BULLETIN №083Last updated · 05 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -22.5%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 07 Nov 2020 | B.B.B.B.B.B. was fined by the AEPD EUR 2,000 for operating a video surveillance system directed toward public space. The measure affected the rights of third parties without justified cause and raised data protection compliance concerns. | ES | AEPD | GDPR | €2,000 | ↗ |
| 05 Nov 2020 | B.B.B.The entity was fined by the AEPD EUR 2,000 for using security cameras that recorded public spaces extensively without justification. The authority found that this breached data protection principles. | ES | AEPD | GDPR | €2,000 | ↗ |
| 05 Nov 2020 | DR MARÍN CIRUGIA PLÁSTICA, S.L.P.DR MARÍN CIRUGIA PLÁSTICA, S.L.P. was fined EUR 4,000 by the AEPD. The authority found that the company failed to provide a privacy policy on its website and used personal data for marketing purposes without consent. | ES | AEPD | ePrivacy | €4,000 | ↗ |
| 04 Nov 2020 | VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD 70,000 EUR for processing a fraudulent phone number portability request without the data subject's consent. The authority found a breach of GDPR Article 6(1). | ES | AEPD | GDPR | €70,000 | ↗ |
| 04 Nov 2020 | VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined EUR 60,000 by the AEPD after a contract was entered into using another person's identity. The case concerns a breach of data protection rules and insufficient identity verification. | ES | AEPD | GDPR | €60,000 | ↗ |
| 03 Nov 2020 | CANARYCLICK CONSULTING SLCANARYCLICK CONSULTING SL was fined EUR 8,000 by the AEPD for improper management of its cookie policy on its websites. The authority also found that user consent was collected in a generic manner, in breach of data protection rules. | ES | AEPD | GDPR | €8,000 | ↗ |
| 03 Nov 2020 | LOSADA ADVOCATS S.L.LOSADA ADVOCATS S.L. was fined by the AEPD EUR 10,000 for sending an email without using BCC. This exposed recipients’ email addresses and breached data protection principles. | ES | AEPD | GDPR | €10,000 | ↗ |
| 29 Oct 2020 | Ministero dell’InternoThe Italian Data Protection Authority fined the Ministry of the Interior EUR 50,000 for the incorrect disclosure of personal data to a limited number of organizations. It also ordered the Ministry to consider training initiatives to improve data accuracy. | IT | Garante | GDPR | €50,000 | ↗ |
| 29 Oct 2020 | Città Metropolitana di NapoliCittà Metropolitana di Napoli was fined EUR 8,000 by the Garante for improper handling of personal data. The authority found that a disciplinary document was not marked as confidential, which allowed unauthorized access within the administration. | IT | Garante | GDPR | €8,000 | ↗ |
| 29 Oct 2020 | Borgo Fonte Scura s.r.l.Borgo Fonte Scura s.r.l. was fined by the Garante 4,000 EUR for failing to provide proper data protection information to individuals, including employees, about the use of a video surveillance system at its premises. The authority found that the required privacy notice obligations were not met. | IT | Garante | GDPR | €4,000 | ↗ |
| 29 Oct 2020 | Gaypa s.r.l.Gaypa s.r.l. was fined EUR 20,000 by the Garante for continuing to use a personalized email account of a former employee after the employment ended. The authority found this conduct inconsistent with GDPR principles of lawfulness and purpose limitation. | IT | Garante | GDPR | €20,000 | ↗ |
| 27 Oct 2020 | VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined 50,000 EUR by the AEPD for requesting payment for services contracted without the complainant’s consent. The case concerns a data protection breach linked to processing and debt collection without a valid legal basis. | ES | AEPD | GDPR | €50,000 | ↗ |
| 26 Oct 2020 | ***EMPRESA.1.The company was fined by the AEPD 10,000 EUR for sending an email containing personal data of a former employee to a third party without authorization. The case involved a breach of data protection principles and unauthorized disclosure of information. | ES | AEPD | GDPR | €10,000 | ↗ |
| 26 Oct 2020 | ESTILO 1221, S.C.ESTILO 1221, S.C. was fined by the AEPD EUR 1,500 for sending unsolicited commercial emails without recipient consent. The conduct breached Article 21.1 of the LSSI, which prohibits this type of marketing communication without prior consent. | ES | AEPD | ePrivacy | €1,500 | ↗ |
| 22 Oct 2020 | Jogalap nélküli adattovábbítás mobilparkolási szolgáltatás kapcsánThe controller transferred the complainant's personal data to the complainant's employer without a valid legal basis. This breached the purpose limitation principle and the complainant's right of access. | HU | NAIH | GDPR | €5,480 | ↗ |
| 21 Oct 2020 | HEREDAD DE UREÑA, S.L.HEREDAD DE UREÑA, S.L. was fined by the AEPD EUR 4,000 for not having a privacy policy on its website, lacking a cookies policy, and sending unsolicited marketing emails without consent. The case indicates failures in basic transparency obligations and consent requirements for electronic communications. | ES | AEPD | GDPR | €4,000 | ↗ |
| 21 Oct 2020 | VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD EUR 60,000 for processing personal data without proper consent. The case involved a customer receiving a notification of a purchase they had not made, indicating improper use of personal data. | ES | AEPD | GDPR | €60,000 | ↗ |
| 19 Oct 2020 | Anonymisiert (DSB 2020-0.550.322)An individual was fined for unlawfully processing image data by using a smartphone to record a person in a restroom. The authority found a breach of the principles of lawfulness, fairness, and transparency under Art. 5 GDPR and no legal basis under Art. 6 GDPR. | AT | DSB | GDPR | €150 | ↗ |
| 19 Oct 2020 | Anonymisiert (DSB 2020-0.111.488)A fine of EUR 600 was imposed for publishing excerpts from patient letters and medical records on a personal Facebook page. The authority found that personal data and health data were processed without consent or another legal basis. | AT | DSB | GDPR | €600 | ↗ |
| 19 Oct 2020 | PREDASE SERVICIOS INTEGRALES SOCIEDAD LIMITADAPREDASE SERVICIOS INTEGRALES S.L. was fined EUR 5,000 by the AEPD for failing to publish a privacy policy on its website and for misleadingly using the AEPD logo. The conduct could imply an association with the authority and influence user decisions. | ES | AEPD | GDPR | €5,000 | ↗ |