BULLETIN №082Last updated · 03 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 27 May 2021 | Azienda Usl della RomagnaAzienda Usl della Romagna was fined by the Garante in the amount of EUR 120,000 for violations related to the processing of a patient's health data in the gynecology department. The case also involved issues with electronic health records and data breaches. | IT | Garante | GDPR | €120,000 | ↗ |
| 27 May 2021 | Poste Italiane S.p.a.Poste Italiane S.p.a. was fined by the Garante 10,000 EUR for unlawfully communicating a customer's financial data related to a Postepay card to an unauthorized third party. The case concerns a breach of personal data protection and financial confidentiality requirements. | IT | Garante | GDPR | €10,000 | ↗ |
| 27 May 2021 | Società e Salute S.p.a.Società e Salute S.p.a. was fined by the Garante EUR 10,000 for a data breach involving the mishandling of personal data, including health information. The authority found violations of GDPR Articles 5 and 9. | IT | Garante | GDPR | €10,000 | ↗ |
| 27 May 2021 | Società Cavourese S.p.A.Società Cavourese S.p.A. was fined EUR 4,000 by the Italian data protection authority, Garante. The case concerned improper handling of personal data related to employee disciplinary proceedings, in breach of the GDPR and national privacy rules. | IT | Garante | GDPR | €4,000 | ↗ |
| 27 May 2021 | Tempocasa S.p.A.Tempocasa S.p.A. was fined €120,000 by the Italian Garante. The authority found that the company made unsolicited promotional calls without the required consent, breaching GDPR rules on data processing and consent. | IT | Garante | GDPR | €120,000 | ↗ |
| 27 May 2021 | Intesa Sanpaolo s.p.a.Intesa Sanpaolo s.p.a. was fined by the Garante in the amount of 200,000 EUR for unlawfully communicating banking data to an unauthorized third party. The case concerned breaches of data protection principles, including lawfulness and restricted access to information. | IT | Garante | GDPR | €200,000 | ↗ |
| 26 May 2021 | VODAFONE ESPAÑA, S.A.U.The AEPD fined VODAFONE ESPAÑA, S.A.U. 50,000 EUR for sending SMS messages about an alleged debt for services not contracted by the complainant. The case involved incorrect processing of personal data and the use of inaccurate contact details. | ES | AEPD | GDPR | €50,000 | ↗ |
| 21 May 2021 | COOPERA RC SERVICES, S.L.COOPERA RC SERVICES, S.L. was fined by the AEPD 2,000 EUR for failing to provide the contact details needed to exercise data protection rights. The authority found a breach of the information obligations under Article 13 GDPR. | ES | AEPD | GDPR | €2,000 | ↗ |
| 20 May 2021 | B.B.B.The entity did not provide the complainant with information about data processing or the ability to exercise rights after receiving a CV via WhatsApp in response to a job offer. AEPD imposed a fine of EUR 2,000 for breaching transparency obligations. | ES | AEPD | GDPR | €2,000 | ↗ |
| 19 May 2021 | CP&A B.V.CP&A B.V. was fined by the AP in the amount of EUR 15,000 for processing employees' health data without a legal basis. The authority also found that adequate security measures were not implemented for this processing. | NL | AP | GDPR | €15,000 | ↗ |
| 19 May 2021 | Asociație de Proprietari din municipiul IașiThe association was fined EUR 500 by ANSPDCP for failing to provide requested information to the supervisory authority. The breach concerned obligations under the GDPR. | RO | ANSPDCP | GDPR | €500 | ↗ |
| 19 May 2021 | TNT EXPRESS WORLDWIDE SPAIN, S.L.TNT Express Worldwide Spain, S.L. was fined by the AEPD €10,000 for incorrectly linking a personal delivery service to a corporate account. This resulted in the unauthorized sharing of personal data with the complainant’s employer. | ES | AEPD | GDPR | €10,000 | ↗ |
| 17 May 2021 | VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined 5,000 EUR by the AEPD for failing to provide requested information. The case concerns a breach of obligations under data protection rules. | ES | AEPD | GDPR | €5,000 | ↗ |
| 17 May 2021 | Vodafone Servicios, S.L.U.The AEPD fined Vodafone Servicios, S.L.U. 50,000 EUR for processing personal data without proper consent. The breach led to unauthorized charges on a customer's bank account. | ES | AEPD | GDPR | €50,000 | ↗ |
| 17 May 2021 | VODAFONE ESPAÑA, S.A.U.Vodafone España, S.A.U. was fined by the AEPD 80,000 EUR for processing personal data without proper consent. The case involved linking phone lines to incorrect data and enrolling a customer in services without authorization. | ES | AEPD | GDPR | €80,000 | ↗ |
| 17 May 2021 | TELEFÓNICA DE ESPAÑA, S.A.U.Telefónica de España, S.A.U. was fined by the AEPD for using personal data to contract a service without the data subject’s consent and for listing the complainant in credit information files for a debt that was not recognized. The case concerns processing without a valid legal basis and improper reporting of alleged debt. | ES | AEPD | GDPR | €75,000 | ↗ |
| 14 May 2021 | persoană fizicăA natural person was fined EUR 200 by ANSPDCP for violating GDPR requirements. The case concerned breaches related to the processing of personal data. | RO | ANSPDCP | GDPR | €200 | ↗ |
| 14 May 2021 | SIA "SS"DVI imposed a fine of EUR 100,000 on SIA "SS". According to the record, the sanction was later annulled. | LV | DVI | GDPR | €100,000 | ↗ |
| 13 May 2021 | Comune di BolzanoThe Municipality of Bolzano was fined 84,000 EUR by the Garante for improper handling of employee internet navigation data. The authority found that personal data were systematically collected without adequate safeguards and in breach of data protection principles. | IT | Garante | GDPR | €84,000 | ↗ |
| 13 May 2021 | Brico Rida s.r.l.Brico Rida s.r.l. was fined by the Garante in the amount of 2,000 EUR for operating a video surveillance system without the required information notice to data subjects. The authority found a breach of Article 13 GDPR. | IT | Garante | GDPR | €2,000 | ↗ |