BULLETIN №082Last updated · 04 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 17 Mar 2021 | VASCO ANDALUZA DE INVERSIONES, S.L.VASCO ANDALUZA DE INVERSIONES, S.L. was fined by the AEPD 2,000 EUR for unlawfully sharing personal data with third parties without informing the data subject. The authority found this conduct to be in breach of Article 6 of the GDPR. | ES | AEPD | GDPR | €2,000 | ↗ |
| 17 Mar 2021 | GERCO FIT, S.L.GERCO FIT, S.L. was fined by the AEPD in the amount of 2,000 EUR for processing personal data without proper consent. The authority found a breach of Article 6 of the GDPR. | ES | AEPD | GDPR | €2,000 | ↗ |
| 17 Mar 2021 | SOLRAM T Y R S.L.SOLRAM T Y R S.L. was fined by the AEPD in the amount of 3,000 EUR for failing to delete personal data from its databases. The authority found a breach of Article 17 GDPR after the company continued sending unsolicited commercial messages via WhatsApp. | ES | AEPD | GDPR | €3,000 | ↗ |
| 16 Mar 2021 | SIA "“fit People”A fine of EUR 5,836 was imposed. The decision has entered into force. | LV | DVI | GDPR | €5,836 | ↗ |
| 15 Mar 2021 | Geanonimiseerd (APD 36/2021)A school used Smartschool to conduct a “well-being” survey among minor students without parental consent. The authority found that several GDPR provisions governing the processing of children’s data were breached. | BE | APD | GDPR | €2,000 | ↗ |
| 12 Mar 2021 | PRODUCCIONES ROCKNROCK, S.L.PRODUCCIONES ROCKNROCK, S.L. was fined EUR 2,000 by the AEPD for failing to provide information or obtain consent for cookies on its website. The authority found a breach of Article 22.2 of the LSSI. | ES | AEPD | ePrivacy | €2,000 | ↗ |
| 11 Mar 2021 | Mediacom s.r.l.Mediacom s.r.l. was fined by the Garante for making unsolicited promotional calls without proper consent. The authority found that this conduct breached GDPR rules on the processing of personal data for marketing purposes. | IT | Garante | GDPR | €15,000 | ↗ |
| 11 Mar 2021 | Università degli Studi di Napoli Federico IIUniversità degli Studi di Napoli Federico II was fined by the Garante in the amount of 10,000 EUR for breaches of data protection principles. The authority found violations of lawfulness, fairness, transparency, and data minimization in the processing of personal data. | IT | Garante | GDPR | €10,000 | ↗ |
| 11 Mar 2021 | COMUNIDAD DE PROPIETARIOS B.B.B.COMUNIDAD DE PROPIETARIOS B.B.B. was fined by the AEPD in the amount of 2,000 EUR for irregularities in its video surveillance system. The authority found that the cameras captured public spaces, which breached the data minimization principle under Article 5(1)(c) GDPR. | ES | AEPD | GDPR | €2,000 | ↗ |
| 11 Mar 2021 | Azienda Ospedaliera San Giovanni AddolorataAzienda Ospedaliera San Giovanni Addolorata was fined EUR 20,000 by the Garante for inadequate data protection measures concerning patient health data. The authority found breaches of GDPR Articles 5 and 32. | IT | Garante | GDPR | €20,000 | ↗ |
| 11 Mar 2021 | Plurima s.r.l.Plurima s.r.l. was fined EUR 5,000 by the Italian data protection authority, Garante. The sanction concerned unsolicited promotional calls made to individuals whose consent was not recorded in the consent database. This conduct breached GDPR requirements for marketing-related processing. | IT | Garante | GDPR | €5,000 | ↗ |
| 11 Mar 2021 | Planet Group spaPlanet Group spa was fined EUR 80,000 by the Garante. The authority found that the company made unsolicited promotional calls without a proper legal basis, breaching GDPR rules on data processing and privacy by design. | IT | Garante | GDPR | €80,000 | ↗ |
| 11 Mar 2021 | dott. Gregorio GrecoDott. Gregorio Greco was fined 6,400 EUR by the Garante for failing to provide information to data subjects and for processing patients' health-related personal data without consent. The case concerns patient data and breaches of transparency and lawful basis requirements. | IT | Garante | GDPR | €6,400 | ↗ |
| 10 Mar 2021 | B.B.B.The entity was fined by the AEPD in the amount of 4,000 EUR for installing a video surveillance system aimed at public areas. The authority also found that images were captured without justified cause and retained longer than permitted by law. | ES | AEPD | GDPR | €4,000 | ↗ |
| 09 Mar 2021 | NBQ TECHNOLOGY, S.A.U.NBQ TECHNOLOGY, S.A.U. was fined by the AEPD €20,000 for processing personal data without a legal basis. The case was related to identity theft in a microcredit contract. | ES | AEPD | GDPR | €20,000 | ↗ |
| 09 Mar 2021 | VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined EUR 100,000 by the AEPD for failing to permanently delete personal data after a request. As a result, the complainant continued to receive SMS messages. | ES | AEPD | GDPR | €100,000 | ↗ |
| 05 Mar 2021 | APARTAMENTOS PLAYA DE COVACHOS, S.L.The company was fined by the AEPD in the amount of 1,000 EUR for operating video surveillance without the required information for recorded individuals. It did not identify the data controller, explain how rights could be exercised, or state the purpose of the surveillance, which breaches Article 13 GDPR. | ES | AEPD | GDPR | €1,000 | ↗ |
| 04 Mar 2021 | VODAFONE ESPAÑA, S.A.U.Vodafone España was fined for processing personal data without a legal basis. The company linked a prepaid phone line to an individual without consent and shared the data with law enforcement. | ES | AEPD | GDPR | €100,000 | ↗ |
| 04 Mar 2021 | Anonymizováno (ÚOOÚ UOOU-02022/20-24)The entity was fined for unauthorized publication of personal data of thirty individuals on a website. The authority found a breach of the basic principles of personal data processing under GDPR. | CZ | UOOU | GDPR | €5,724 | ↗ |
| 04 Mar 2021 | CEDICO, CENTRO DE DIAGNÓSTICO POR LA IMÁGEN, S.L.CEDICO, a diagnostic imaging center, was fined EUR 30,000 by the AEPD. The authority found that the company unlawfully shared a patient's MRI report with a mutual insurance company, breaching data protection principles. | ES | AEPD | GDPR | €30,000 | ↗ |