BULLETIN №083Last updated · 05 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -22.5%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 20 Jan 2021 | XFERA MÓVILES, S.A.XFERA MÓVILES, S.A. was fined EUR 40,000 by the AEPD for failing to respond to a data access request. The case concerns non-compliance with GDPR obligations relating to data subject rights. | ES | AEPD | GDPR | €40,000 | ↗ |
| 20 Jan 2021 | BICLAMEDIA, S.L.BICLAMEDIA, S.L. was fined 1,500 EUR by the AEPD for sending commercial emails without the recipient’s consent. The conduct breached Article 21 of the LSSI governing electronic marketing communications. | ES | AEPD | ePrivacy | €1,500 | ↗ |
| 19 Jan 2021 | EQUIFAX IBERICA, S.L.EQUIFAX IBERICA, S.L. was fined by the AEPD 50,000 EUR for including personal data in a credit file without a valid debt and without proper notice. The authority found this breached data processing principles. | ES | AEPD | GDPR | €50,000 | ↗ |
| 18 Jan 2021 | INDUSTRIAS METÁLICAS ANRO, S.L.INDUSTRIAS METÁLICAS ANRO, S.L. was fined by the AEPD for failing to comply with cookie policy requirements on its website. The breach concerned Article 22.2 of the LSSI. | ES | AEPD | ePrivacy | €2,000 | ↗ |
| 18 Jan 2021 | MEJORFRESCO TIENDA ONLINE, S.L.MEJORFRESCO TIENDA ONLINE, S.L. was fined by the AEPD EUR 2,000 for sending advertising emails without the recipient's consent. The case concerned Article 21 of the LSSI and reflects unlawful direct marketing practices. | ES | AEPD | ePrivacy | €2,000 | ↗ |
| 15 Jan 2021 | VODAFONE ESPAÑA, S.A.U.The Spanish data protection authority imposed a total fine of EUR 8,150,000 on VODAFONE ESPAÑA, S.A.U. The sanction covers breaches of GDPR Articles 28 and 44, as well as additional violations of LSSICE and tax-related rules. | ES | Agencia Española de Protección de Datos | GDPR | €8,150,000 | ↗ |
| 14 Jan 2021 | Agenzia regionale protezione ambientale Campania (ARPAC)ARPAC was fined by the Garante EUR 8,000 for violations concerning data security measures and data breach notification obligations. The case involved non-compliance with GDPR Articles 5 and 32. | IT | Garante | GDPR | €8,000 | ↗ |
| 14 Jan 2021 | Coop Finnmark SAThe Norwegian DPA fined Coop Finnmark SA 400,000 NOK for unlawfully sharing a surveillance video from a store. The store manager recorded the footage with a mobile phone and shared it without a legal basis, breaching GDPR principles. | NO | Datatilsynet | GDPR | €38,796 | ↗ |
| 14 Jan 2021 | IDFINANCE SPAIN, S.L.IDFINANCE SPAIN, S.L. was fined by the AEPD EUR 5,000 after an incident in which a user could access another customer's personal data and loan information through a faulty email link. The authority found breaches of GDPR Articles 5(1)(f) and 32 relating to security and confidentiality. | ES | AEPD | GDPR | €5,000 | ↗ |
| 14 Jan 2021 | Poliambulatorio Talenti S.r.l.Poliambulatorio Talenti S.r.l. was fined €2,000 by the Italian supervisory authority, Garante. The case concerned the improper handling of a data access request, which constitutes a breach of GDPR Article 5. | IT | Garante | GDPR | €2,000 | ↗ |
| 14 Jan 2021 | Azienda Ospedaliera San Pio di BeneventoAzienda Ospedaliera San Pio di Benevento was fined by the Garante 10,000 EUR for publishing employees’ personal data on its intranet without a proper legal basis. The case concerned unauthorized disclosure of personal data within the organization’s internal environment. | IT | Garante | GDPR | €10,000 | ↗ |
| 14 Jan 2021 | SIA "Lursoft IT"A fine of EUR 65,000 was imposed. The decision is final and has entered into force. | LV | DVI | GDPR | €65,000 | ↗ |
| 14 Jan 2021 | Comune di Falconara MarittimaComune di Falconara Marittima was fined EUR 10,000 by the Garante for violating data protection principles. The authority found improper processing of personal data in a disciplinary context, including breaches of lawfulness, fairness, transparency, and data minimization. | IT | Garante | GDPR | €10,000 | ↗ |
| 14 Jan 2021 | Azienda Usl di BolognaAzienda Usl di Bologna was fined by the Garante 18,000 EUR for violations related to personal data protection in the healthcare sector. The case concerned irregularities in the processing of patient data, which breached data protection requirements. | IT | Garante | GDPR | €18,000 | ↗ |
| 14 Jan 2021 | Azienda sanitaria provinciale di EnnaAzienda sanitaria provinciale di Enna was fined by the Garante €30,000 for unlawfully processing employees’ biometric data to monitor attendance. The conduct breached GDPR requirements on lawful processing and data minimisation. | IT | Garante | GDPR | €30,000 | ↗ |
| 14 Jan 2021 | VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD EUR 200,000 for continuing to send emails to a complainant despite earlier sanctions for similar conduct. The authority treated this as a recurring breach of GDPR Article 6.1, indicating processing without a valid legal basis. | ES | AEPD | GDPR | €200,000 | ↗ |
| 12 Jan 2021 | ASOCIACIÓN CULTURAL ***ASOCIACIÓN.1The association was fined for sharing images of a minor in WeChat groups without parental consent. The authority found a breach of GDPR Article 6(1)(a). | ES | AEPD | GDPR | €3,000 | ↗ |
| 11 Jan 2021 | RIPOBRUNA 2007, S.L.RIPOBRUNA 2007, S.L. was fined by the AEPD 2,000 EUR for installing surveillance cameras directed toward public spaces without justified cause. The authority found this processing to be contrary to data protection principles. | ES | AEPD | GDPR | €2,000 | ↗ |
| 11 Jan 2021 | Dane anonimowe (M. S.A. z siedzibą w Z. przy ul.)The President of UODO imposed an administrative fine of PLN 136,437 on M. S.A. The penalty was issued because the company did not report a personal data breach to the supervisory authority without undue delay. | PL | UODO | GDPR | €30,123 | ↗ |
| 08 Jan 2021 | C.C.C.C.C.C. was fined EUR 2,000 by the AEPD. The authority found that the company failed to provide a written contract and did not inform the complainant about the processing of personal data, in breach of Article 13 GDPR. | ES | AEPD | GDPR | €2,000 | ↗ |