. This led to unauthorized access to protected personal data. | DK | Datatilsynet | GDPR | €6,724 | ↗ |
| 16 Dec 2021 | Progetto Udire S.r.l.Progetto Udire S.r.l. was fined by the Garante 30,000 EUR. The authority found that the company sent unsolicited marketing communications without proper consent and failed to provide information on the origin of personal data when requested by the data subject. | IT | Garante | GDPR | €30,000 | ↗ |
| 16 Dec 2021 | Enel Energia S.p.a.Enel Energia S.p.a. was investigated for improper promotional contacts, including contacts to individuals with reserved numbers or registered in the ROP. The authority also challenged making access to online services conditional on consent to marketing and profiling. | IT | Garante | GDPR | €26,513,000 | ↗ |
| 16 Dec 2021 | Centro di Medicina preventiva s.r.l.Centro di Medicina preventiva s.r.l. was fined by the Garante 10,000 EUR for failing to implement adequate measures to prevent unauthorized access to personal data. The deficiency resulted in a data breach. | IT | Garante | GDPR | €10,000 | ↗ |
| 16 Dec 2021 | Sindicato Intersectorial Trabajadores/as Provincia de AlicanteThe labor union was fined by the AEPD for breaching data protection rules. The case concerned the publication of committee meeting minutes containing signatures on a union notice board and in a WhatsApp group. | ES | AEPD | GDPR | €2,000 | ↗ |
| 16 Dec 2021 | ASL LatinaASL Latina was fined for violations of data protection rules. The authority found inadequate measures to prevent data breaches involving health data. | IT | Garante | GDPR | €10,000 | ↗ |
| 16 Dec 2021 | LiikennevakuutuskeskusThe entity was fined for collecting patient data excessively for insurance claim resolution. The authority found breaches of data minimization and fairness principles. | FI | TSV | GDPR | €52,000 | ↗ |
| 16 Dec 2021 | Università Telematica Internazionale UninettunoUniversità Telematica Internazionale Uninettuno was fined EUR 1,000 by the Italian supervisory authority Garante. The authority found breaches of lawfulness, fairness, transparency, and data minimization principles. | IT | Garante | GDPR | €1,000 | ↗ |
| 16 Dec 2021 | 1000 Luci Round a BarThe establishment 1000 Luci Round a Bar was fined EUR 1,000 by the Italian authority Garante. The sanction concerned a video surveillance system that did not meet the information requirements of Article 13 GDPR. | IT | Garante | GDPR | €1,000 | ↗ |
| 15 Dec 2021 | Anonymisé (CNPD decision-48-fr-2021)The company did not comply with GDPR requirements on data minimization and on providing information to data subjects, including employees and third parties, in connection with its video surveillance system. CNPD imposed a fine of 11,600 EUR. | LU | CNPD | GDPR | €11,600 | ↗ |
| 15 Dec 2021 | Anonymizováno (ÚOOÚ UOOU-01071/21-30)The entity was fined by the UOOU for repeatedly sending unsolicited commercial communications to electronic contacts without prior consent. The messages also failed to clearly identify the sender or label the content as commercial. | CZ | UOOU | ePrivacy | €11,871 | ↗ |
| 15 Dec 2021 | GrindrNorway's Datatilsynet imposed an administrative fine of NOK 65 million on Grindr on 15.12.2021. The case concerned violations of the GDPR consent requirements. | NO | Datatilsynet | GDPR | €6,355,000 | ↗ |
| 14 Dec 2021 | MALAGATROM, S.L.UMALAGATROM, S.L.U was fined by the AEPD in the amount of EUR 1,000 for failing to comply with a prior decision. That decision required the removal of comments containing personal data from its Amazon page and the implementation of measures to prevent similar incidents in the future. | ES | AEPD | GDPR | €1,000 | ↗ |