BULLETIN №083Last updated · 05 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -22.5%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 01 Jan 2021 | DAVISER SERVICIOS, S.L.DAVISER SERVICIOS, S.L. was fined by the AEPD 20,000 EUR for using biometric data from fingerprint readers and surveillance cameras without properly informing employees. The authority found this to be a breach of data protection principles. | ES | AEPD | GDPR | €20,000 | ↗ |
| 01 Jan 2021 | LYNGUAL GMBHLYNGUAL GMBH was fined by the AEPD 3,000 EUR for sending unsolicited commercial emails. The messages continued despite the recipient’s attempts to unsubscribe and requests to stop communications. | ES | AEPD | ePrivacy | €3,000 | ↗ |
| 01 Jan 2021 | B.B.B.The sanctioned individual installed a video surveillance camera covering common areas without informed consent. This breached data protection rules and led to a fine imposed by the AEPD. | ES | AEPD | GDPR | €1,500 | ↗ |
| 01 Jan 2021 | JUBASER DE CONTROL, S.L.JUBASER DE CONTROL, S.L. was fined by the AEPD 5,000 EUR for unlawful processing of personal data. The case concerned improper handling of a customer's ID and personal information, which later appeared on an adult contact website. | ES | AEPD | GDPR | €5,000 | ↗ |
| 01 Jan 2021 | Dña. B.B.B.The entity was fined for publishing personal images and contact numbers on a dating website without proper consent. The authority found a breach of Article 6(1) of the GDPR. | ES | AEPD | GDPR | €2,000 | ↗ |
| 01 Jan 2021 | RODALI GESTIÓN INMOBILIARIA, S.L.RODALI GESTIÓN INMOBILIARIA, S.L. was fined by the AEPD 5,000 EUR for failing to provide clients with information about the processing of their personal data. The authority found a breach of Article 13 of the GDPR. | ES | AEPD | GDPR | €5,000 | ↗ |
| 01 Jan 2021 | ASOCIACIÓN ESPAÑOLA PARA LA ENSEÑANZA ONLINEThe entity was fined by the AEPD for sending advertising emails without the recipients’ consent. It also failed to comply with a request to delete personal data from its databases. | ES | AEPD | ePrivacy | €5,000 | ↗ |
| 01 Jan 2021 | ORANGE ESPAGNE, S.A.U.ORANGE ESPAGNE, S.A.U. was fined 100,000 EUR by the AEPD for requiring customers to submit photographs of both sides of their ID cards as a condition for package delivery. The authority found that this practice breached data protection principles. | ES | AEPD | GDPR | €100,000 | ↗ |
| 01 Jan 2021 | ORANGE ESPAÑA VIRTUAL, S.L.SIMYO was fined for failing to adequately protect personal data, which enabled unauthorized SIM card duplication. The incident led to fraudulent bank transactions and indicates significant security shortcomings. | ES | AEPD | GDPR | €70,000 | ↗ |
| 01 Jan 2021 | CLUB DEPORTIVO RITMO DE ANDALUCÍAThe club was fined by the AEPD 4,000 EUR for failing to adequately inform users about the processing of their personal data. The authority also found that users were not given the opportunity to provide free and voluntary consent for each specific processing purpose. | ES | AEPD | GDPR | €4,000 | ↗ |
| 01 Jan 2021 | Município de LisboaThe Portuguese data protection authority fined Município de Lisboa EUR 1,250,000 in 2021. The sanction concerned the unlawful transfer of protesters’ personal data to the Russian Embassy in breach of the GDPR. | PT | Comissão Nacional de Proteção de Dados | GDPR | €1,250,000 | ↗ |
| 01 Jan 2021 | ASM PRATASM PRAT was fined EUR 5,000 by the AEPD for requiring recipients to submit photos of their ID cards without consent. The company also failed to provide information about the data processing, which breached data protection rules. | ES | AEPD | GDPR | €5,000 | ↗ |
| 30 Dec 2020 | B.B.B.The entity was fined by the AEPD in the amount of 1,500 EUR. The violation concerned installing surveillance cameras directed toward public areas without the required authorization and without compliant informational signage. | ES | AEPD | GDPR | €1,500 | ↗ |
| 23 Dec 2020 | Anonymizováno (ÚOOÚ UOOU-02528/20-14)The entity was fined by the UOOU for breaching a legal prohibition on disclosing personal data under another regulation. The case concerned information about criminal proceedings and the persons involved. | CZ | UOOU | GDPR | €38 | ↗ |
| 22 Dec 2020 | Anonymizováno (ÚOOÚ UOOU-004103/19-31)The company was fined for unlawfully processing personal data of members of homeowners' associations by publishing the data on its website without consent. The authority found this conduct to be in breach of the GDPR. | CZ | UOOU | GDPR | €1,141 | ↗ |
| 17 Dec 2020 | Dane anonimowe (J.)The UODO imposed a fine of PLN 1,069,850 on Anonymous data (J.) for breaching personal data protection rules. The case concerned unlawful processing of personal data. | PL | UODO | GDPR | €240,000 | ↗ |
| 17 Dec 2020 | University College DublinThe Irish DPC imposed a fine of EUR 70,000 on University College Dublin in inquiry IN-19-7-4. The fine has been collected. | IE | DPC | GDPR | €70,000 | ↗ |
| 17 Dec 2020 | Roma CapitaleRoma Capitale was fined 500,000 EUR by the Garante for violations related to the processing of personal data in the TuPassi system. The authority also identified shortcomings in the information provided to users. | IT | Garante | GDPR | €500,000 | ↗ |
| 17 Dec 2020 | Comune di Santo Stefano BelboComune di Santo Stefano Belbo was fined for unlawfully disclosing personal data, including names and legal information, on its website without a proper legal basis. The case concerned the publication of data that should not have been made publicly available. | IT | Garante | GDPR | €4,000 | ↗ |
| 17 Dec 2020 | Azienda Unità Sanitaria Locale Toscana Sud EstAzienda Unità Sanitaria Locale Toscana Sud Est was fined for processing personal data without proper safeguards. The authority also found that patient data was shared without anonymization, in breach of GDPR requirements. | IT | Garante | GDPR | €100,000 | ↗ |