BULLETIN №082Last updated · 02 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 06 Oct 2021 | Telefónica de España, S.A.U.Telefónica de España, S.A.U. was fined by the AEPD EUR 15,000 for sending commercial emails without meeting the requirements of Article 21 of the LSSI. The authority noted that the messages were sent despite the recipient's objection. | ES | AEPD | ePrivacy | €15,000 | ↗ |
| 06 Oct 2021 | Anonymisé (CNPD decision-35-fr-2021)The company was fined by the CNPD in the amount of 5,300 EUR for breaching GDPR requirements. The authority found that it failed to provide adequate information to data subjects and did not comply with the data minimization principle. | LU | CNPD | GDPR | €5,300 | ↗ |
| 04 Oct 2021 | AD735 DATA MEDIA ADVERTISING S.L.The entity was fined by the AEPD for breaching data protection rules. It continued sending commercial emails despite repeated requests from the complainant to delete their data. | ES | AEPD | ePrivacy | €6,000 | ↗ |
| 04 Oct 2021 | LA ÚLTIMA HORA NOTICIAS, S.L.LA ÚLTIMA HORA NOTICIAS, S.L. was fined by the AEPD EUR 2,000 for installing cookies on users’ devices without prior consent. The authority also found that the website did not provide adequate information about the cookies used. | ES | AEPD | ePrivacy | €2,000 | ↗ |
| 04 Oct 2021 | ENDESA ENERGÍA, S.A.U.ENDESA ENERGÍA, S.A.U. was fined by the AEPD 50,000 EUR for breaching GDPR data accuracy principles. The case involved identity theft and false documentation in a request to transfer an electricity contract. | ES | AEPD | GDPR | €50,000 | ↗ |
| 04 Oct 2021 | SAKBO SPAIN, S.L.SAKBO SPAIN, S.L. was fined by the AEPD in the amount of 5,000 EUR for sending unsolicited commercial emails without recipient consent. The conduct breached Article 21 of the LSSI governing electronic marketing communications. | ES | AEPD | ePrivacy | €5,000 | ↗ |
| 29 Sept 2021 | dott.ssa Manuela MazzoliThe Garante imposed a fine of 2,000 EUR on dott.ssa Manuela Mazzoli for breaches of data protection rules. The case concerned the processing of personal data in the healthcare sector, including the principles of lawfulness, fairness, and transparency. | IT | Garante | GDPR | €2,000 | ↗ |
| 29 Sept 2021 | Solera Italia s.r.l.Solera Italia s.r.l. was fined EUR 10,000 by the Garante for continuing to use an employee's email account after the employment ended. The authority found that the company did not provide proper information about this processing. | IT | Garante | GDPR | €10,000 | ↗ |
| 29 Sept 2021 | Kræftens BekæmpelseKræftens Bekæmpelse was fined by Datatilsynet 75,000 DKK for inadequate protection of sensitive health data. The incident affected at least 1,448 individuals and resulted from missing security measures that allowed unauthorized access to personal data. | DK | Datatilsynet | GDPR | €10,086 | ↗ |
| 29 Sept 2021 | GEDI News Network S.p.A.GEDI News Network S.p.A. was fined 30,000 EUR by the Garante for publishing personal data and detailed information about an individual involved in a workplace accident. The authority found a breach of data protection rules. | IT | Garante | GDPR | €30,000 | ↗ |
| 29 Sept 2021 | K-city srlK-city srl was fined by the Italian Garante in the amount of 5,000 EUR for breaching data protection principles. The case concerned the management of a paid parking service for the Municipality of Formia, where compliance with lawfulness, fairness, and transparency was not ensured. | IT | Garante | GDPR | €5,000 | ↗ |
| 29 Sept 2021 | Prefettura - Ufficio Territoriale del Governo di GenovaPrefettura - Ufficio Territoriale del Governo di Genova was fined by the Garante for publishing personal data on its institutional website. The conduct breached GDPR requirements on lawful processing and protection of personal data. | IT | Garante | GDPR | €11,000 | ↗ |
| 29 Sept 2021 | Comune di FormiaComune di Formia was fined for processing personal data linked to parking subscription services without providing adequate information to data subjects. The authority also found excessive data collection and a failure to clearly define the role of the external data processor. | IT | Garante | GDPR | €30,000 | ↗ |
| 27 Sept 2021 | Сиела Норма АДThe CPDP found that Сиела Норма АД violated the GDPR by inaccurately processing personal data. The error led to an individual being misidentified as a liquidator of companies, and a fine of 5,000 BGN was imposed. | BG | CPDP | GDPR | €2,557 | ↗ |
| 27 Sept 2021 | B.B.B.The entity was fined by the AEPD for operating a video surveillance system without proper informational signage. The system also captured footage beyond the intended purpose, including public transit areas. | ES | AEPD | GDPR | €1,500 | ↗ |
| 24 Sept 2021 | B.B.B.The entity was fined for operating a video surveillance system aimed at public and private spaces without sufficient justification. The authority found this to be a breach of data protection rules. | ES | AEPD | GDPR | €2,500 | ↗ |
| 23 Sept 2021 | TELEFÓNICA MÓVILES ESPAÑA, S.A.U.TELEFÓNICA MÓVILES ESPAÑA, S.A.U. was fined by the AEPD EUR 1,000,000 for failing to adequately prevent unauthorized SIM card duplication. The breach enabled access to confidential information and caused financial losses for customers. | ES | AEPD | GDPR | €1,000,000 | ↗ |
| 17 Sept 2021 | Mediterranean Hospital of CyprusMediterranean Hospital of Cyprus was fined 10,000 EUR by the CyDPC for failing to comply with a data access request. The authority also found a lack of cooperation with the supervisory authority, constituting a breach of Article 31 GDPR. | CY | CyDPC | GDPR | €10,000 | ↗ |
| 16 Sept 2021 | Farpa s.r.l.Farpa s.r.l. was fined by the Garante 1,000 EUR for failing to provide proper information to data subjects, including workers, about the processing of personal data through a video surveillance system. The authority found that the information duty toward affected individuals was not met adequately. | IT | Garante | GDPR | €1,000 | ↗ |
| 16 Sept 2021 | Barilla G. e R. fratelli S.p.A.Barilla G. e R. fratelli S.p.A. was fined by the Garante EUR 75,000 for violations linked to the use of a video surveillance system at its operational site. The system did not comply with data protection requirements. | IT | Garante | GDPR | €75,000 | ↗ |