BULLETIN №082Last updated · 02 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 14 Jul 2021 | LABORATORIOS GONZÁLEZ, S.L.LABORATORIOS GONZÁLEZ, S.L. was fined by the AEPD 20,000 EUR for sharing an employee’s COVID-19 antibody test result with the employee’s superior without consent. The authority found this to be a breach of data protection rules. | ES | AEPD | GDPR | €20,000 | ↗ |
| 14 Jul 2021 | Anonymised (HDPA 31/2021)The fined individual unlawfully obtained and processed personal data from the complainant's personnel file. The data came from an unauthorized source and were used in a complaint against the complainant, in breach of data protection rules. | GR | HDPA | GDPR | €2,000 | ↗ |
| 13 Jul 2021 | Dane anonimowe (Prezesa Sądu Rejonowego w M. za naruszenie art. 5 ust. 1 lit. f), art. 25 ust. 1, art. 32 ust. 1 lit. b) i d) oraz art. 32 ust. 2 rozporządzenia 2016/679)UODO imposed a fine of PLN 10,000 on the President of the District Court for failing to implement appropriate technical and organizational measures. The authority found that the security level did not match the risk associated with processing data using portable external storage devices. | PL | UODO | GDPR | €2,189 | ↗ |
| 12 Jul 2021 | A.A.A.The entity was fined for processing personal data through a video surveillance system without appropriate security measures and without the required informational signage. The authority found a breach of Article 13 GDPR. | ES | AEPD | GDPR | €1,000 | ↗ |
| 12 Jul 2021 | B.B.B.B.B.B. was fined by the AEPD EUR 1,200 for operating a video surveillance system without proper signage. The case involved a breach of GDPR Article 13, and a new camera was installed despite prior warnings without correcting the deficiencies. | ES | AEPD | GDPR | €1,200 | ↗ |
| 09 Jul 2021 | ORANGE ESPAGNE, S.A.U.ORANGE ESPAGNE, S.A.U. was fined 50,000 EUR by the AEPD for failing to implement adequate security measures. The deficiency led to unauthorized bank transfers from a customer's account after a SIM card incident. | ES | AEPD | GDPR | €50,000 | ↗ |
| 09 Jul 2021 | Medicals Nordic I/SMedicals Nordic I/S was fined by Datatilsynet for inadequate security measures when processing sensitive health data related to COVID-19 tests. The authority also noted the use of WhatsApp for data transmission without proper access controls. | DK | Datatilsynet | GDPR | €53,788 | ↗ |
| 08 Jul 2021 | Consiglio Regionale della Valle d’AostaConsiglio Regionale della Valle d’Aosta was fined EUR 1,000 by the Garante for failing to remove personal data from its website after a request. The authority found this to be a breach of data protection rights. | IT | Garante | GDPR | €1,000 | ↗ |
| 08 Jul 2021 | Azienda ospedaliero-universitaria SeneseAzienda ospedaliero-universitaria Senese was fined by the Garante 25,000 EUR for violations related to data breaches involving health data and patient information. The case concerned the handling of sensitive data and required assessment of compliance with data protection obligations. | IT | Garante | GDPR | €25,000 | ↗ |
| 08 Jul 2021 | Regione PugliaThe Garante fined Regione Puglia EUR 30,000 for the unlawful dissemination of personal health data on the web. The authority found breaches of lawfulness, fairness, transparency, and data minimization principles. | IT | Garante | GDPR | €30,000 | ↗ |
| 07 Jul 2021 | Nordbornholms Byggeforretning ApSNordbornholms Byggeforretning ApS was fined 100,000 DKK by Datatilsynet. The company unlawfully disclosed information about a former employee's criminal activities to customers without a legal basis. | DK | Datatilsynet | GDPR | €13,448 | ↗ |
| 07 Jul 2021 | Uitvoeringsinstituut werknemersverzekeringen (UWV)UWV was fined by the AP for failing to ensure an adequate level of security for personal data. The deficiencies led to multiple breaches involving sensitive information of job seekers. | NL | AP | GDPR | €450,000 | ↗ |
| 07 Jul 2021 | Anonymizováno (ÚOOÚ UOOU-04873/20-24)The entity was fined for unlawfully publishing personal data on YouTube. The authority found a breach of GDPR principles of lawfulness, fairness, and transparency. | CZ | UOOU | GDPR | €117 | ↗ |
| 05 Jul 2021 | Anonymisoitu (TSV 943)The controller unlawfully processed employees' location data, breaching the GDPR principles of data minimization and lawfulness. The case concerned processing that went beyond what was necessary for the stated purpose. | FI | TSV | GDPR | €25,000 | ↗ |
| 05 Jul 2021 | FUTURE VINLINE SLFUTURE VINLINE SL was fined by the AEPD EUR 10,000 for not having an adequate privacy policy on its website. The authority found that the company failed to provide clear and complete information about data processing under Article 13 GDPR. | ES | AEPD | GDPR | €10,000 | ↗ |
| 04 Jul 2021 | VODAFONE ESPAÑA, S.A.U.The AEPD fined VODAFONE ESPAÑA, S.A.U. EUR 70,000 for allowing a third party to contract phone numbers using another individual's identity. The case concerns a breach of data protection rules and inadequate identity verification. | ES | AEPD | GDPR | €70,000 | ↗ |
| 02 Jul 2021 | PODEMOS PARTIDO POLÍTICOPODEMOS PARTIDO POLÍTICO was fined by the AEPD for irregularities in its video surveillance system. The cameras excessively captured public space without justification, and proper signage was missing. | ES | AEPD | GDPR | €4,000 | ↗ |
| 01 Jul 2021 | A.A.A.The entity was fined by the AEPD 1,000 EUR for operating a video surveillance system without proper informational signage and customer information forms. The authority found this to be a breach of Article 13 of the GDPR. | ES | AEPD | GDPR | €1,000 | ↗ |
| 01 Jul 2021 | UNIVERSIDAD A DISTANCIA DE MADRID, S.A.UNIVERSIDAD A DISTANCIA DE MADRID, S.A. was fined by the AEPD for failing to comply with a request to delete personal data. As a result, the individual received unsolicited marketing emails, indicating a breach of data protection obligations. | ES | AEPD | GDPR | €5,000 | ↗ |
| 30 Jun 2021 | Dane anonimowe (Fundację)UODO imposed a PLN 13,644 administrative fine on the Foundation for failing to report a personal data breach without undue delay. The Foundation also did not notify the affected individuals about the incident, breaching controller obligations. | PL | UODO | GDPR | €3,018 | ↗ |