BULLETIN №083Last updated · 05 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -22.5%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 15 Oct 2020 | Comune di CollegnoComune di Collegno was fined by the Garante for failing to respond in time to a data subject’s request for access to personal data. The authority found a breach of GDPR Article 15. | IT | Garante | GDPR | €2,000 | ↗ |
| 14 Oct 2020 | Munkahelyi kamerás megfigyelés célhoz kötöttséggel, adattakarékossággal és az érintettek tájékoztatásával kapcsolatos hiányosságaiThe entity was fined by NAIH in the amount of HUF 700,000 for improperly implementing camera surveillance of employees. The authority also found that employees were not adequately informed about the scope and rules of the video monitoring. | HU | NAIH | GDPR | €1,925 | ↗ |
| 08 Oct 2020 | Servicio de Alojamientos Responsables, S.L.The entity was fined by the AEPD 6,000 EUR for processing personal data without a legal basis. The breach involved signing a contract on behalf of an individual without authorization. | ES | AEPD | GDPR | €6,000 | ↗ |
| 08 Oct 2020 | Anonymizováno (ÚOOÚ UOOU-00179/19-38)The entity was fined for retaining personal data of financial service applicants longer than necessary, failing to inform them about potential data recipients, and lacking internal data protection measures. The authority found these practices inconsistent with data protection obligations. | CZ | UOOU | GDPR | €6,459 | ↗ |
| 07 Oct 2020 | UST GLOBAL ESPAÑA, S.A.UST Global España, S.A. was fined by the AEPD EUR 5,000 for improperly sharing employees’ personal data in a group email. The disclosed data included names, email addresses, and DNI numbers, which breached data protection principles. | ES | AEPD | GDPR | €5,000 | ↗ |
| 06 Oct 2020 | PROSAD CONSULTORES, S.L.PROSAD CONSULTORES, S.L. was fined by the AEPD 12,000 EUR for sending unsolicited commercial emails without prior consent. The authority found this conduct breached Article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €12,000 | ↗ |
| 05 Oct 2020 | Pontosság elvének megsértéseThe controller was fined for processing inaccurate personal data, in breach of the accuracy principle under GDPR Art. 5(1)(d). The authority also ordered correction of the complainant’s address data. | HU | NAIH | GDPR | €1,674 | ↗ |
| 02 Oct 2020 | INSTITUTO DEL DAÑO CEREBRAL Y PSÍQUICO, S.L.The entity did not provide timely access to clinical records, which constituted a breach of data protection obligations. Deficiencies were also identified in the website's cookie policy, leading the AEPD to impose a fine. | ES | AEPD | ePrivacy | €3,000 | ↗ |
| 02 Oct 2020 | GRUPO OCIO DESARROLLO Y SERVICIOS, S.L.The entity was fined by the AEPD in the amount of 1,500 EUR for sending unsolicited commercial communications via WhatsApp. The authority found a breach of the complainant's rights to data protection and to object to data processing. | ES | AEPD | ePrivacy | €1,500 | ↗ |
| 01 Oct 2020 | Asociația de proprietari Militari R, comuna Chiajna, județul IlfovThe homeowners' association was fined by ANSPDCP €2,000 for failing to respond to a data subject's request. The authority treated this as a breach of GDPR rules on the exercise of individual rights. | RO | ANSPDCP | GDPR | €2,000 | ↗ |
| 01 Oct 2020 | Università Campus Bio-medico di RomaThe Garante fined Università Campus Bio-medico di Roma 20,000 EUR for a data protection breach. Online medical reports were accessible to other patients, resulting in unauthorized disclosure of sensitive information. | IT | Garante | GDPR | €20,000 | ↗ |
| 01 Oct 2020 | Megareduceri TV S.R.L.Megareduceri TV S.R.L. was fined EUR 3,000 by ANSPDCP for violating GDPR provisions. The case concerned non-compliance with certain personal data protection obligations. | RO | ANSPDCP | GDPR | €3,000 | ↗ |
| 30 Sept 2020 | Követeléskezelő cég által végzett adatkezelés jogszerűségeThe authority imposed a fine for violating the data subject’s right to erasure because outdated address data was not deleted. It also found that personal data was processed without a proper legal basis. | HU | NAIH | GDPR | €2,740 | ↗ |
| 29 Sept 2020 | PLAY ORENES, S.L.PLAY ORENES, S.L. was fined by the AEPD €20,000 for improperly positioning surveillance cameras. The cameras captured public areas, which breached data protection rules. | ES | AEPD | GDPR | €20,000 | ↗ |
| 29 Sept 2020 | GABINETE PARAPSICOLÓGICO MYSTIC S.L.The entity was fined for sending unsolicited advertising SMS messages without the recipient's consent. This conduct breached Article 21 of the LSSI and constituted unlawful marketing communication. | ES | AEPD | ePrivacy | €2,500 | ↗ |
| 29 Sept 2020 | Geanonimiseerd (APD 64/2020)The Litigation Chamber fined the data controller for failing to close email accounts after employees left the company. The authority found breaches of GDPR principles of purpose limitation, data minimization, and storage limitation. | BE | APD | GDPR | €5,000 | ↗ |
| 29 Sept 2020 | Vodafone Magyarország Távközlési Zártkörűen Működő RészvénytársaságThe NAIH imposed a 60,000,000 HUF fine on Vodafone Magyarország for unlawful voice recording practices at customer service offices. The authority found GDPR breaches relating to legal basis, transparency, purpose limitation, and data minimization. | HU | NAIH | GDPR | €163,000 | ↗ |
| 25 Sept 2020 | SINDICATO DE TRABAJADORES DE LA ADMINISTRACIÓN PÚBLICA (STAP-CGT)The labor union STAP-CGT was fined EUR 3,000 by the AEPD for unlawful processing of personal data. The case concerned publishing a video of a court hearing on YouTube without proper consent, in breach of GDPR Article 6(1)(a). | ES | AEPD | GDPR | €3,000 | ↗ |
| 25 Sept 2020 | THE WASHPOINT S.L.THE WASHPOINT S.L. was fined by the AEPD 2,000 EUR for lacking a privacy policy and for having an improper cookie policy on its website. The breach concerned Article 13 of the GDPR and Article 22.2 of the LSSI. | ES | AEPD | ePrivacy | €2,000 | ↗ |
| 24 Sept 2020 | BRONSON BAR, S.L.BRONSON BAR, S.L. was fined 2,000 EUR by the AEPD. The company used the reverse side of a contract to create an inventory, which was then publicly displayed, breaching data integrity and confidentiality principles. | ES | AEPD | GDPR | €2,000 | ↗ |