BULLETIN №082Last updated · 04 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 27 Apr 2021 | B.B.B.B.B.B. was fined 500 EUR by the AEPD for installing a surveillance camera. The camera captured common areas and a neighbor's parking space, which breached data protection rules. | ES | AEPD | GDPR | €500 | ↗ |
| 23 Apr 2021 | Vodafone España, S.A.U.Vodafone España, S.A.U. was fined by the AEPD 70,000 EUR for processing personal data without proper consent. The case involved a call to a customer about a service package that the customer had not authorized. | ES | AEPD | GDPR | €70,000 | ↗ |
| 23 Apr 2021 | Vodafone España, S.A.U.The AEPD fined Vodafone España, S.A.U. EUR 70,000 for failing to adequately prevent identity theft. As a result, unauthorized phone line contracts were entered into using a customer's personal data. | ES | AEPD | GDPR | €70,000 | ↗ |
| 23 Apr 2021 | VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD 50,000 EUR for changing a customer's mobile line ownership without consent. The company also charged the customer's account amounts related to a third party's phone line. | ES | AEPD | GDPR | €50,000 | ↗ |
| 23 Apr 2021 | FRIGORIFICA BOTANA, S.L.FRIGORIFICA BOTANA, S.L. was fined by the AEPD EUR 4,000 for disproportionate audio/video recording in a meeting room without a justified cause or proper notice. The authority found this breached data protection principles. | ES | AEPD | GDPR | €4,000 | ↗ |
| 23 Apr 2021 | VODAFONE SERVICIOS, S.L.U.Vodafone Servicios, S.L.U. was fined by the AEPD 50,000 EUR for failing to verify a customer's identity. The lapse enabled identity fraud and the unauthorized creation of an account. | ES | AEPD | GDPR | €50,000 | ↗ |
| 23 Apr 2021 | B.B.B.The entity was fined for operating a video surveillance system at the workplace without informing employees through the required informational signage. The authority found this to be a breach of Article 13 GDPR. | ES | AEPD | GDPR | €1,000 | ↗ |
| 23 Apr 2021 | Vodafone España, S.A.U.Vodafone España, S.A.U. was fined by the AEPD EUR 70,000 for allowing unauthorized access to a customer's personal data. The data was then used to fraudulently contract mobile lines without the customer's consent. | ES | AEPD | GDPR | €70,000 | ↗ |
| 23 Apr 2021 | VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD 50,000 EUR for changing a customer's tariff without consent. The case involved identity impersonation and improper processing of personal data under the GDPR. | ES | AEPD | GDPR | €50,000 | ↗ |
| 23 Apr 2021 | Vodafone España, S.A.U.Vodafone España, S.A.U. was fined EUR 70,000 by the AEPD after a third party gained unauthorized access to a customer account. The incident led to changes in personal data and services without the customer’s consent. | ES | AEPD | GDPR | €70,000 | ↗ |
| 22 Apr 2021 | DKN.5130.3114.2020StatusnieprawomocnaTytuUODO imposed an administrative fine of PLN 1,136,975. The authority found that the entity failed to implement appropriate technical and organizational measures to secure personal data processed in cooperation with a courier service provider. | PL | UODO | GDPR | €249,000 | ↗ |
| 22 Apr 2021 | Magyar ÁllamkincstárThe Hungarian National Authority for Data Protection and Freedom of Information (NAIH) fined Magyar Államkincstár HUF 1,000,000. The authority found a breach of GDPR lawfulness and data minimization principles because personal data were transferred without a proper legal basis. | HU | NAIH | GDPR | €2,750 | ↗ |
| 21 Apr 2021 | Fondazione Policlinico Tor Vergata di RomaFondazione Policlinico Tor Vergata di Roma was fined by the Garante 15,000 EUR for breaches of data processing principles. The case concerned compliance with lawfulness, fairness, transparency, and security measures. | IT | Garante | GDPR | €15,000 | ↗ |
| 21 Apr 2021 | Ministero dell’Istruzione, dell’Università e della Ricerca, Ufficio Scolastico Regionale per la Toscana, Ufficio VIII Ambito territoriale della provincia di LivornoThe Italian Ministry of Education was fined 3,000 EUR by the Garante. The case concerned personal data of teachers remaining accessible online in breach of GDPR principles of lawfulness, fairness, transparency, and data minimization. | IT | Garante | GDPR | €3,000 | ↗ |
| 21 Apr 2021 | Isinc S.r.l.s.Isinc S.r.l.s. was fined 20,000 EUR by the Garante for sending promotional emails using personal data taken from public databases without proper consent. The authority found this conduct to be in breach of GDPR Article 5. | IT | Garante | GDPR | €20,000 | ↗ |
| 21 Apr 2021 | Azienda provinciale per i servizi sanitari di TrentoAzienda provinciale per i servizi sanitari di Trento was fined by the Garante EUR 40,000 for violations related to the processing of health data. The authority found omissions in implementing technical and organizational measures for access to the health dossier. | IT | Garante | GDPR | €40,000 | ↗ |
| 21 Apr 2021 | Società Eurosanità s.p.a.Società Eurosanità s.p.a. was fined by the Garante in the amount of 5,000 EUR for a breach involving the processing of health data. The authority found violations of GDPR Articles 5 and 9, indicating improper handling of special category personal data. | IT | Garante | GDPR | €5,000 | ↗ |
| 21 Apr 2021 | ParkkiPateThe Finnish Data Protection Ombudsman fined ParkkiPate EUR 70,000 for GDPR violations. The case concerned data minimization, identification of data subjects, and the handling of access rights. | FI | TSV | GDPR | €70,000 | ↗ |
| 20 Apr 2021 | RIUSA II, S.ARIUSA II, S.A was fined by the AEPD 5,000 EUR for not providing users with the option to reject or configure cookies on its website. The authority treated this as a breach of data protection rules. | ES | AEPD | ePrivacy | €5,000 | ↗ |
| 20 Apr 2021 | Elszámoltathatóság elvének megsértéseThe entity was fined by the NAIH for breaching the accountability principle and failing to implement appropriate technical and organizational measures to ensure GDPR compliance. The violations concerned data processing activities related to its websites. | HU | NAIH | GDPR | €2,770 | ↗ |