BULLETIN №082Last updated · 02 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 13 Dec 2021 | SC Nobiotic Pharma SRLSC Nobiotic Pharma SRL was fined €2,000 by ANSPDCP for failing to respond to information requests. The authority treated this as a breach of GDPR obligations. | RO | ANSPDCP | GDPR | €2,000 | ↗ |
| 09 Dec 2021 | RESTAURANTE FUENTEBRO, S.C.The entity was fined for operating a video surveillance system without the required informational signage. The authority found this to be a breach of Article 13 GDPR. | ES | AEPD | GDPR | €1,500 | ↗ |
| 09 Dec 2021 | ***COMUNIDAD.1The entity installed surveillance cameras in a community property without proper authorization from all owners. The authority found this to be a breach of data protection rules. | ES | AEPD | GDPR | €1,500 | ↗ |
| 09 Dec 2021 | Limerick City and County CouncilThe Irish DPC imposed a fine of EUR 110,000 on Limerick City and County Council in inquiry 03/SIU/2018. The penalty has been collected. | IE | DPC | GDPR | €110,000 | ↗ |
| 07 Dec 2021 | Minister van FinanciënThe Dutch Data Protection Authority imposed a fine on the Minister of Finance for unlawfully processing the nationality data of Dutch citizens in the Toeslagen system without a legal basis. The conduct breached the GDPR and national data protection laws. | NL | AP | GDPR | €2,750,000 | ↗ |
| 06 Dec 2021 | Telekom România Communications SAANSPDCP completed an investigation into Telekom România Communications SA in November 2021 and imposed a fine for GDPR violations. The case concerned deficiencies identified during the supervisory authority’s review. | RO | ANSPDCP | GDPR | €1,000 | ↗ |
| 06 Dec 2021 | Telekom România Communications SAANSPDCP completed an investigation into Telekom România Communications SA in November 2021. As a result, a fine of EUR 5,000 was imposed for GDPR violations. | RO | ANSPDCP | GDPR | €5,000 | ↗ |
| 06 Dec 2021 | Societatea Civilă Medicală Policlinica TommedANSPDCP completed an investigation at Societatea Civilă Medicală Policlinica Tommed and found breaches of GDPR provisions. The operator was fined and required to align data collection and processing activities with data protection requirements to prevent unauthorized disclosure of personal data. | RO | ANSPDCP | GDPR | €2,000 | ↗ |
| 03 Dec 2021 | MEDIOS DE PREVENCIÓN EXTERNOS, S.L.The entity was fined for sending unsolicited advertising emails despite requests to cancel the subscription. This conduct breached rules on electronic commercial communications. | ES | AEPD | ePrivacy | €2,000 | ↗ |
| 03 Dec 2021 | Bűnügyi személyes adatok kezelése magánvádló általThe controller unlawfully transferred the complainant's criminal personal data, breaching the principles of lawful and fair processing and purpose limitation. The authority also found no legal basis for processing under the GDPR. | HU | NAIH | GDPR | €825 | ↗ |
| 03 Dec 2021 | GARLEX SOLUTIONS, S.L.GARLEX SOLUTIONS, S.L. was fined by the AEPD 15,000 EUR for processing personal data without consent. The case concerned an unsolicited contract offer for electricity supply. | ES | AEPD | GDPR | €15,000 | ↗ |
| 02 Dec 2021 | Casa di cura Fondazione Gaetano e Piera Borghi s.r.l.The Garante imposed a EUR 30,000 fine on Casa di cura Fondazione Gaetano e Piera Borghi s.r.l. for inadequate data protection measures. The authority found insufficient password security and no HTTPS protocol, affecting patient health data. | IT | Garante | GDPR | €30,000 | ↗ |
| 02 Dec 2021 | Teaching CouncilThe Irish DPC fined Teaching Council EUR 60,000 in inquiry IN-20-4-1. The fine has been collected. | IE | DPC | GDPR | €60,000 | ↗ |
| 02 Dec 2021 | Società Med Store Saronno s.r.l.The Garante fined Società Med Store Saronno s.r.l. EUR 7,000 for inadequate data protection measures. The authority found insufficient password security and no HTTPS protocol, affecting personal health data. | IT | Garante | GDPR | €7,000 | ↗ |
| 02 Dec 2021 | La Duomo S.r.l.s.La Duomo S.r.l.s. was fined EUR 20,000 by the Garante for sending unsolicited promotional SMS messages without valid consent. The authority found that the company’s conduct breached data protection rules. | IT | Garante | GDPR | €20,000 | ↗ |
| 02 Dec 2021 | Ica s.r.l.Ica s.r.l. was fined by the Garante EUR 30,000 for failing to implement adequate security measures in its online traffic-fine payment service. The weakness allowed unauthorized access to the personal data of fined citizens. | IT | Garante | GDPR | €30,000 | ↗ |
| 02 Dec 2021 | Azienda USL di ParmaAzienda USL di Parma was fined by the Garante for a data breach involving the unauthorized disclosure of health data. The incident affected one individual and did not result in significant harm, but it was still treated as a GDPR violation. | IT | Garante | GDPR | €5,000 | ↗ |
| 02 Dec 2021 | Omnia 24 S.r.l.Omnia 24 S.r.l. was fined EUR 100,000 by the Garante for sending unsolicited promotional SMS messages without proper consent. The authority found that the company’s conduct breached data protection rules. | IT | Garante | GDPR | €100,000 | ↗ |
| 01 Dec 2021 | GrindrThe Norwegian DPA, Datatilsynet, fined Grindr NOK 65 million for sharing user data with third parties for marketing purposes without a legal basis. The authority found a breach of GDPR consent requirements. | NO | Datatilsynet | GDPR | €6,360,000 | ↗ |
| 01 Dec 2021 | Dane anonimowe (P. Sp. z o.o. z siedzibą we W. przy ul.)The UODO imposed an administrative fine of PLN 18,192 on P. Sp. z o.o. The case concerned a breach of applicable rules that resulted in an administrative sanction. | PL | UODO | GDPR | €3,931 | ↗ |