BULLETIN №083Last updated · 06 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -22.8%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 01 Sept 2020 | Geanonimiseerd (APD 53/2020)A politician was fined for sending an election propaganda email without consent. The authority found unlawful processing of personal data and a failure to implement appropriate technical and organizational measures. | BE | APD | GDPR | €2,000 | ↗ |
| 28 Jul 2020 | Geanonimiseerd (APD 39/2020)The case concerns a complaint about the processing of voters’ personal data during municipal elections. The controller used old electoral lists without a lawful basis, breaching the GDPR principles of purpose limitation and lawfulness. | BE | APD | GDPR | €5,000 | ↗ |
| 15 Mar 2021 | Geanonimiseerd (APD 36/2021)A school used Smartschool to conduct a “well-being” survey among minor students without parental consent. The authority found that several GDPR provisions governing the processing of children’s data were breached. | BE | APD | GDPR | €2,000 | ↗ |
| 14 May 2020 | Geanonimiseerd (APD 25/2020)The APD Litigation Chamber imposed a EUR 50,000 fine on an anonymized social media platform for processing personal data without a valid legal basis. The case involved several GDPR breaches, including data processing principles and consent requirements. | BE | APD | GDPR | €50,000 | ↗ |
| 14 May 2020 | Geanonimiseerd (APD 24/2020)The decision concerns an insurance company that failed to provide sufficient transparency in its privacy policy. It involved the use of health data without explicit consent for purposes beyond hospitalization insurance. | BE | APD | GDPR | €50,000 | ↗ |
| 17 Dec 2024 | Geanonimiseerd (APD 166/2024)The hospital was fined by the APD for failing to carry out a data protection impact assessment and for lacking effective information security policies. These deficiencies contributed to a ransomware incident affecting up to 300,000 individuals. | BE | APD | GDPR | €50,000 | ↗ |
| 23 Aug 2022 | Geanonimiseerd (APD 129/2022)The Litigation Chamber imposed a fine for insufficient technical and organizational measures to protect data security. This led to unauthorized access to personal documents. | BE | APD | GDPR | €2,500 | ↗ |
| 23 Aug 2024 | Geanonimiseerd (APD 107/2024)The APD Litigation Chamber imposed a EUR 5,000 fine for responding to a data subject access request after more than 14 months. The authority found a breach of GDPR Articles 12 and 15, which require timely handling of access rights. | BE | APD | GDPR | €5,000 | ↗ |
| 11 May 2026 | Geanonimiseerd (APD 100/2026)The Litigation Chamber imposed a fine for violations related to camera surveillance at a residential complex. It found a lack of transparency and a failure to properly facilitate data subject rights. | BE | APD | GDPR | €5,000 | ↗ |
| 17 Sept 2019 | Geanonimiseerd (APD 06/2019)The case concerned a complaint about the use of electronic identity cards to create customer cards. The Litigation Chamber found breaches of data minimization, lawful basis for processing, and information duties under the GDPR, and imposed a fine of EUR 10,000. | BE | APD | GDPR | €10,000 | ↗ |
| 28 May 2019 | Geanonimiseerd (APD 04/2019)The APD Litigation Chamber imposed a EUR 2,000 fine for using email addresses collected for urban planning purposes to send election propaganda by a mayor. The authority found a breach of the GDPR purpose limitation principle. | BE | APD | GDPR | €2,000 | ↗ |
| 29 Oct 2020 | Gaypa s.r.l.Gaypa s.r.l. was fined EUR 20,000 by the Garante for continuing to use a personalized email account of a former employee after the employment ended. The authority found this conduct inconsistent with GDPR principles of lawfulness and purpose limitation. | IT | Garante | GDPR | €20,000 | ↗ |
| 28 Nov 2022 | GAVANOVA DE IMMOBLES, S.L.GAVANOVA DE IMMOBLES, S.L. was fined by the AEPD 2,000 EUR for failing to provide an adequate privacy policy on its website. The authority also found that personal data was shared with a cleaning company without the data subjects’ consent. | ES | AEPD | GDPR | €2,000 | ↗ |
| 19 May 2025 | GATIGOS, S.L.GATIGOS, S.L. was fined EUR 6,000 by the AEPD for failing to provide access to personal data and the information requested by the data protection authority. The authority found a breach of Article 58(1) GDPR. | ES | AEPD | GDPR | €6,000 | ↗ |
| 20 Mar 2012 | GAS NATURAL S.U.R. SDG S.A.GAS NATURAL S.U.R. SDG S.A. was fined EUR 1,800 by the AEPD for continuing to send commercial emails to a complainant after they had requested that such communications stop. The authority found this to be a breach of Article 21 of the LSSI. | ES | AEPD | ePrivacy | €1,800 | ↗ |
| 01 Jan 2024 | GASEXPRESS PATRAIX, S.L.GASEXPRESS PATRAIX, S.L. was fined by the AEPD 25,000 EUR for allowing unauthorized access to previous users' data in its automated gas station system. The exposed information included DNI numbers and partial credit card numbers. | ES | AEPD | GDPR | €25,000 | ↗ |
| 03 Dec 2021 | GARLEX SOLUTIONS, S.L.GARLEX SOLUTIONS, S.L. was fined by the AEPD 15,000 EUR for processing personal data without consent. The case concerned an unsolicited contract offer for electricity supply. | ES | AEPD | GDPR | €15,000 | ↗ |
| 19 Mar 2026 | GarðabærGarðabær was fined for multiple data protection violations in its use of Google Workspace for Education without ensuring GDPR compliance. The case concerned the processing of children's personal data, which required additional safeguards and a proper legal basis. | IS | Persónuvernd | GDPR | €17,425 | ↗ |
| 02 Dec 2019 | GARANTIZA AUTOMOCIÓN, S.L.The company was fined by the AEPD in the amount of EUR 3,000 for failing to provide information or obtain consent for the use of cookies on its website. The breach concerned LSSI requirements on transparency and user consent. | ES | AEPD | ePrivacy | €3,000 | ↗ |
| 18 Dec 2024 | GAOLANIA SERVICIOS, S.L.GAOLANIA SERVICIOS, S.L. was fined EUR 30,000 by the AEPD for breaching the GDPR data accuracy principle under Article 5(1)(d). The authority found a lack of diligence in handling data errors. | ES | AEPD | GDPR | €30,000 | ↗ |