BULLETIN №081Last updated · 27 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -20.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 22 Jun 2021 | VirksomhetenThe Norwegian DPA fined Virksomheten NOK 150,000 for accessing a former employee’s email account without a legal basis and for failing to close the account. The authority found breaches of GDPR rules on information duties, data deletion, and handling objections. | NO | Datatilsynet | GDPR | €14,678 | ↗ |
| 09 Jan 2014 | Virano s.n.c. di Virano Franco & C.Virano s.n.c. was fined by the Garante for collecting personal data through its website without providing an adequate privacy notice. The authority found a breach of Article 13 of the Italian Privacy Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 27 Jul 2012 | VIPVENTA, S.L.VIPVENTA, S.L. was fined EUR 30,001 by the AEPD for sending unsolicited commercial emails to the complainant. The authority found this conduct breached Article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €30,001 | ↗ |
| 30 Apr 2020 | vingerafdrukken personeelThe Autoriteit Persoonsgegevens imposed a fine for the unlawful processing of employees' biometric data, specifically fingerprints, for time registration purposes. The authority found this to be a breach of Article 9 of the GDPR. | NL | AP | GDPR | €725,000 | ↗ |
| 14 Mar 2013 | Vinci s.r.l.Vinci s.r.l. was fined €6,000 by the Italian data protection authority, Garante. The case concerned the failure to provide the required privacy notice on the website contact form, in breach of Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €6,000 | ↗ |
| 11 Apr 2019 | Vincall s.r.l.sVincall s.r.l.s was fined EUR 2,018,000 by the Garante for failing to provide required information to individuals contacted during telemarketing activities. The authority found this to be a breach of data protection rules. | IT | Garante | GDPR | €2,018,000 | ↗ |
| 25 Sept 2025 | Vimar S.p.A.Vimar S.p.A. was fined EUR 15,000 by the Garante for failing to provide adequate information to a complainant and for improper account handling. The account was accessible to unauthorized individuals, indicating weaknesses in access control and safeguards. | IT | Garante | GDPR | €15,000 | ↗ |
| 13 Jan 2022 | Villa Masi Residenza per anzianiVilla Masi Residenza per anziani was fined EUR 1,000 by the Garante for a video surveillance system that did not comply with GDPR Article 13. The authority found that the required information notices for monitored individuals were not properly provided. | IT | Garante | GDPR | €1,000 | ↗ |
| 11 Sept 2014 | Villa dei Cedri s.p.a.Villa dei Cedri s.p.a. was fined by the Garante 2,400 EUR for failing to provide simplified information on the use of video surveillance systems. The authority found this to be a breach of privacy rules. | IT | Garante | GDPR | €2,400 | ↗ |
| 04 Oct 2011 | Villa Azzurra Hospital s.r.l.Villa Azzurra Hospital s.r.l. was fined by the Garante in the amount of 30,000 EUR for failing to comply with data processing notification requirements. The breach concerned obligations under the Italian Data Protection Code. | IT | Garante | GDPR | €30,000 | ↗ |
| 26 Jul 2018 | VILAN DATAMINING, S.L.VILAN DATAMINING, S.L. was fined by the AEPD in the amount of 1,600 EUR for sending unsolicited commercial emails without the required consent. The conduct breached article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €1,600 | ↗ |
| 26 Sept 2018 | VILAN DATAMINING SLVILAN DATAMINING SL was fined by the AEPD €800 for sending unsolicited commercial emails. The messages did not provide a way to exercise the rights of access, rectification, cancellation, or objection. | ES | AEPD | ePrivacy | €800 | ↗ |
| 10 Apr 2014 | Vienne s.r.l.Vienne s.r.l. was fined EUR 4,800 by the Italian data protection authority, Garante. The case concerned inadequate data protection notices for its video surveillance systems, in breach of the Italian Data Protection Code. | IT | Garante | GDPR | €4,800 | ↗ |
| 25 Nov 2015 | Video s.r.l.Video s.r.l. was fined by the Garante 25,000 EUR for registering 500 phone cards to five unaware individuals without their consent. The case concerns a breach of data protection rules and the absence of a lawful basis for processing personal data. | IT | Garante | GDPR | €25,000 | ↗ |
| 01 Jan 2019 | VIAQUA XESTIÓN INTEGRAL DE AUGAS DE GALICIA, S.A.The company changed contract data without authorization, which constituted a breach of Article 6 of the GDPR. The AEPD imposed a fine of 60,000 EUR. | ES | AEPD | GDPR | €60,000 | ↗ |
| 21 Oct 2013 | VIAJES INCENTIVE GOLF, S.L.VIAJES INCENTIVE GOLF, S.L. was fined by the AEPD 1,200 EUR for sending unsolicited emails. The authority also found that recipients' email addresses were not hidden, in breach of Article 21 of the LSSI. | ES | AEPD | ePrivacy | €1,200 | ↗ |
| 06 Sept 2011 | VIAJES IBERIA S.A. (ORIZINIA CORPORACION)VIAJES IBERIA S.A. was fined EUR 1,200 by the AEPD for sending unsolicited commercial communications to email addresses obtained from a university website. The company did not obtain proper consent or provide information about the source of the data. | ES | AEPD | ePrivacy | €1,200 | ↗ |
| 19 Jun 2019 | VF JEANSWEAR ESPAÑA S.L.VF Jeanswear España S.L. was fined by the AEPD 5,000 EUR for using cookies on its website without obtaining user consent. The case concerns a breach of data protection rules and consent requirements for cookies. | ES | AEPD | ePrivacy | €5,000 | ↗ |
| 28 Mar 2019 | Vestas s.r.l.Vestas s.r.l. was fined by the Garante 4,000 EUR for obtaining a single mandatory consent covering different processing purposes. This approach breached data protection rules because consent was not separated by purpose. | IT | Garante | GDPR | €4,000 | ↗ |
| 26 Feb 2024 | VESTAS CEU ROMÂNIA SRLThe company was fined EUR 3,000 by ANSPDCP for unauthorized disclosure of personal data. The breach included names, place of residence, salary, and CV details. | RO | ANSPDCP | GDPR | €3,000 | ↗ |