BULLETIN №082Last updated · 04 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 08 Apr 2021 | Anonymisé (CNPD decision-11-fr-2021)The company breached the GDPR by failing to respect data retention limits, by not adequately informing employees about data processing, and by applying insufficient security measures. The CNPD decision of 8 April 2021 resulted in a fine of 4,000 EUR. | LU | CNPD | GDPR | €4,000 | ↗ |
| 07 Apr 2021 | Anonymizováno (ÚOOÚ UOOU-03058/20-30)The entity did not respond to a data subject's request to delete personal data from a publicly accessible auction notice. The authority found this to be a breach of GDPR rights and imposed a monetary penalty. | CZ | UOOU | GDPR | €386 | ↗ |
| 07 Apr 2021 | IMPORTACIONES CRBD, S.L.The entity was fined for sending commercial emails without the recipient's consent, in breach of Article 21 of the LSSI. The case concerns unauthorized direct electronic marketing. | ES | AEPD | ePrivacy | €1,000 | ↗ |
| 07 Apr 2021 | Ignatiadis Nikolaos and SIA E.E.The company was fined for unlawfully using a surveillance camera to monitor employees. The authority found a breach of data protection principles and an absence of a valid legal basis for processing. | GR | HDPA | GDPR | €2,000 | ↗ |
| 07 Apr 2021 | MZN HELLAS A.E.The company was fined for sending unsolicited marketing SMS messages to a customer who had explicitly objected to such communications. The authority found this to be a breach of GDPR rules on data subject rights and data protection by design. | GR | HDPA | GDPR | €20,000 | ↗ |
| 07 Apr 2021 | Jogellenes adatkezelés, adattakarékosság és megfelelő tájékoztatási kötelezettség megsértéseThe authority found that the controller unlawfully processed personal data related to debt collection. It held that the principles of data minimization and transparency were breached, together with the duty to provide proper information to data subjects. | HU | NAIH | GDPR | €2,780 | ↗ |
| 07 Apr 2021 | EDICIONES TU REFORMA, S.L.EDICIONES TU REFORMA, S.L. was fined by the AEPD EUR 1,500 for sending unsolicited commercial SMS messages without the recipient's consent. This conduct breached Article 21 of the LSSI on commercial communications. | ES | AEPD | ePrivacy | €1,500 | ↗ |
| 06 Apr 2021 | CAFFE VECCHIO, S.L.CAFFE VECCHIO, S.L. was fined by the AEPD EUR 1,500 for publishing an individual's personal data in response to negative Google reviews. The disclosure included the person's name and details of an employment sanction. | ES | AEPD | GDPR | €1,500 | ↗ |
| 02 Apr 2021 | PAGAMASTARDE, S.L.PAGAMASTARDE, S.L. was fined EUR 5,000 by the AEPD for sending advertising emails after a request for data cancellation had already been confirmed as processed. The authority treated this as a breach of data protection rules. | ES | AEPD | ePrivacy | €5,000 | ↗ |
| 31 Mar 2021 | ORANGE ESPAGNE, S.A.U.Orange Espagne, S.A.U. was fined by the AEPD 150,000 EUR for violations related to direct marketing communications. The case concerned conduct that may have breached data protection rules. | ES | AEPD | ePrivacy | €150,000 | ↗ |
| 31 Mar 2021 | Anonymizováno (ÚOOÚ UOOU-04077/20-13)The entity was fined for processing personal data from public registers without a legal basis and for failing to respond to a data subject's erasure request. The case highlights deficiencies in lawful processing and in handling data subject rights. | CZ | UOOU | GDPR | €4,590 | ↗ |
| 31 Mar 2021 | Booking.com B.V.Booking.com B.V. was fined for failing to report a personal data breach to the Dutch Data Protection Authority within 72 hours of becoming aware of it, as required by GDPR Article 33. The case concerns the controller’s obligation to notify the supervisory authority without undue delay. | NL | AP | GDPR | €475,000 | ↗ |
| 30 Mar 2021 | TELEFÓNICA MÓVILES ESPAÑA, S.A.U.TELEFÓNICA MÓVILES ESPAÑA, S.A.U. was fined by the AEPD 75,000 EUR for using a customer's phone number without consent. This led to numerous unsolicited calls, despite prior claims that security measures had been implemented. | ES | AEPD | GDPR | €75,000 | ↗ |
| 30 Mar 2021 | VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD 150,000 EUR for failing to delete personal data after phone contracts ended. This led to continued SMS notifications with zero-balance invoices being sent to former customers. | ES | AEPD | GDPR | €150,000 | ↗ |
| 30 Mar 2021 | PROMOTECH DIGITAL, S.L.PROMOTECH DIGITAL, S.L. was fined by the AEPD in the amount of 5,000 EUR for sending unsolicited SMS messages without recipient consent. The authority also found that the company did not provide an easy opt-out mechanism, in breach of data protection rules. | ES | AEPD | GDPR | €5,000 | ↗ |
| 26 Mar 2021 | CAIXABANK S.A.CAIXABANK S.A. was fined EUR 60,000 by the AEPD for processing personal data without consent. The case concerned a current account contract signed on behalf of the complainant without proper authorization. | ES | AEPD | GDPR | €60,000 | ↗ |
| 25 Mar 2021 | Centro diagnostico italiano di MilanoThe Italian Data Protection Authority imposed a fine of EUR 50,000 on Centro diagnostico italiano di Milano. The sanction concerned violations of data protection rules. | IT | Garante | GDPR | €50,000 | ↗ |
| 25 Mar 2021 | Comune di MonteiasiComune di Monteiasi was fined by the Garante €4,000 for breaching the data minimization principle. The municipality published personal data on its website, including names and IBANs, that were not necessary for transparency purposes. | IT | Garante | GDPR | €4,000 | ↗ |
| 25 Mar 2021 | Kamerák üzemeltetése idősek otthonábanThe authority imposed a fine for using video surveillance for unlawful purposes. It also found that the data subjects were not adequately informed and that there was no proper legal basis for processing. | HU | NAIH | GDPR | €1,370 | ↗ |
| 25 Mar 2021 | Dragefossen ASDragefossen AS was fined 150,000 NOK by Datatilsynet for unlawfully live streaming surveillance footage from a camera in Rognan sentrum on the internet. The authority found no legal basis for the processing, which breached GDPR Articles 6 and 5. | NO | Datatilsynet | GDPR | €14,756 | ↗ |