BULLETIN №083Last updated · 05 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -22.5%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 03 Feb 2021 | ASESORÍA MUNIZ SOLÁN, S.L.ASESORÍA MUNIZ SOLÁN, S.L. was fined by the AEPD 2,000 EUR for breaching confidentiality after sending a debt certificate relating to a third party instead of the correct document. The authority also noted inadequate security measures under GDPR Article 32. | ES | AEPD | GDPR | €2,000 | ↗ |
| 03 Feb 2021 | NBQ TECHNOLOGY, S.A.U.NBQ TECHNOLOGY, S.A.U. was fined by the AEPD 40,000 EUR for processing personal data without a legal basis. The case was linked to a denied financial operation following an identity theft incident. | ES | AEPD | GDPR | €40,000 | ↗ |
| 03 Feb 2021 | MERCADONA S.A.MERCADONA S.A. was fined EUR 170,000 by the AEPD for failing to respond to a data access request within the required timeframe and for deleting security camera footage. The authority found that these actions breached GDPR obligations, including Articles 12 and 6. | ES | AEPD | GDPR | €170,000 | ↗ |
| 30 Jan 2021 | DEGOM, S.A.DEGOM, S.A. was fined EUR 3,000 by the AEPD for failing to display cookie warnings and data protection acceptance checkboxes on its website. The case concerned deficiencies in online transparency and user consent requirements. | ES | AEPD | ePrivacy | €3,000 | ↗ |
| 28 Jan 2021 | TRES-F-NETWORK, S.A.UTRES-F-NETWORK, S.A.U was fined by the AEPD 4,000 EUR for sending commercial SMS messages without the recipient's consent and without an existing commercial relationship. The authority found this conduct breached Article 21 of the LSSI. | ES | AEPD | ePrivacy | €4,000 | ↗ |
| 27 Jan 2021 | Azienda Ospedaliero Universitaria SeneseAzienda Ospedaliero Universitaria Senese was fined by the Garante in the amount of 10,000 EUR for breaches of data protection rules in the healthcare sector. The case concerned the processing of sensitive personal data in a medical setting. | IT | Garante | GDPR | €10,000 | ↗ |
| 27 Jan 2021 | Azienda ospedaliera regionale “San Carlo” di PotenzaAzienda ospedaliera regionale “San Carlo” di Potenza was fined EUR 70,000 by the Garante for violations related to the processing of personal data. The case concerned the handling of sensitive health data. | IT | Garante | GDPR | €70,000 | ↗ |
| 27 Jan 2021 | Dental Leader S.p.A.Dental Leader S.p.A. was fined EUR 10,000 by the Garante. The authority found that the company required consent to process personal data for promotional purposes in order to complete an online order, even though this was not necessary for contract performance. | IT | Garante | GDPR | €10,000 | ↗ |
| 27 Jan 2021 | Azienda Ospedaliero Universitaria di ParmaAzienda Ospedaliero Universitaria di Parma was fined by the Garante for violations related to the handling of health data. The violations resulted in a data breach, which led to the 10,000 EUR penalty. | IT | Garante | GDPR | €10,000 | ↗ |
| 27 Jan 2021 | Istituto Comprensivo Villanova D’AstiIstituto Comprensivo Villanova D’Asti was fined EUR 4,000 by the Garante for publishing personal data online. The disclosed information could reveal health status and economic-social conditions, breaching data minimization and transparency principles. | IT | Garante | GDPR | €4,000 | ↗ |
| 27 Jan 2021 | Comune di Cesano BosconeThe Municipality of Cesano Boscone was fined EUR 2,000 by the Garante for publishing personal data related to a disciplinary sanction on its website. The authority found a breach of the principles of lawfulness, fairness, and transparency. | IT | Garante | GDPR | €2,000 | ↗ |
| 27 Jan 2021 | Roma CapitaleRoma Capitale was fined EUR 10,000 by the Garante for publishing the personal data of a minor and the minor’s mother on its official website without a proper legal basis. The authority found a breach of the principles of lawfulness, fairness, and transparency. | IT | Garante | GDPR | €10,000 | ↗ |
| 27 Jan 2021 | Powerplay S.r.l.Powerplay S.r.l. was fined by the Garante for making unsolicited promotional calls despite the recipient's clear request not to receive further communications. The company failed to place the number on a blacklist, which breached data protection rules. | IT | Garante | GDPR | €20,000 | ↗ |
| 27 Jan 2021 | Azienda USL della RomagnaAzienda USL della Romagna was fined by the Garante 50,000 EUR for failing to implement procedures to prevent unauthorized disclosure of patients' health information. The authority found a breach of GDPR Article 9 on special categories of personal data. | IT | Garante | GDPR | €50,000 | ↗ |
| 27 Jan 2021 | Vodafone España, S.A.U.Vodafone España, S.A.U. was fined by the AEPD 100,000 EUR for making a commercial call to a number registered on the Robinson list. The authority found that this breached data protection and direct marketing opt-out requirements. | ES | AEPD | GDPR | €100,000 | ↗ |
| 27 Jan 2021 | STOCKHUNTERS, S.L.STOCKHUNTERS, S.L. was fined EUR 4,000 by the AEPD for failing to comply with GDPR Article 13. The authority found that the website privacy policy did not meet the required information standards. | ES | AEPD | GDPR | €4,000 | ↗ |
| 27 Jan 2021 | De Nationale Dienst voor Promotie van Kinderartikelen, NVThe company was fined for unlawfully sharing personal data of (expectant) mothers with third parties for direct marketing without valid consent. The authority found breaches of GDPR transparency and information obligations. | BE | APD | GDPR | €50,000 | ↗ |
| 26 Jan 2021 | Grindr LLCThe Norwegian DPA intends to fine Grindr 100 million NOK for sharing user data with third parties without valid consent. The conduct was assessed as a breach of GDPR consent requirements. | NO | Datatilsynet | GDPR | €9,627,000 | ↗ |
| 26 Jan 2021 | VODAFONE ESPAÑA, S.A.U.Vodafone España was fined by the AEPD 100,000 EUR for unlawfully registering a prepaid phone line under the complainant’s ID and accessing credit information without a legitimate interest. The company also failed to properly comply with requests for access to and deletion of personal data. | ES | AEPD | GDPR | €100,000 | ↗ |
| 25 Jan 2021 | PATIO ANCESTRAL, S.L.PATIO ANCESTRAL, S.L. was fined by the AEPD in the amount of EUR 5,000 for sending a letter containing personal data to the complainant's workplace. The authority found this to be a breach of data protection rules. | ES | AEPD | GDPR | €5,000 | ↗ |