BULLETIN №083Last updated · 05 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -22.5%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 02 Dec 2020 | Sahlgrenska UniversitetssjukhusetSahlgrenska University Hospital was fined SEK 3.5 million for failing to perform the required needs and risk analysis before granting access rights in its medical record systems. The authority found this breached GDPR requirements on data security and accountability. | SE | IMY | GDPR | €340,000 | ↗ |
| 02 Dec 2020 | Region ÖstergötlandRegion Östergötland was fined by IMY for failing to perform a needs and risk analysis before granting access rights in its journal system. The authority found that this breached several GDPR provisions. | SE | IMY | GDPR | €243,000 | ↗ |
| 02 Dec 2020 | Karolinska UniversitetssjukhusetKarolinska Universitetssjukhuset was fined by IMY for failing to conduct a needs and risk analysis before granting access rights in its TakeCare journal system. The authority found this breached GDPR requirements on data security and accountability. | SE | IMY | GDPR | €389,000 | ↗ |
| 02 Dec 2020 | Aleris Närsjukvård ABAleris Närsjukvård AB was fined by IMY for failing to conduct a needs and risk analysis before granting access rights in its medical record systems. The authority found this breached GDPR data security requirements. | SE | IMY | GDPR | €1,167,000 | ↗ |
| 02 Dec 2020 | Region VästerbottenThe Health and Medical Services Board of Region Västerbotten was fined for failing to conduct a needs and risk analysis before granting access rights in the NCS Cross journal system. The authority found this breached GDPR requirements on data security and accountability. | SE | IMY | GDPR | €243,000 | ↗ |
| 02 Dec 2020 | Capio S:t Görans Sjukhus ABCapio S:t Görans Sjukhus AB was fined by IMY for processing personal data in breach of GDPR. The authority found inadequate needs and risk analyses and insufficient restriction of user access to patient data in the journal systems. | SE | IMY | GDPR | €2,917,000 | ↗ |
| 02 Dec 2020 | Aleris Sjukvård ABAleris Sjukvård AB was fined by IMY for failing to conduct a needs and risk analysis before granting access rights in its TakeCare journal system. The authority found this breached GDPR security requirements. | SE | IMY | GDPR | €1,458,000 | ↗ |
| 27 Nov 2020 | CERTIME, S.A.CERTIME, S.A. was fined by the AEPD in the amount of 5,000 EUR for processing personal data for a purpose different from the one originally specified. The authority found this to be a breach of Article 5(1)(b) GDPR. | ES | AEPD | GDPR | €5,000 | ↗ |
| 26 Nov 2020 | Reti Televisive Italiane S.p.a.Reti Televisive Italiane S.p.a. was fined EUR 10,000 by the Garante for broadcasting a segment on “Le Iene” that included footage of an individual recorded without consent. The person was identifiable, which constituted a breach of data protection rules. | IT | Garante | GDPR | €10,000 | ↗ |
| 26 Nov 2020 | Concentrix Cvg Italy s.r.l.Concentrix Cvg Italy s.r.l. was fined 20,000 EUR by the Garante for violating GDPR principles. The case concerned a company policy that improperly handled employees' personal data, including a requirement to keep personal items visible on desks. | IT | Garante | GDPR | €20,000 | ↗ |
| 26 Nov 2020 | Ministero dell’InternoThe Ministry of the Interior was fined by the Garante for the unauthorized dissemination of video and images related to a police incident. The authority found a breach of GDPR rules governing the processing of personal data. | IT | Garante | GDPR | €60,000 | ↗ |
| 26 Nov 2020 | Charly Mike s.r.l.Charly Mike s.r.l. was fined by the Garante EUR 3,000 for improper use of a video surveillance system at Hotel Olimpo. The system was used for continuous monitoring and remote viewing of employees, in breach of data protection rules. | IT | Garante | GDPR | €3,000 | ↗ |
| 24 Nov 2020 | LSS-boendeGnosjö kommun - Socialutskottet was fined by IMY for unlawful video surveillance in an LSS residence. The authority found processing of personal and sensitive data without a legal basis and no data protection impact assessment. | SE | IMY | GDPR | €19,600 | ↗ |
| 23 Nov 2020 | Utbildningsnämnden i Stockholms stad, SkolplattformenThe Education Committee of Stockholm City was fined by IMY 4,000,000 SEK for processing personal data in breach of GDPR Articles 5 and 32. The authority cited inadequate security measures and failure to conduct impact assessments for systems handling sensitive student data. | SE | IMY | GDPR | €391,000 | ↗ |
| 19 Nov 2020 | ALTERNA OPERADOR INTEGRAL, S.L.ALTERNA OPERADOR INTEGRAL, S.L. was fined by the AEPD EUR 50,000 for changing an electricity provider without the customer's consent. The authority found that the processing lacked a valid legal basis under Article 6(1)(b) GDPR. | ES | AEPD | GDPR | €50,000 | ↗ |
| 17 Nov 2020 | PEDROSO Y GÓMEZ ASESORÍA DE EMPRESAS, S.L.The company was fined by the AEPD in the amount of 6,000 EUR for sending emails without the recipients' consent. The authority also noted the absence of contact information for exercising data protection rights. | ES | AEPD | GDPR | €6,000 | ↗ |
| 13 Nov 2020 | Y HuisvestingsmaatschappijThe social housing company was fined for breaching GDPR principles, including lawfulness and transparency in personal data processing. The authority also identified deficiencies in access rights handling and privacy policy transparency. | BE | APD | GDPR | €528,000 | ↗ |
| 13 Nov 2020 | B.B.B.The entity was fined EUR 1,500 by the AEPD for improperly installing a surveillance camera. The camera captured images of a public transit area without justified cause, which breached data protection rules. | ES | AEPD | GDPR | €1,500 | ↗ |
| 12 Nov 2020 | VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD EUR 70,000 for continuing to send billing emails to a complainant despite an arbitration ruling. The ruling required the company to stop all services and delete the complainant’s data, which it failed to do. | ES | AEPD | GDPR | €70,000 | ↗ |
| 12 Nov 2020 | Vodafone Italia S.p.A.Vodafone Italia S.p.A. was fined by the Garante 12,251,601 EUR for making unauthorized promotional calls and sending messages. The authority also found that effective measures to ensure data processing security and GDPR compliance were not in place. | IT | Garante | GDPR | €12,251,000 | ↗ |