BULLETIN №083Last updated · 06 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -22.8%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 02 Jul 2020 | Mapei S.p.A.Mapei S.p.A. was fined EUR 15,000 by the Italian authority Garante. The case concerned the failure to respond to a request for access to email communications and the failure to delete an email account after employment ended, in breach of GDPR principles. | IT | Garante | GDPR | €15,000 | ↗ |
| 02 Jul 2020 | Głównego Geodetę Kraju z siedzibą w Warszawie przy ul.UODO imposed a fine of PLN 100,000 on the Chief Surveyor of Poland based in Warsaw. The sanction concerned failure to provide access during an inspection to rooms, equipment and tools used for personal data processing, as well as access to personal data and information. | PL | UODO | GDPR | €22,351 | ↗ |
| 02 Jul 2020 | Istituto Nazionale della Previdenza Sociale-Direzione Provinciale di BresciaThe Italian Data Protection Authority fined the INPS Brescia Provincial Directorate for failing to respond to a request for access to personal health data. The authority found a breach of data protection rules. | IT | Garante | GDPR | €5,000 | ↗ |
| 02 Jul 2020 | Istituto Comprensivo di Uggiano La ChiesaIstituto Comprensivo di Uggiano La Chiesa was fined €2,000 by the Garante for posting lists at the school entrance that included minors' names, dates of birth, addresses, phone numbers, and vaccination status. The authority found breaches of lawfulness, fairness, transparency, and data minimization principles. | IT | Garante | GDPR | €2,000 | ↗ |
| 02 Jul 2020 | Regione CampaniaRegione Campania was fined EUR 4,000 by the Garante. The authority found a breach of the data minimization principle after personal data was published online without a proper legal basis. | IT | Garante | GDPR | €4,000 | ↗ |
| 02 Jul 2020 | GTL s.r.l.GTL s.r.l. was fined EUR 3,000 by the Garante for failing to respond to an individual's data access request. The authority treated this as a breach of GDPR obligations. | IT | Garante | GDPR | €3,000 | ↗ |
| 02 Jul 2020 | Comune di ManduriaComune di Manduria was fined by the Garante in the amount of 2,000 EUR for breaching data protection principles, including lawfulness, fairness, and transparency. The authority found that personal data had been improperly disseminated through journalistic outlets. | IT | Garante | GDPR | €2,000 | ↗ |
| 02 Jul 2020 | Comune di Greve in ChiantiComune di Greve in Chianti was fined by the Garante for unlawfully disclosing personal data relating to criminal convictions and proceedings. The conduct breached the principles of lawfulness, fairness, and transparency in data processing. | IT | Garante | GDPR | €4,000 | ↗ |
| 02 Jul 2020 | CENTRO INTERNACIONAL DE CRECIMIENTO LABORAL Y PROFESIONAL, S.L.The entity sent unsolicited commercial emails without the recipients’ consent. It also failed to provide a valid unsubscribe option, which breached the LSSI. | ES | AEPD | ePrivacy | €1,000 | ↗ |
| 01 Jul 2020 | XFERA MÓVILES, S.A.XFERA MÓVILES, S.A. was fined by the Spanish Data Protection Agency (AEPD) for failing to provide requested information. The breach concerned cooperation obligations under data protection rules. | ES | AEPD | GDPR | €5,000 | ↗ |
| 01 Jul 2020 | ANMAVAS 61, S.L. (LA CUEVA SEX CLUB)ANMAVAS 61, S.L. did not respond to a data subject’s request for erasure. The AEPD imposed a fine of EUR 2,000 for breaching GDPR obligations. | ES | AEPD | GDPR | €2,000 | ↗ |
| 01 Jul 2020 | COMUNIDAD DE PROPIETARIOS R.R.R.COMUNIDAD DE PROPIETARIOS R.R.R. was fined by the AEPD for publishing a resident’s personal data on a community notice board. The conduct breached data protection rules. | ES | AEPD | GDPR | €10,000 | ↗ |
| 01 Jul 2020 | CAFÉ RESTAURANTE B.B.B.The entity installed a surveillance camera facing a public space, despite recommendations from the local police. This breached data protection regulations. | ES | AEPD | GDPR | €1,500 | ↗ |
| 30 Jun 2020 | VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD 15,000 EUR for incorrectly listing a customer's ex-spouse as the account holder, even though the customer's data appeared on invoices. The company acknowledged responsibility and paid the reduced fine. | ES | AEPD | GDPR | €15,000 | ↗ |
| 30 Jun 2020 | AOK Baden-WürttembergThe Baden-Württemberg data protection authority fined AOK Baden-Württemberg EUR 1.24 million on 2020-06-30. It found that personal data from more than 500 contest participants was processed for advertising purposes without valid consent, and that the technical and organizational measures required under Article 32 GDPR were insufficient. | DE | Landesbeauftragter für den Datenschutz und die Informationsfreiheit Baden-Württemberg | GDPR | €1,240,000 | ↗ |
| 30 Jun 2020 | Lejre KommuneLejre Kommune was fined by Datatilsynet for failing to implement appropriate security measures. This led to unauthorized access to sensitive personal data, including information about minors. | DK | Datatilsynet | GDPR | €6,709 | ↗ |
| 29 Jun 2020 | VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD EUR 60,000 for unauthorized processing of personal data. The case involved a fraudulent contract and the porting of a customer's phone line without a valid legal basis. | ES | AEPD | GDPR | €60,000 | ↗ |
| 29 Jun 2020 | NEW YORK COLLEGE A.ENEW YORK COLLEGE A.E was fined EUR 5,000 by the HDPA for conducting targeted phone calls without providing the required GDPR information. The authority found breaches of data processing principles and accountability obligations. | GR | HDPA | GDPR | €5,000 | ↗ |
| 26 Jun 2020 | ESLORA PROYECTOS, S.L.ESLORA PROYECTOS, S.L. was fined by the AEPD 10,000 EUR for failing to provide cookie information and for not obtaining user consent before using cookies. The authority cited a breach of Article 22.2 of the LSSI. | ES | AEPD | ePrivacy | €10,000 | ↗ |
| 24 Jun 2020 | Azienda Sanitaria Universitaria Giuliano IsontinaAzienda Sanitaria Universitaria Giuliano Isontina was fined by the Garante for unlawfully communicating health data without an adequate legal basis. The conduct breached Article 20 of the Italian Privacy Code. | IT | Garante | GDPR | €10,000 | ↗ |