BULLETIN №082Last updated · 04 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 25 Mar 2021 | Fastweb S.p.A.Fastweb S.p.A. was sanctioned by the Garante for making unauthorized promotional calls and sending messages without proper consent. The authority also found insufficient measures to ensure data processing security and GDPR compliance. | IT | Garante | GDPR | €4,501,000 | ↗ |
| 25 Mar 2021 | Unione dei Comuni Valli del Reno, Lavino e SamoggiaUnione dei Comuni Valli del Reno, Lavino e Samoggia was fined by the Garante EUR 13,000 for improperly publishing personal data on the web. The authority found a breach of GDPR principles on lawfulness and data processing. | IT | Garante | GDPR | €13,000 | ↗ |
| 25 Mar 2021 | TECNOMEDICAL S.r.l.TECNOMEDICAL S.r.l. was fined by the Garante for violating data protection rules related to the processing of health data. The case concerned non-compliance in the handling of sensitive personal data. | IT | Garante | GDPR | €7,000 | ↗ |
| 25 Mar 2021 | OneDirect S.r.l.OneDirect S.r.l. was fined EUR 30,000 by the Garante. The authority found that the company sent unsolicited promotional emails despite objections and failed to respond to data subject requests. | IT | Garante | GDPR | €30,000 | ↗ |
| 25 Mar 2021 | Convitto Nazionale Statale "Giordano Bruno"Convitto Nazionale Statale "Giordano Bruno" was fined by the Garante for breaching data protection principles. The authority found that personal data had been made available online for an extended period, contrary to the principles of lawfulness, fairness, transparency, and data minimization. | IT | Garante | GDPR | €1,000 | ↗ |
| 25 Mar 2021 | Comune di CastellanzaComune di Castellanza was fined by the Garante EUR 4,000 for breaching data protection principles, including lawfulness, fairness, transparency, and data minimization. Personal data remained accessible online for an extended period. | IT | Garante | GDPR | €4,000 | ↗ |
| 25 Mar 2021 | GEDI News Network S.p.a.GEDI News Network S.p.a. was fined by the Italian data protection authority, Garante, in the amount of EUR 20,000. The case concerned failure to comply with a request to delete personal data from an article about a 1998 legal case, which remained prejudicial because the outcome was not updated. | IT | Garante | GDPR | €20,000 | ↗ |
| 24 Mar 2021 | ALLIANZ COMPAÑIA DE SEGUROS Y REASEGUROS, S.A.ALLIANZ COMPAÑIA DE SEGUROS Y REASEGUROS, S.A. was fined EUR 30,000 by the AEPD. The authority found that after a policy was canceled, the company continued processing personal data without a lawful basis, in breach of Article 6 GDPR. | ES | AEPD | GDPR | €30,000 | ↗ |
| 24 Mar 2021 | IBERDROLA CLIENTES, SAUIberdrola Clientes, SAU was fined EUR 70,000 by the AEPD for changing the contracted power in a supply agreement without the consent of the contract holder. The authority found that this conduct breached data protection rules. | ES | AEPD | GDPR | €70,000 | ↗ |
| 24 Mar 2021 | Ålesund kommuneÅlesund kommune was fined by Datatilsynet for using the Strava app in schools without conducting a risk assessment. As a result, students’ personal data was processed without adequate controls and safeguards. | NO | Datatilsynet | GDPR | €4,923 | ↗ |
| 24 Mar 2021 | Budapest Főváros Kormányhivatala XI. kerületi HivatalaBudapest Főváros Kormányhivatala XI. kerületi Hivatala failed to implement adequate security measures for health data related to Covid-19 tests. The office also did not report a high-risk personal data breach to NAIH or notify the affected individuals. | HU | NAIH | GDPR | €27,400 | ↗ |
| 23 Mar 2021 | Anonymizováno (ÚOOÚ UOOU-00681/20-18)The entity was fined for sending unsolicited commercial communications by email without the recipients' consent. This breached Czech electronic communications rules. | CZ | UOOU | ePrivacy | €382 | ↗ |
| 23 Mar 2021 | KUTXABANK, S.A.KUTXABANK, S.A. was fined EUR 100,000 by the AEPD for failing to properly handle a data deletion request. The issue affected the complainant’s ability to open a new account. | ES | AEPD | GDPR | €100,000 | ↗ |
| 23 Mar 2021 | ABANCA CORPORACIÓN BANCARIA, S.A.ABANCA CORPORACIÓN BANCARIA, S.A. was fined EUR 5,000 by the AEPD for using cookies on its website without providing the required information to users or obtaining their consent. The case concerns failures to meet legal notice and consent requirements. | ES | AEPD | ePrivacy | €5,000 | ↗ |
| 23 Mar 2021 | Irish Credit Bureau DACThe Irish Data Protection Commission (DPC) fined Irish Credit Bureau DAC EUR 90,000 in inquiry IN-19-7-2. The fine has been collected. | IE | DPC | GDPR | €90,000 | ↗ |
| 22 Mar 2021 | Tájékoztatási kötelezettség elmulasztása, hozzáférési jog és adatkezelés korlátozásához való jogThe controller did not inform the data subject within the required timeframe about actions taken on their requests. It also delayed access to the requested footage and failed to block the camera recording, resulting in a data protection fine. | HU | NAIH | GDPR | €1,365 | ↗ |
| 22 Mar 2021 | Engedményezés utáni követeléskezeléssel kapcsolatos adatkezelés jogalapja, érintetti kérelem teljesítéseThe supervisory authority found a GDPR breach in the processing of personal data for debt collection after assignment of a claim. The controller did not establish a proper legal basis, failed to provide clear information about that basis, and did not properly handle data subject requests. | HU | NAIH | GDPR | €13,650 | ↗ |
| 19 Mar 2021 | Dane anonimowe (T. Spółka z o.o.)The President of UODO imposed an administrative fine of PLN 22,739.5 on T. Sp. z o.o. The sanction was issued for failing to cooperate with the supervisory authority and for not providing information necessary to examine a complaint. | PL | UODO | GDPR | €4,922 | ↗ |
| 18 Mar 2021 | Vodafone España, S.A.U.The AEPD imposed a 50,000 EUR fine on Vodafone España, S.A.U. for unauthorized processing of personal data. The case involved fraudulent contracting of mobile services in the complainant's name. | ES | AEPD | GDPR | €50,000 | ↗ |
| 17 Mar 2021 | BODY TONIC SHOP, S.L.BODY TONIC SHOP, S.L. was fined by the AEPD EUR 2,000 for processing personal data without proper consent. The authority found a breach of Article 6 of the GDPR. | ES | AEPD | GDPR | €2,000 | ↗ |