BULLETIN №082Last updated · 04 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 04 Mar 2021 | ALAVA NORTE, S.L.ALAVA NORTE, S.L. was fined by the AEPD in the amount of 4,000 EUR for installing surveillance cameras without sufficient justification. The cameras captured both public and private spaces, which breached data protection principles. | ES | AEPD | GDPR | €4,000 | ↗ |
| 03 Mar 2021 | COMUNIDAD DE PROPIETARIOS R.R.R.COMUNIDAD DE PROPIETARIOS R.R.R. was fined by the AEPD EUR 2,000 for installing a surveillance camera system without the required authorization. The cameras recorded private areas, which breached privacy rules. | ES | AEPD | GDPR | €2,000 | ↗ |
| 02 Mar 2021 | Anonymisert (Datatilsynet far-gebyr-for-ulovlig-videresending-av-e-post)The company was fined 250,000 NOK for forwarding an employee’s emails without a legal basis. The authority found that this breached the GDPR and the rules governing employer access to employee email accounts. | NO | Datatilsynet | GDPR | €24,378 | ↗ |
| 01 Mar 2021 | COMUNIDAD DE PROPIETARIOS ***DIRECCIÓN.1The entity was fined EUR 2,000 by the AEPD for installing cameras without the informed consent of the property owners' association. The conduct may have affected third-party rights and data protection obligations. | ES | AEPD | GDPR | €2,000 | ↗ |
| 26 Feb 2021 | PINTODIS, S.L.PINTODIS, S.L. was fined by the AEPD for installing surveillance cameras that recorded employees in private areas without sufficient justification. The authority found this to be a breach of data protection principles. | ES | AEPD | GDPR | €10,000 | ↗ |
| 25 Feb 2021 | Mistore Canarias, S.L.U.Mistore Canarias, S.L.U. was fined by the AEPD 5,000 EUR for processing personal data without consent. The conduct resulted in unauthorized charges to a customer's bank account. | ES | AEPD | GDPR | €5,000 | ↗ |
| 24 Feb 2021 | UNIÓN FINANCIERA ASTURIANA S.A. E.F.C.UNIÓN FINANCIERA ASTURIANA S.A. E.F.C. was fined by the AEPD 15,000 EUR for consulting personal data in the Asnef file without a contractual relationship. The authority found this breached GDPR Article 6.1. | ES | AEPD | GDPR | €15,000 | ↗ |
| 23 Feb 2021 | SFAM ESPAÑA GENERAL S.L.SFAM ESPAÑA GENERAL S.L. was fined by the AEPD in the amount of 5,000 EUR. The case concerned unauthorized charges to a customer's bank account after a purchase, raised in a complaint about data misuse. | ES | AEPD | GDPR | €5,000 | ↗ |
| 22 Feb 2021 | B.B.B.The entity was fined by the AEPD for a video surveillance system that was improperly oriented toward private areas. The authority also found that the area was not adequately signposted, breaching data protection rules. | ES | AEPD | GDPR | €3,000 | ↗ |
| 22 Feb 2021 | B.B.B.A fine was imposed for installing a surveillance camera aimed at public and private spaces without justification. The authority found a breach of data protection principles. | ES | AEPD | GDPR | €1,500 | ↗ |
| 20 Feb 2021 | FLEXOGRÁFICA DEL MEDITERRÁNEO, S.L.The company was fined by the AEPD for failing to provide a privacy policy and cookie management on its websites. The authority also found that user consent was collected in a generic manner, which did not meet data protection requirements. | ES | AEPD | GDPR | €3,000 | ↗ |
| 19 Feb 2021 | SERVICIOS LOGÍSTICOS MARTORELL SIGLO XXI, S.L.The company was fined by the AEPD for deploying a biometric fingerprint system for employee attendance control without carrying out a data protection impact assessment. The authority found this to be a breach of Article 35 GDPR because the processing involved biometric data requiring prior risk assessment. | ES | AEPD | GDPR | €20,000 | ↗ |
| 18 Feb 2021 | INFORMÁTICA MÉDICA, S.L.INFORMÁTICA MÉDICA, S.L. was fined by the AEPD 60,000 EUR for failing to have a proper data processing agreement with its processor, OUTENUVE. The authority treated this as a breach of Article 28 GDPR. | ES | AEPD | GDPR | €60,000 | ↗ |
| 17 Feb 2021 | VODAFONE ONO, S.A.U.VODAFONE ONO, S.A.U. was fined by the AEPD 10,000 EUR for sending an unsolicited commercial SMS to a complainant without prior consent. The authority found that the message was sent without the required authorization. | ES | AEPD | ePrivacy | €10,000 | ↗ |
| 15 Feb 2021 | KHR-be való adattovábbítás (létre nem jött szerződés esetén)The controller unlawfully transferred personal data to the Central Credit Information System (KHR) even though no contract had been concluded. The authority found a breach of Article 6 GDPR and imposed a fine of 1,500,000 HUF. | HU | NAIH | GDPR | €4,185 | ↗ |
| 15 Feb 2021 | ANYTIME FITNESS IBERIA, S.L.ANYTIME FITNESS IBERIA, S.L. was fined by the AEPD 15,000 EUR for failing to delete personal data after a request and for sending promotional SMS messages without consent. The case concerns non-compliance with data subject rights and rules on direct marketing. | ES | AEPD | ePrivacy | €15,000 | ↗ |
| 12 Feb 2021 | A*** GmbHA*** GmbH was fined by the Austrian Data Protection Authority for failing to cooperate in three separate complaint procedures. The authority found a breach of Article 31 GDPR, which requires cooperation with the supervisory authority. | AT | DSB | GDPR | €3,000 | ↗ |
| 12 Feb 2021 | KUKIMBIA S.L.KUKIMBIA S.L. was fined EUR 3,000 by the AEPD for leaving documents containing personal data unattended. The authority found this to be a breach of data security obligations under Article 32(1) of the GDPR. | ES | AEPD | GDPR | €3,000 | ↗ |
| 12 Feb 2021 | HIGHCLIFFE ESTATES MARBELLA, S.L.The company was fined by the AEPD for not providing a legal notice, privacy policy, or consent checkbox on its website. The authority also found that it used an individual's image without consent, breaching GDPR Articles 13 and 6(1). | ES | AEPD | GDPR | €8,000 | ↗ |
| 12 Feb 2021 | ELECTROTECNIA BASTIDA, S.L.ELECTROTECNIA BASTIDA, S.L. was fined by the AEPD 3,000 EUR for leaving employees’ confidential medical information abandoned in a field. The incident constituted a breach of data protection rules and required supervisory action. | ES | AEPD | GDPR | €3,000 | ↗ |