BULLETIN №083Last updated · 06 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -22.8%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 22 Sept 2020 | VENU SANZ CHEF, S.L.VENU SANZ CHEF, S.L. used a client's personal data, including full name, profile photo, and health information, for advertising purposes without consent. The AEPD found this conduct to be a breach of data protection rules. | ES | AEPD | GDPR | €3,000 | ↗ |
| 21 Sept 2020 | CONSEGURIDAD S.L.CONSEGURIDAD S.L. was fined 50,000 EUR by the AEPD for failing to appoint a Data Protection Officer. The authority found a breach of Article 37(1)(b) of the GDPR. | ES | AEPD | GDPR | €50,000 | ↗ |
| 21 Sept 2020 | AVATA HISPANIA, S.L.AVATA HISPANIA, S.L. was fined by the AEPD 5,000 EUR for using personal data after the contract had ended. The company acted as a data processor, and continued use of the data was inconsistent with its obligations in that role. | ES | AEPD | GDPR | €5,000 | ↗ |
| 17 Sept 2020 | Azienda Ospedaliera di Rilievo Nazionale “Antonio Cardarelli"The Garante imposed an EUR 80,000 fine on Azienda Ospedaliera di Rilievo Nazionale “Antonio Cardarelli” for a data breach involving sensitive health data. The incident occurred during a platform maintenance period, indicating insufficient safeguards around processing. | IT | Garante | GDPR | €80,000 | ↗ |
| 17 Sept 2020 | Scanshare s.r.l.Scanshare s.r.l. was fined by the Garante 60,000 EUR for inadequate technical and organizational measures in handling candidate data during a hospital recruitment process. The authority also found a breach of GDPR Article 13 because the required information was not provided to candidates. | IT | Garante | GDPR | €60,000 | ↗ |
| 11 Sept 2020 | BODEGAS DINASTIA, S.L.BODEGAS DINASTIA, S.L. was fined by the AEPD EUR 2,000 for non-compliance with data protection rules on its websites. The issues concerned the privacy policy and the way cookie consent was obtained. | ES | AEPD | ePrivacy | €2,000 | ↗ |
| 08 Sept 2020 | Sanatatea Press Group S.R.L.Sanatatea Press Group S.R.L. was fined EUR 2,000 by ANSPDCP for a data security breach during an online event. Login details were mistakenly sent to incorrect email addresses, resulting in disclosure of information to unauthorized recipients. | RO | ANSPDCP | GDPR | €2,000 | ↗ |
| 08 Sept 2020 | XFERA MÓVILES, S.A.XFERA MÓVILES, S.A. was fined by the AEPD €40,000 for processing personal data without a legal basis. The case involved fraudulent contracts created in individuals’ names without their consent, breaching the principle of lawful processing. | ES | AEPD | GDPR | €40,000 | ↗ |
| 03 Sept 2020 | Comune di CasaloldoComune di Casaloldo was fined by the Garante for publishing personal data on its institutional website without an appropriate legal basis. The conduct breached the principles of lawfulness, fairness, transparency, and data minimization. | IT | Garante | GDPR | €2,000 | ↗ |
| 03 Sept 2020 | Deichmann Cipőkereskedelmi Korlátolt Felelősségű TársaságThe company failed to respond properly to data subject requests for access and restriction of processing. The authority also found inadequate technical and organizational measures for the processing of CCTV data. | HU | NAIH | GDPR | €55,800 | ↗ |
| 01 Sept 2020 | Asociația de proprietari Bl. FC 5, orașul Năvodari, județul ConstanțaThe homeowners' association was fined by ANSPDCP EUR 500 for unlawfully processing an individual's image from the video surveillance system. The image was displayed on the building's notice board, which breached data processing principles. | RO | ANSPDCP | GDPR | €500 | ↗ |
| 01 Sept 2020 | Geanonimiseerd (APD 53/2020)A politician was fined for sending an election propaganda email without consent. The authority found unlawful processing of personal data and a failure to implement appropriate technical and organizational measures. | BE | APD | GDPR | €2,000 | ↗ |
| 01 Sept 2020 | Iweb Internet Learning, S.L.Iweb Internet Learning, S.L. was fined by the AEPD EUR 13,000 for failing to inform data subjects about the processing of their personal data. The authority also found the use of storage and retrieval devices without the required notice or consent. | ES | AEPD | ePrivacy | €13,000 | ↗ |
| 01 Sept 2020 | B.B.B.The entity was fined by the AEPD €5,000 for using a webcam to record video and audio without justification. The conduct infringed privacy by monitoring private conversations and activities inside a rented residence. | ES | AEPD | GDPR | €5,000 | ↗ |
| 26 Aug 2020 | Anonymizováno (ÚOOÚ UOOU-03916/19-49)The entity was fined for sending unsolicited commercial communications without a valid legal basis. The conduct violated the Czech law on certain information society services. | CZ | UOOU | ePrivacy | €228,000 | ↗ |
| 24 Aug 2020 | Głównego Geodetę KrajuUODO imposed a fine of PLN 100,000 on the Chief Surveyor of Poland. The authority found a breach of the lawfulness principle in personal data processing due to the intentional disclosure, without a legal basis, of land and mortgage register numbers obtained from the land and building records. | PL | UODO | GDPR | €22,735 | ↗ |
| 21 Aug 2020 | ZSOUODO imposed a PLN 50,000 fine on ZSO for breaching personal data protection rules. The case concerned non-compliance with requirements under data protection regulations. | PL | UODO | GDPR | €11,369 | ↗ |
| 19 Aug 2020 | Anonymizováno (ÚOOÚ UOOU-05284/19-36)The entity was fined for publishing a partially anonymized criminal order on Facebook that still contained personal data. The authority found a breach of GDPR principles governing lawful processing and personal data protection. | CZ | UOOU | GDPR | €383 | ↗ |
| 18 Aug 2020 | HSEThe Irish DPC fined HSE EUR 65,000 in inquiry IN-19-9-1. The fine was collected. | IE | DPC | GDPR | €65,000 | ↗ |
| 13 Aug 2020 | Engedményezés után kezelt telefonszám és e-mail címThe case concerned unlawful processing of personal data in connection with debt collection. The controller was fined for breaching the GDPR principles of data minimization and lawful basis. | HU | NAIH | GDPR | €5,800 | ↗ |