BULLETIN №083Last updated · 06 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -22.8%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 24 Oct 2019 | Anonymizováno (ÚOOÚ UOOU-01096/19-19)The entity was fined by the UOOU for sending commercial communications without a valid legal basis. The messages were not properly identified as commercial and the sender was not correctly identified. | CZ | UOOU | ePrivacy | €391 | ↗ |
| 24 Oct 2019 | Magyar Honvédség Egészségügyi KözpontMagyar Honvédség Egészségügyi Központ was fined by NAIH 2,500,000 HUF. The authority found that the organization failed to report a data breach involving a VIP entry request form within the required 72-hour period and did not maintain an internal incident register. | HU | NAIH | GDPR | €7,600 | ↗ |
| 23 Oct 2019 | CERRAJERIA CARLOS RODRIGUEZ S.L.CERRAJERIA CARLOS RODRIGUEZ S.L. was fined by the AEPD EUR 1,500 for collecting personal data without providing the required information to the data subjects. The authority found a breach of Article 13 GDPR. | ES | AEPD | GDPR | €1,500 | ↗ |
| 23 Oct 2019 | CERRAJERIA VERIN S.L.CERRAJERIA VERIN S.L. was fined by the AEPD EUR 1,500 for collecting personal data without providing the required information to data subjects. The authority found a breach of Article 13 GDPR. | ES | AEPD | GDPR | €1,500 | ↗ |
| 23 Oct 2019 | SHOP MACOYN, S.L. (YBL ABOGADOS)SHOP MACOYN, S.L. was fined EUR 5,000 by the AEPD for disclosing email addresses in promotional emails. The case concerned a breach of data protection principles and the confidentiality of recipients’ personal data. | ES | AEPD | GDPR | €5,000 | ↗ |
| 22 Oct 2019 | IBERDROLA COMERCIALIZACIÓN DE ÚLTIMO RECURSO, S.A.U. (CURENERGIA COMERCIALIZADORA DE ULTIMO RECURSO, S.A.U.)CURENERGIA was fined EUR 75,000 by the AEPD for using a former client's personal data without consent. The data was used to carry out a fraudulent contract registration. The case indicates a breach of lawful processing and personal data protection requirements. | ES | AEPD | GDPR | €75,000 | ↗ |
| 21 Oct 2019 | Anonymizováno (ÚOOÚ UOOU-02928/19-13)The entity was fined for publishing personal data related to criminal proceedings on its website. The authority found a breach of GDPR rules on the processing and disclosure of personal data. | CZ | UOOU | GDPR | €1,561 | ↗ |
| 18 Oct 2019 | National Revenue Agency (Bulgaria)The Commission for Personal Data Protection imposed a fine of 5,100,000 BGN on Bulgaria’s National Revenue Agency. The sanction concerned the unauthorized disclosure and dissemination of personal data following a major security breach. | BG | Commission for Personal Data Protection | GDPR | €2,607,000 | ↗ |
| 18 Oct 2019 | Dane anonimowe (Burmistrza G. karę pieniężną w kwocie 40.000 zł)UODO found a breach of the principles of lawful processing and confidentiality. A fine of PLN 40,000 was imposed, together with an order to bring processing operations into compliance with data protection rules. | PL | UODO | GDPR | €9,336 | ↗ |
| 17 Oct 2019 | VODAFONE ESPAÑA, S.A.U.The AEPD fined Vodafone España, S.A.U. EUR 75,000 for incorrectly charging a customer's account and retaining inaccurate personal data. The case concerns breaches of data protection principles, including data accuracy and proper processing. | ES | AEPD | GDPR | €75,000 | ↗ |
| 16 Oct 2019 | Dane anonimowe (S. Sp. z o.o. z siedzibą w P., karę pieniężną w kwocie 201 559,50 PLN)UODO imposed a fine of PLN 201,559.50 on S. Sp. z o.o. for failing to implement appropriate technical and organizational measures. The authority also found that personal data were processed without a lawful basis, which led to the sanction. | PL | UODO | GDPR | €46,923 | ↗ |
| 15 Oct 2019 | Munkavállaló munkaeszközeinek ellenőrzéseThe controller unlawfully processed the complainant's personal data by reviewing and monitoring their email account without prior notice. This breached the principle of fair processing. | HU | NAIH | GDPR | €3,010 | ↗ |
| 09 Oct 2019 | Vreau Credit S.R.L.Vreau Credit S.R.L. was fined by ANSPDCP in the amount of 20,000 EUR for failing to notify a personal data breach without undue delay. The company had been aware of the incident since December 2018 but did not inform the supervisory authority promptly. | RO | ANSPDCP | GDPR | €20,000 | ↗ |
| 09 Oct 2019 | Vreau Credit S.R.L.Vreau Credit S.R.L. was fined by ANSPDCP for failing to notify the supervisory authority of a data breach without undue delay and for unauthorized processing of personal data. The violations resulted in a loss of data confidentiality and indicate inadequate compliance controls. | RO | ANSPDCP | GDPR | €150,000 | ↗ |
| 08 Oct 2019 | Министър на вътрешните работиThe Ministry of Interior was fined for unlawfully processing and sharing the personal data of a Finnish citizen with Togo authorities without a legal basis. The authority found a breach of GDPR principles on lawful processing and data disclosure. | BG | CPDP | GDPR | €5,113 | ↗ |
| 07 Oct 2019 | Анонимизирано (CPDP решение-по-жалба-с-рег-№-ппн-01-657-08-0)The Bulgarian data protection authority, CPDP, fined an individual, V.M., BGN 1,000. The sanction concerned failure to provide access to information requested by the authority in connection with a complaint about unlawful dissemination of personal data. | BG | CPDP | GDPR | €511 | ↗ |
| 07 Oct 2019 | OTEOTE was fined by the HDPA EUR 200,000 for failing to process unsubscribe requests from marketing emails due to a technical error. The issue affected about 8,000 subscribers and had been ongoing since 2013. | GR | HDPA | GDPR | €200,000 | ↗ |
| 04 Oct 2019 | Kerepes Város Települési ÖnkormányzataThe municipality of Kerepes was fined for unlawful processing of personal data through security cameras. The authority found a GDPR breach because data subjects were not informed in advance. | HU | NAIH | GDPR | €15,050 | ↗ |
| 02 Oct 2019 | Tgroup s.r.l.Tgroup s.r.l. was fined 6,400 EUR by the Italian data protection authority, Garante. The case concerned the activation of a SIM card without the user's knowledge, which breached data protection rules. | IT | Garante | GDPR | €6,400 | ↗ |
| 25 Sept 2019 | ASOCIACION DE MEDICOS DEMOCRATASASOCIACION DE MEDICOS DEMOCRATAS was fined by the AEPD EUR 10,000 for processing the personal data of medical professionals without their consent. The authority found a breach of Article 6(1)(a) GDPR. | ES | AEPD | GDPR | €10,000 | ↗ |