BULLETIN №082Last updated · 04 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 20 Apr 2021 | EB CREATIVE LABEB CREATIVE LAB was fined by the AEPD EUR 5,000 for failing to provide information or obtain consent for cookies on its website. The breach concerned Article 22.2 of the LSSI. | ES | AEPD | ePrivacy | €5,000 | ↗ |
| 20 Apr 2021 | B.B.B.The entity was fined for not providing an adequate privacy policy on its website. This constituted a breach of Article 13 of the GDPR, which requires proper information to be provided to data subjects. | ES | AEPD | GDPR | €2,000 | ↗ |
| 19 Apr 2021 | BankThe Bank was fined by NAIH for breaching the principles of purpose limitation and data minimization when transferring personal data without a proper legal basis. The authority also found failures to respect the data subject's rights of access and objection. | HU | NAIH | GDPR | €13,900 | ↗ |
| 19 Apr 2021 | AD735 DATA MEDIA ADVERTISING S.L.AD735 DATA MEDIA ADVERTISING S.L. was fined EUR 15,000 by the AEPD. The authority found that the company failed to comply with a data subject's right to erasure and sent commercial communications without the recipient's explicit consent. | ES | AEPD | ePrivacy | €15,000 | ↗ |
| 16 Apr 2021 | CREATOR ENERGY, S.L.CREATOR ENERGY, S.L. was fined by the AEPD 6,000 EUR for using personal data without consent to contract gas, electricity, and maintenance services. The authority found this conduct breached Article 6(1)(b) GDPR. | ES | AEPD | GDPR | €6,000 | ↗ |
| 15 Apr 2021 | Clear Channel Italia S.p.A.Clear Channel Italia S.p.A. was fined by the Garante EUR 75,000 for conducting intrusive checks on employees’ devices without a proper legal basis. The authority found breaches of data minimization and proportionality principles. | IT | Garante | GDPR | €75,000 | ↗ |
| 15 Apr 2021 | INPSThe Italian Data Protection Authority fined INPS €12,000 for failing to provide a data subject with access to their personal data and for unlawfully communicating personal data to third parties. The authority found breaches of lawfulness, fairness, and transparency. | IT | Garante | GDPR | €12,000 | ↗ |
| 15 Apr 2021 | HAZTEOIR.ORGThe association HazteOir.Org was fined EUR 5,000 by the AEPD for including images and names of individuals in a pamphlet without their consent. The authority found this to be a breach of data protection rules. | ES | AEPD | GDPR | €5,000 | ↗ |
| 15 Apr 2021 | Ordinanza ingiunzione - 15 aprile 2021The case concerned a breach of data protection rules by a healthcare entity. Consent for processing personal data for epidemiological research was obtained improperly. | IT | Garante | GDPR | €5,000 | ↗ |
| 15 Apr 2021 | Società triveneta di chirurgiaSocietà triveneta di chirurgia was fined EUR 2,000 by the Garante for processing personal data without meeting the requirements of lawfulness, fairness, and transparency. The authority also found a breach of the data minimization principle. | IT | Garante | GDPR | €2,000 | ↗ |
| 15 Apr 2021 | Ordine degli Avvocati di LagonegroOrdine degli Avvocati di Lagonegro was fined EUR 3,000 by the Garante for publishing the content of a PEC email on its institutional website. The authority found breaches of lawfulness, fairness, transparency, and data minimization. | IT | Garante | GDPR | €3,000 | ↗ |
| 15 Apr 2021 | Tiberia Assicurazioni s.a.s.Tiberia Assicurazioni s.a.s. was fined by the Garante 1,500 EUR for sending an insurance contract proposal by email without the recipient's consent. The authority found this to be a breach of GDPR Article 6. | IT | Garante | GDPR | €1,500 | ↗ |
| 15 Apr 2021 | Ordine degli Avvocati di RomaOrdine degli Avvocati di Roma was fined €2,000 by the Garante for a significant delay in responding to a data subject access request. The case highlights a failure to meet the required timelines for handling access requests under data protection rules. | IT | Garante | GDPR | €2,000 | ↗ |
| 14 Apr 2021 | ANIVERSALIA NETWORKS, S.L.ANIVERSALIA NETWORKS, S.L. was fined by the AEPD EUR 2,000 for not having a GDPR-compliant privacy policy on its website. In particular, it failed to provide contact details for exercising data subject rights. | ES | AEPD | GDPR | €2,000 | ↗ |
| 14 Apr 2021 | MASTER DISTANCIA S.A.MASTER DISTANCIA S.A. was fined EUR 25,000 by the AEPD for unlawfully processing personal data by including it in credit information systems without a valid legal basis. The authority found a breach of GDPR Article 6. | ES | AEPD | GDPR | €25,000 | ↗ |
| 14 Apr 2021 | Avalos Consultores, S.L.Avalos Consultores, S.L. was fined by the AEPD 4,000 EUR for transferring personal data to another company without the data subject's consent. The authority found this breached Article 6 of the GDPR. | ES | AEPD | GDPR | €4,000 | ↗ |
| 13 Apr 2021 | Vodafone España, S.A.U.Vodafone España, S.A.U. was fined 40,000 EUR by the AEPD for charging a customer's phone bill without consent. The authority found a breach of Article 6(1) GDPR due to the lack of a lawful basis for processing. | ES | AEPD | GDPR | €40,000 | ↗ |
| 12 Apr 2021 | COMUNIDAD DE PROPIETARIOS R.R.R.The entity was fined by the AEPD EUR 1,500 for installing a video surveillance system without the required authorization from the homeowners' association. The case concerned a breach of data protection rules. | ES | AEPD | GDPR | €1,500 | ↗ |
| 12 Apr 2021 | INSTAPACK, S.L.INSTAPACK, S.L. was fined by the AEPD for sending unsolicited SMS messages without valid consent. The authority also found that the company failed to respond to a deletion request, constituting a breach of GDPR Article 6(1)(a). | ES | AEPD | GDPR | €3,000 | ↗ |
| 09 Apr 2021 | Miljø- og Kvalitetsledelse ASMiljø- og Kvalitetsledelse AS was fined 35,000 NOK by Datatilsynet for unlawfully sending personal data from camera recordings to an employer without a legal basis. The authority cited breaches of GDPR Articles 6 and 5. | NO | Datatilsynet | GDPR | €3,461 | ↗ |