BULLETIN №082Last updated · 02 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 29 Jun 2021 | Anonymisé (CNPD decision-24-fr-2021)The company was fined EUR 17,000 by the CNPD for breaching the data minimization principle and for failing to provide adequate information to data subjects. The deficiencies concerned employees and third parties in relation to processing activities. | LU | CNPD | GDPR | €17,000 | ↗ |
| 28 Jun 2021 | ELEGA ENERGÍA, S.L.ELEGA ENERGÍA, S.L. was fined EUR 2,000 by the AEPD for failing to provide information about cookies and for not obtaining user consent before placing them. The authority found a breach of Article 22.2 of the LSSI. | ES | AEPD | ePrivacy | €2,000 | ↗ |
| 24 Jun 2021 | NEXTGEN FINANCIAL SERVICES S.L.NEXTGEN FINANCIAL SERVICES S.L. failed to update the address in a loan contract and did not correct inaccurate data in a credit file. The AEPD found this to be a breach of the right to data rectification and imposed a fine of 50,000 EUR. | ES | AEPD | GDPR | €50,000 | ↗ |
| 24 Jun 2021 | Comune di FiscianoComune di Fisciano was fined EUR 1,000 by the Garante for improper handling of personal data. The data were removed after the complaint, and the case concerned transparency and data protection obligations. | IT | Garante | GDPR | €1,000 | ↗ |
| 24 Jun 2021 | B.B.B.The entity was fined by the AEPD EUR 1,000 for installing a surveillance camera in a hair salon without informing individuals about the video surveillance area. The authority found this to be a breach of Article 13 of the GDPR. | ES | AEPD | GDPR | €1,000 | ↗ |
| 24 Jun 2021 | BAZTANDIS, S.L.BAZTANDIS, S.L. was fined EUR 1,000 by the AEPD for deficiencies in signage related to video surveillance. The authority found a breach of Article 13 GDPR concerning the information duties owed to individuals under surveillance. | ES | AEPD | GDPR | €1,000 | ↗ |
| 24 Jun 2021 | Comune di Cogollo del CengioThe Municipality of Comune di Cogollo del Cengio was fined by the Garante 1,000 EUR for unlawfully publishing personal data related to a disciplinary procedure. The authority found no legal basis for the disclosure and held that it breached the principles of lawfulness, fairness, and transparency. | IT | Garante | GDPR | €1,000 | ↗ |
| 24 Jun 2021 | Moss kommuneMoss kommune was fined 500,000 NOK by Datatilsynet for insufficiently securing personal data during the merger of IT systems after the merger of Rygge and Moss municipalities. The violations included incorrect vaccine registrations and unauthorized access to patient data. | NO | Datatilsynet | GDPR | €49,145 | ↗ |
| 24 Jun 2021 | Istituto Professionale per i servizi commerciali e turistici “G. Ravizza” di NovaraThe Istituto Professionale per i servizi commerciali e turistici “G. Ravizza” in Novara was fined by the Garante EUR 2,000. The authority found breaches of data protection principles, including lawfulness, fairness, transparency, and data minimization. | IT | Garante | GDPR | €2,000 | ↗ |
| 24 Jun 2021 | Soluzione Tasse S.p.A.Soluzione Tasse S.p.A. was fined by the Garante 30,000 EUR for sending unsolicited emails without proper consent. The case concerned GDPR principles on data processing and transparency. | IT | Garante | GDPR | €30,000 | ↗ |
| 24 Jun 2021 | Ospedale Pediatrico Bambino GesùOspedale Pediatrico Bambino Gesù was fined by the Garante 15,000 EUR for breaches involving a data incident and improper handling of patient health data. The authority cited violations of GDPR Articles 5 and 32 on lawful processing and security of personal data. | IT | Garante | GDPR | €15,000 | ↗ |
| 23 Jun 2021 | Lakcímadat helyesbítése szolgáltató általThe NAIH imposed a fine of HUF 1,000,000 for breaching the accuracy principle and the right to rectification. The controller failed to correct inaccurate personal data despite a request from the data subject. | HU | NAIH | GDPR | €2,860 | ↗ |
| 22 Jun 2021 | VirksomhetenThe Norwegian DPA fined Virksomheten NOK 150,000 for accessing a former employee’s email account without a legal basis and for failing to close the account. The authority found breaches of GDPR rules on information duties, data deletion, and handling objections. | NO | Datatilsynet | GDPR | €14,678 | ↗ |
| 21 Jun 2021 | GSMA LTD.GSMA LTD. was fined by the AEPD for requiring biometric data, including passport details and photos, for facial recognition at the Mobile World Congress without a valid legal basis. The authority found a breach of data protection rules. | ES | AEPD | GDPR | €200,000 | ↗ |
| 21 Jun 2021 | DKN.5131.3.2021StatusprawomocnaTytuUODO imposed an administrative fine of PLN 159,176 on an insurance company. The authority found that the company failed to notify the President of UODO of a personal data breach within the required timeframe. | PL | UODO | GDPR | €35,116 | ↗ |
| 21 Jun 2021 | Storstockholms Lokaltrafik, SLStorstockholms Lokaltrafik, SL was fined by IMY for using body-worn cameras without a legal basis. The authority found breaches of the GDPR principles of lawfulness, transparency, and data minimization. | SE | IMY | GDPR | €1,566,000 | ↗ |
| 18 Jun 2021 | DESPACHO TEJEDOR INFANTES CONSULTORES ASESORES, S.L.The entity unlawfully disclosed personal data to a third party, breaching the confidentiality principle under GDPR. The AEPD imposed a fine of 2,000 EUR. | ES | AEPD | GDPR | €2,000 | ↗ |
| 18 Jun 2021 | Kiskorúra vonatkozó egészségügyi adatok közlése országos híradásbanThe authority found that the respondent disclosed the complainant’s personal data and special-category health data without a lawful basis. Several GDPR provisions were breached, and a fine of HUF 5,000,000 was imposed. | HU | NAIH | GDPR | €14,050 | ↗ |
| 18 Jun 2021 | STAROFSERVICE SASSTAROFSERVICE SAS was fined by the AEPD 3,000 EUR for sending advertising emails without the recipient's consent. This conduct breached Article 21 of the LSSI. | ES | AEPD | ePrivacy | €3,000 | ↗ |
| 18 Jun 2021 | IZA OBRAS Y PROMOCIONES, S.A.IZA OBRAS Y PROMOCIONES, S.A. was fined by the AEPD 50,000 EUR for disclosing an employee’s health data and personal email address without consent. The authority treated this as a breach of data protection rules. | ES | AEPD | GDPR | €50,000 | ↗ |