BULLETIN №082Last updated · 02 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 03 Nov 2021 | B.B.B.The entity was fined by the AEPD 10,000 EUR for publishing the complainant's phone number on a website without consent. This led to unwanted calls, and despite requests for removal, the number reappeared, breaching GDPR Article 6. | ES | AEPD | GDPR | €10,000 | ↗ |
| 02 Nov 2021 | Közterület megfigyelése magánszemély általThe case concerned unlawful processing of personal data through surveillance cameras installed on a property. The authority found breaches of GDPR Articles 5, 6, and 13 and imposed a fine of HUF 50,000 on the controller. | HU | NAIH | GDPR | €139 | ↗ |
| 02 Nov 2021 | MYHERITAGE, LTDMYHERITAGE, LTD was fined EUR 20,000 by the AEPD for international data transfers without adequate safeguards and for unclear legal grounds for processing. The authority also found insufficient information provided to data subjects and improper handling of genetic data. | ES | AEPD | ePrivacy | €20,000 | ↗ |
| 01 Nov 2021 | IKEA ROMÂNIA SAIKEA ROMÂNIA SA was fined EUR 1,000 by ANSPDCP for compromising data confidentiality. The case concerned processing practices that were not compliant with GDPR and could affect data subjects’ rights. | RO | ANSPDCP | GDPR | €1,000 | ↗ |
| 28 Oct 2021 | Anfiteatro Flavio s.r.l.Anfiteatro Flavio s.r.l. was fined EUR 2,000 by the Garante for operating a video surveillance system without the required privacy notice. The authority found a breach of Article 13 of the GDPR. | IT | Garante | GDPR | €2,000 | ↗ |
| 28 Oct 2021 | Società LARCSocietà LARC was fined EUR 8,000 by the Garante for violations related to the processing of health data. The authority found non-compliance with GDPR requirements in the handling of these data. | IT | Garante | GDPR | €8,000 | ↗ |
| 28 Oct 2021 | OTTO s.r.l.OTTO s.r.l. was fined by the Italian data protection authority, Garante, in the amount of 2,000 EUR. The case concerned a video surveillance system operated without the required privacy notice, which constitutes a breach of Article 13 GDPR. | IT | Garante | GDPR | €2,000 | ↗ |
| 28 Oct 2021 | dott.ssa GiglioA doctor was fined for improperly handling personal data, including medical prescriptions. The authority found breaches of GDPR Articles 5, 9, and 32 on processing principles, special-category data, and security measures. | IT | Garante | GDPR | €10,000 | ↗ |
| 28 Oct 2021 | TPER Trasporto Passeggeri Emilia Romagna S.p.A.TPER Trasporto Passeggeri Emilia Romagna S.p.A. was fined by the Garante EUR 30,000 for violations related to the processing of personal data of call center employees. The case involved potential unauthorized monitoring and insufficient data protection measures. | IT | Garante | GDPR | €30,000 | ↗ |
| 27 Oct 2021 | ImportőrImportőr was fined by the NAIH 5,000,000 HUF for processing personal data without properly informing the data subjects and without a valid legal basis. The authority found breaches of lawfulness, transparency, accountability, and data minimization principles. | HU | NAIH | GDPR | €13,750 | ↗ |
| 27 Oct 2021 | VENTANAS MAKE YOURSELF, S.L.The company was fined by the AEPD EUR 4,000 for not having a privacy policy and a cookie policy on its website. The breach concerned GDPR and LSSI requirements on information provided to users. | ES | AEPD | ePrivacy | €4,000 | ↗ |
| 27 Oct 2021 | Anonymisé (CNPD decision-41-fr-2021)The CNPD imposed a fine of 18,700 EUR on Anonymisé for improper implementation of Data Protection Officer obligations. The company did not publish the DPO’s contact details, did not involve the DPO in all data protection matters, did not ensure the DPO’s autonomy, and did not assign monitoring of GDPR compliance. | LU | CNPD | GDPR | €18,700 | ↗ |
| 26 Oct 2021 | ЧСИ2The Commission fined the private bailiff ЧСИ2 for unlawfully processing personal data by accessing bank account information after the enforcement proceeding had ended. The authority found a breach of the purpose limitation principle under Article 5 GDPR. | BG | CPDP | GDPR | €383 | ↗ |
| 26 Oct 2021 | AMAZON ROAD TRANSPORT SPAIN, S.LAmazon Road Transport Spain, S.L was fined 3,300,000 EUR by the AEPD for requiring job candidates to provide a criminal record certificate and consent for data transfers outside the EEA. The authority found that these practices breached GDPR and LOPDGDD rules on lawful processing and data transfer safeguards. | ES | AEPD | GDPR | €3,300,000 | ↗ |
| 26 Oct 2021 | OPEN BANK, S.A.OPEN BANK, S.A. was fined by the AEPD for using non-essential third-party cookies without prior user consent. The authority also found that the cookies could not be removed, which breached Article 22.2 of the LSSI. | ES | AEPD | ePrivacy | €5,000 | ↗ |
| 25 Oct 2021 | Anonymizováno (ÚOOÚ UOOU-00288/20-21)The entity was fined by the UOOU for sending unsolicited commercial communications by email without prior recipient consent. The conduct breached Czech rules on information society services. | CZ | UOOU | ePrivacy | €1,166 | ↗ |
| 20 Oct 2021 | PLUSVECINOS, S.L.PLUSVECINOS, S.L. was fined by the AEPD in the amount of 3,000 EUR for sending commercial emails without prior consent from recipients. The conduct breached Article 21 of the LSSI. | ES | AEPD | ePrivacy | €3,000 | ↗ |
| 14 Oct 2021 | Azienda per la Tutela della Salute (ATS) della SardegnaAzienda per la Tutela della Salute (ATS) della Sardegna was fined EUR 8,000 by the Garante for improper processing of personal data, including health data. The authority found breaches of GDPR Articles 5 and 9. | IT | Garante | GDPR | €8,000 | ↗ |
| 14 Oct 2021 | Dane anonimowe (Bank Z. S.A.)The Polish DPA (UODO) imposed an administrative fine of PLN 363,832 on Bank Z. S.A. The authority found that the bank failed to notify the supervisory authority of a personal data breach and did not inform the affected individuals. | PL | UODO | GDPR | €79,625 | ↗ |
| 13 Oct 2021 | Anonymisé (CNPD decision-36-fr-2021)The company did not involve the Data Protection Officer in all matters related to personal data protection. CNPD found this breached GDPR Articles 38(1) and 39(1) and imposed a EUR 23,400 fine. | LU | CNPD | GDPR | €23,400 | ↗ |