BULLETIN №082Last updated · 03 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 13 May 2021 | Artemisia s.p.a.Artemisia s.p.a. was fined EUR 100,000 by the Garante for GDPR breaches in data processing. The violations concerned consent, information notices, and the handling of health data. | IT | Garante | GDPR | €100,000 | ↗ |
| 13 May 2021 | Synlab Med srlSynlab Med srl was fined EUR 20,000 by the Garante. The authority found that personal data were improperly transmitted to an entity not competent to process them, breaching the principles of data minimization and integrity. | IT | Garante | GDPR | €20,000 | ↗ |
| 13 May 2021 | ATS di Bergamo, Agenzia di Tutela della saluteATS di Bergamo was fined by the Garante 20,000 EUR for violations involving the improper handling of sensitive health data. The case concerned the use of email to transmit data, which did not provide an adequate level of protection. | IT | Garante | GDPR | €20,000 | ↗ |
| 13 May 2021 | Iren Mercato S.p.A.Iren Mercato S.p.A. was fined by the Garante for processing personal data for marketing purposes without proper consent. The company also contacted individuals listed in the public opposition register. | IT | Garante | GDPR | €2,856,000 | ↗ |
| 13 May 2021 | Agenzia di Tutela della Salute della Città metropolitana di MilanoAgenzia di Tutela della Salute della Città metropolitana di Milano was fined by the Garante 80,000 EUR for violations linked to data processing during an emergency. The authority found inadequate data protection measures and a failure to provide required information to data subjects. | IT | Garante | GDPR | €80,000 | ↗ |
| 12 May 2021 | A. EPILOGI IDIOTIKI KEFALAIOUCHIKI ETAIREIAThe company was fined by the HDPA 5,000 EUR for sending unsolicited promotional emails without consent. The authority also found that it failed to respond to data subject access requests and did not provide a valid opt-out address for communications. | GR | HDPA | GDPR | €5,000 | ↗ |
| 12 May 2021 | Anonymisé (CNPD decision-17-fr-2021)The CNPD found that the company breached GDPR principles by failing to comply with data minimization and retention limits in its video surveillance practices. A fine of EUR 1,900 was imposed. | LU | CNPD | GDPR | €1,900 | ↗ |
| 12 May 2021 | Locatefamily.comLocatefamily.com was fined for failing to appoint an EU representative, in breach of GDPR Article 27. The authority also imposed a penalty payment because the violation remained unresolved. | NL | AP | GDPR | €525,000 | ↗ |
| 12 May 2021 | xy d.o.o.The company xy d.o.o. was fined by AZOP for failing to implement appropriate technical security measures. This resulted in unauthorized processing of personal data of 28,085 data subjects, indicating a data protection compliance failure. | HR | AZOP | GDPR | €30,553 | ↗ |
| 12 May 2021 | E4LEGAL ANALYTICS, S.L. (EMÉRITA LEGAL)E4LEGAL ANALYTICS, S.L. was fined by the AEPD EUR 3,100,000 for processing personal data from judicial sentences without proper authorization. The case concerned the reuse of data in a way that may have breached data protection rules and restrictions on further use. | ES | AEPD | GDPR | €3,100,000 | ↗ |
| 12 May 2021 | Anonymisé (CNPD decision-14-fr-2021)The company was fined by the CNPD in the amount of 2,600 EUR for breaching GDPR requirements on data minimization, data retention, and information obligations. The case concerned non-compliant personal data processing and a failure to provide the required information to data subjects. | LU | CNPD | GDPR | €2,600 | ↗ |
| 12 May 2021 | KARIERA A.E.The company was fined for failing to comply with data subjects' requests to delete personal data. As a result, unsolicited email communications continued. | GR | HDPA | GDPR | €5,000 | ↗ |
| 12 May 2021 | Anonymisé (CNPD decision-16-fr-2021)The company was fined for failing to comply with the data minimization principle and for not providing adequate information to data subjects under GDPR Articles 5(1)(c) and 13. The CNPD decision indicates deficiencies in the company’s processing practices and privacy disclosures. | LU | CNPD | GDPR | €1,000 | ↗ |
| 12 May 2021 | Anonymisé (CNPD decision-15-fr-2021)The CNPD imposed a EUR 2,900 fine for breaching the data minimization principle in connection with video surveillance. The camera’s field of view covered areas that were not necessary for the processing purpose, contrary to Article 5(1)(c) GDPR. | LU | CNPD | GDPR | €2,900 | ↗ |
| 11 May 2021 | Érintetti jog és tájékoztatási kötelezettség megsértéseThe case concerned unlawful processing of personal data in connection with debt collection. The entity failed to respond to data subject requests and unlawfully transferred personal data. | HU | NAIH | GDPR | €1,395 | ↗ |
| 11 May 2021 | Stichting Ondersteuning Provinciale Fractie Overijssel Partij voor de Vrijheid (PVV Overijssel)PVV Overijssel was fined by the AP EUR 7,500 for failing to report a personal data breach within the required 72-hour period. The case concerns a delayed notification to the supervisory authority about a security incident. | NL | AP | GDPR | €7,500 | ↗ |
| 11 May 2021 | Norges idrettsforbundThe Norwegian DPA fined Norges idrettsforbund 1,250,000 NOK for insufficient security measures during testing. As a result, personal data of 3.2 million individuals was exposed online for 87 days. | NO | Datatilsynet | GDPR | €124,000 | ↗ |
| 10 May 2021 | VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD for processing personal data without proper consent, in breach of Article 6(1) GDPR. The penalty was set at EUR 70,000, with reductions available for early payment and acknowledgment of responsibility. | ES | AEPD | GDPR | €70,000 | ↗ |
| 07 May 2021 | B.B.B.The entity was fined for improperly directing surveillance cameras toward public transit areas and the complainant's home entrance. This conduct breached data protection rules. | ES | AEPD | GDPR | €1,500 | ↗ |
| 06 May 2021 | Ferde ASThe Norwegian DPA notified Ferde AS of a NOK 5 million fine for unlawfully transferring personal data of Norwegian motorists to China without a valid legal basis. The case concerns non-compliant processing and cross-border transfer of personal data outside the EEA. | NO | Datatilsynet | GDPR | €497,000 | ↗ |