BULLETIN №082Last updated · 02 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 04 Aug 2021 | Anonymisé (CNPD decision-29-fr-2021)The CNPD found that the organization did not appoint a Data Protection Officer based on the required professional qualities, did not provide the necessary resources, and did not ensure the DPO's autonomy. This constituted breaches of GDPR Articles 37, 38, and 39. | LU | CNPD | GDPR | €17,700 | ↗ |
| 04 Aug 2021 | Anonymisé (CNPD decision-30-fr-2021)The public establishment failed to communicate the DPO’s contact details to the supervisory authority and did not provide the DPO with the resources needed to perform the role effectively. CNPD found breaches of GDPR Articles 37(7), 38(2), and 39(1)(b) and imposed a fine of 6,600 EUR. | LU | CNPD | GDPR | €6,600 | ↗ |
| 02 Aug 2021 | FUENSANTA S.L.FUENSANTA S.L. was fined by the AEPD in the amount of 3,000 EUR for failing to provide access to information under Article 58.1 of the GDPR. The case concerned non-compliance with information access obligations toward the supervisory authority. | ES | AEPD | GDPR | €3,000 | ↗ |
| 30 Jul 2021 | Amendă pentru încălcarea RGPDA fine of EUR 100 was imposed on an individual for violating GDPR requirements. The case was handled by the Romanian supervisory authority ANSPDCP. | RO | ANSPDCP | GDPR | €100 | ↗ |
| 30 Jul 2021 | Amendă pentru încălcarea RGPDA fine of EUR 100 was imposed on an individual by ANSPDCP for violating GDPR requirements. The case concerned a confirmed breach of personal data protection obligations. | RO | ANSPDCP | GDPR | €100 | ↗ |
| 30 Jul 2021 | Mederos Moviten, S.L.Mederos Moviten, S.L. was fined by the AEPD 15,000 EUR for processing personal data without consent. Several unauthorized contracts were created using the complainant’s personal information, indicating unlawful use of personal data. | ES | AEPD | GDPR | €15,000 | ↗ |
| 27 Jul 2021 | BANCO BILBAO VIZCAYA ARGENTARIA, S.A.The bank was fined for failing to implement adequate security measures to verify the identity of customers accessing sensitive information through an automated phone system. The authority found a breach of data integrity and confidentiality principles. | ES | AEPD | GDPR | €200,000 | ↗ |
| 25 Jul 2021 | CALDERERIA Y SOLDADURA DE ESTRUCTURAS METALICAS, S.L.The company was fined by the AEPD for processing personal data without consent, which breaches Article 6 of the GDPR. The case indicates that no valid legal basis was in place for the processing activity. | ES | AEPD | GDPR | €5,000 | ↗ |
| 25 Jul 2021 | CYNGASA, S.L.CYNGASA, S.L. was fined by the AEPD EUR 5,000 for transferring an employee’s personal data to another company without consent. The authority found this conduct to be a breach of Article 6 of the GDPR. | ES | AEPD | GDPR | €5,000 | ↗ |
| 22 Jul 2021 | Atac s.p.a.Atac s.p.a. was fined by the Garante 400,000 EUR for processing personal data without a specific legal basis and without adequate security measures. The case concerned users of paid parking services in Rome. | IT | Garante | GDPR | €400,000 | ↗ |
| 22 Jul 2021 | Università degli Studi di Milano-BicoccaUniversità degli Studi di Milano-Bicocca was fined EUR 10,000 by the Garante for data protection violations linked to the publication of personal data on its institutional website. The case concerned the disclosure of information on the university’s website, which breached data processing rules. | IT | Garante | GDPR | €10,000 | ↗ |
| 22 Jul 2021 | Azienda sanitaria locale di BariAzienda sanitaria locale di Bari was fined EUR 35,000 by the Garante for failing to adopt minimum security measures. The breach resulted in exposure of health data, creating a significant compliance and privacy risk. | IT | Garante | GDPR | €35,000 | ↗ |
| 22 Jul 2021 | Regione LombardiaRegione Lombardia was fined by the Garante 200,000 EUR for publishing personal data on its website that could reveal individuals' economic and social hardship. The authority found that this breached GDPR transparency and data protection requirements. | IT | Garante | GDPR | €200,000 | ↗ |
| 22 Jul 2021 | Flowbird s.r.l.Flowbird s.r.l. was fined EUR 30,000 by the Garante for processing personal data through parking meters in Rome without a legal basis. The authority also found that the company failed to maintain a record of processing activities. | IT | Garante | GDPR | €30,000 | ↗ |
| 22 Jul 2021 | Regione CalabriaThe Garante imposed a 10,000 EUR fine on Regione Calabria for publishing personal data on its website. The conduct breached GDPR rules on lawful processing and protection of personal data. | IT | Garante | GDPR | €10,000 | ↗ |
| 22 Jul 2021 | Roma CapitaleRoma Capitale was fined EUR 800,000 by the Garante for failing to adequately protect the personal data of motorists using parking meters. The authority also found improper data retention practices, increasing the risk to data subjects. | IT | Garante | GDPR | €800,000 | ↗ |
| 22 Jul 2021 | Azienda sanitaria locale di Chieri, Carmagnola, Moncalieri e Nichelino (Asl To5)Azienda sanitaria locale di Chieri, Carmagnola, Moncalieri e Nichelino (Asl To5) was fined EUR 4,000 by the Garante for violations related to the processing of personal data, including health data, during the COVID-19 pandemic. The case concerned improper handling of sensitive data in the context of pandemic-related activities. | IT | Garante | GDPR | €4,000 | ↗ |
| 22 Jul 2021 | TikTok Inc.TikTok Inc. was fined 750,000 EUR by the Dutch authority AP for providing its privacy policy to users in the Netherlands, including children, only in English. The authority found this breached Article 12 GDPR, which requires information to be provided in a clear and easily accessible form. | NL | AP | GDPR | €750,000 | ↗ |
| 16 Jul 2021 | Region SyddanmarkRegion Syddanmark was fined 500,000 DKK by Datatilsynet for failing to implement appropriate security measures. The vulnerability allowed unauthorized access to sensitive health data of children and was identified and reported by a citizen. | DK | Datatilsynet | GDPR | €67,220 | ↗ |
| 15 Jul 2021 | Anonymisé (CNPD decision-27-fr-2021)The company did not meet GDPR requirements to inform individuals about data processing, especially in relation to video surveillance and employee notices. CNPD treated this as a breach of the information obligations owed to data subjects. | LU | CNPD | GDPR | €3,500 | ↗ |