BULLETIN №083Last updated · 06 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -22.8%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 06 Mar 2020 | IBERDROLA CLIENTES, SAUIBERDROLA CLIENTES, SAU was fined by the AEPD in the amount of EUR 5,000 for failing to provide requested information to the data protection authority. The conduct breached Article 58(1) of the GDPR. | ES | AEPD | GDPR | €5,000 | ↗ |
| 06 Mar 2020 | B.B.B.A private individual was fined by the AEPD €1,000 for installing surveillance cameras without the required informational signage. The case concerned a breach of data protection rules linked to proper notice for video surveillance. | ES | AEPD | GDPR | €1,000 | ↗ |
| 06 Mar 2020 | BANCO BILBAO VIZCAYA ARGENTARIA, S.A.BBVA was fined by the AEPD for inaccurate processing of personal data. The bank demanded payment for a debt the complainant did not owe and shared the complainant’s personal data with a debt collection agency. | ES | AEPD | GDPR | €60,000 | ↗ |
| 05 Mar 2020 | S.Á.Á.S.Á.Á. was fined for a data breach in which a former employee received sensitive patient information. The authority found that technical and organizational measures were inadequate. | IS | Persónuvernd | GDPR | €21,090 | ↗ |
| 05 Mar 2020 | Fjölbrautaskólinn í BreiðholtiFjölbrautaskólinn í Breiðholti was fined by Persónuvernd after a teacher accidentally sent sensitive personal data about students to unauthorized recipients. The authority found that the school had not implemented adequate technical and organizational measures to protect data security. | IS | Persónuvernd | GDPR | €9,139 | ↗ |
| 05 Mar 2020 | Comune di San Giorgio JonicoComune di San Giorgio Jonico was fined by the Garante for publishing personal data on its institutional website. The authority found breaches of lawfulness, fairness, transparency, and data minimization principles. | IT | Garante | GDPR | €3,000 | ↗ |
| 05 Mar 2020 | CoolblueCoolblue was fined 40,000 EUR by the Dutch Data Protection Authority, Autoriteit Persoonsgegevens, for unlawfully collecting personal data through cookies without active consent. The violation occurred in 2020, and the company updated its cookie banner after the authority’s investigation. | NL | Autoriteit Persoonsgegevens | GDPR | €40,000 | ↗ |
| 05 Mar 2020 | Azienda Sanitaria Locale di Ciriè, Chivasso e Ivrea (ASL TO4)ASL TO4 was fined by the Garante EUR 8,000 for unlawful data processing through video surveillance. The authority found that the required agreements with unions were not in place. | IT | Garante | GDPR | €8,000 | ↗ |
| 04 Mar 2020 | Fotó készítése és közzététele Facebookon hozzájárulás nélkülThe authority found unlawful processing and publication of personal data without a valid legal basis. A fine was imposed and the image had to be deleted from Facebook. | HU | NAIH | GDPR | €299 | ↗ |
| 03 Mar 2020 | SANGIL Y GARCÍA, S.L.SANGIL Y GARCÍA, S.L. was fined by the AEPD 1,800 EUR for sending promotional emails using personal data obtained from the Boletín Oficial de la Propiedad Industrial. The company had no prior client relationship with the recipients, which breached data protection rules. | ES | AEPD | ePrivacy | €1,800 | ↗ |
| 03 Mar 2020 | Koninklijke Nederlandse Lawn Tennisbond (KNLTB)KNLTB was fined EUR 525,000 by the Dutch data protection authority AP. The authority found that the association unlawfully shared member data with sponsors for direct marketing without a valid legal basis and in breach of the purpose limitation principle. | NL | AP | GDPR | €525,000 | ↗ |
| 27 Feb 2020 | Tim S.p.A.The Italian data protection authority imposed a EUR 27.8 million fine on Tim S.p.A. The case concerned privacy violations in marketing and telemarketing activities, including issues with obtaining valid consent. | IT | Garante per la protezione dei dati personali | GDPR | €27,800,000 | ↗ |
| 26 Feb 2020 | Comune di Fogliano RedipugliaThe Municipality of Comune di Fogliano Redipuglia was fined by the Garante for unlawfully publishing personal data on its institutional website. The authority found breaches of lawfulness, fairness, transparency, and data minimization principles. | IT | Garante | GDPR | €6,000 | ↗ |
| 26 Feb 2020 | Comune di AstiComune di Asti was fined EUR 8,000 by the Garante for unlawfully publishing personal data on the web. The authority found breaches of lawfulness, fairness, transparency, and data minimization principles. | IT | Garante | GDPR | €8,000 | ↗ |
| 25 Feb 2020 | Addiko Bank d.d.The High Administrative Court of the Republic of Croatia upheld AZOP’s decision of 25 February 2020 against Addiko Bank d.d. The confirmed administrative fine was 145,995.09 EUR for obstructing customers’ access to their personal data and credit documentation. | HR | AZOP | GDPR | €145,000 | ↗ |
| 24 Feb 2020 | BANKIA, S.A.BANKIA, S.A. was fined by the AEPD EUR 50,000 for sending commercial advertising by postal mail to a customer who had objected to the processing of their data for advertising purposes. The authority found this conduct contrary to GDPR Article 6(1)(f). | ES | AEPD | GDPR | €50,000 | ↗ |
| 19 Feb 2020 | CITRICOS Y FRUTALES DEL SURESTE, S.L.CITRICOS Y FRUTALES DEL SURESTE, S.L. was fined by the AEPD 3,000 EUR for installing video surveillance in common areas without approval from the property owners' association and without obtaining explicit consent from affected individuals. The authority found breaches of GDPR Articles 5(1)(c) and 13. | ES | AEPD | GDPR | €3,000 | ↗ |
| 18 Feb 2020 | Equifax Iberica, S.L.Equifax Iberica, S.L. was fined by the AEPD in the amount of 75,000 EUR for processing personal data without a proper legal basis. The authority cited a breach of Article 6(1)(f) of the GDPR. | ES | AEPD | GDPR | €75,000 | ↗ |
| 18 Feb 2020 | VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined 70,000 EUR by the AEPD for incorrectly linking a customer's phone lines to another person's details. The case concerned a breach of data protection rules and indicated deficiencies in personal data processing. | ES | AEPD | GDPR | €70,000 | ↗ |
| 18 Feb 2020 | ZSZZS.440.768.2018StatusuchylonaTytuUODO found a breach related to the processing of children’s biometric data in connection with use of the school canteen. A fine of PLN 20,000 was imposed. | PL | UODO | GDPR | €4,679 | ↗ |