BULLETIN №083Last updated · 06 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -22.8%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 24 Sept 2019 | VUELING AIRLINES, S.L.VUELING AIRLINES, S.L. was fined by the AEPD 30,000 EUR for failing to comply with cookie consent requirements on its website. The authority found that the company did not provide the required information and did not properly obtain user consent. | ES | AEPD | ePrivacy | €30,000 | ↗ |
| 23 Sept 2019 | VODAFONE ESPAÑA, S.A.U.The AEPD fined VODAFONE ESPAÑA, S.A.U. 60,000 EUR for processing personal data without consent. The breach led to an unauthorized service change and debt collection attempts. | ES | AEPD | GDPR | €60,000 | ↗ |
| 20 Sept 2019 | IBERDROLA CLIENTES, SAUIBERDROLA CLIENTES, SAU was fined by the AEPD 10,000 EUR for including personal data in the SOLCENT file without the required authorization. The authority found this to be a breach of data protection rules. | ES | AEPD | GDPR | €10,000 | ↗ |
| 17 Sept 2019 | vzw YThe Litigation Chamber fined vzw Y for failing to respond properly to a data subject’s requests for access to and erasure of personal data. The authority found breaches of GDPR Articles 12, 15, and 17. | BE | APD | GDPR | €2,000 | ↗ |
| 17 Sept 2019 | Geanonimiseerd (APD 06/2019)The case concerned a complaint about the use of electronic identity cards to create customer cards. The Litigation Chamber found breaches of data minimization, lawful basis for processing, and information duties under the GDPR, and imposed a fine of EUR 10,000. | BE | APD | GDPR | €10,000 | ↗ |
| 12 Sept 2019 | Anonymised (CyDPC ΑΝΩΝΥΜΟΠΟΙΗΜΕΝΗ ΑΠΟΦΑΣΗ ΔΗΜΟΠΡ)A complaint was filed against an individual for using personal data without consent to contact the complainant about a property sale. The Commissioner found a breach of Article 6 GDPR and imposed a fine of EUR 2,000. | CY | CyDPC | GDPR | €2,000 | ↗ |
| 12 Sept 2019 | MALONEY'S SPORT BAR S.L.MALONEY'S SPORT BAR S.L. was fined by the AEPD in the amount of 6,000 EUR for operating a video surveillance system that monitored public spaces without proper justification. The authority found this practice to be in breach of data protection rules. | ES | AEPD | GDPR | €6,000 | ↗ |
| 12 Sept 2019 | VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD EUR 2,500 for sending unsolicited commercial SMS messages without prior consent. The authority found this breached Article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €2,500 | ↗ |
| 10 Sept 2019 | Dane anonimowe (V. Sp. z o.o. z siedzibą w S. przy ul.)UODO found that V. Sp. z o.o. breached rules on the security and confidentiality of processed personal data. A fine of PLN 2,830,410 was imposed. | PL | UODO | GDPR | €653,000 | ↗ |
| 06 Sept 2019 | Anonymised (CyDPC ΑΝΟΝΥΜΟΠΟΙΗΜΕΝΗ ΑΠΟΦΑΣΗ δημοσί)A medical practice was fined EUR 14,000 for posting a patient's pre- and post-surgery images on Instagram without consent. The authority found a breach of GDPR rules on personal data processing and the protection of special-category data. | CY | CyDPC | GDPR | €14,000 | ↗ |
| 03 Sept 2019 | Национална агенция за приходитеThe National Revenue Agency was fined 55,000 BGN for processing personal data without a lawful basis. The authority found that data were collected and used in enforcement proceedings in breach of Article 6 GDPR. | BG | CPDP | GDPR | €28,122 | ↗ |
| 03 Sept 2019 | ЧСИThe CPDP fined a private bailiff (ЧСИ) for failing to provide a data subject with access to personal data collected through video surveillance. The authority found a breach of Article 12 GDPR. | BG | CPDP | GDPR | €1,790 | ↗ |
| 03 Sept 2019 | А.Т.The CPDP imposed a fine of 23,000 BGN on A.T. for processing personal data without consent, in breach of Article 6 GDPR. The case concerned the creation of financial obligations for the complainant without a valid contract. | BG | CPDP | GDPR | €11,760 | ↗ |
| 02 Sept 2019 | LA SALA 2015 S.L.U.LA SALA 2015 S.L.U. was fined by the AEPD 1,500 EUR for improper processing of personal data through a video surveillance system. The cameras captured images disproportionately from public sidewalks without the required legal basis. | ES | AEPD | GDPR | €1,500 | ↗ |
| 20 Aug 2019 | Gymnasienämnden i Skellefteå kommunGymnasienämnden i Skellefteå kommun was fined by IMY for using facial recognition to record student attendance. The authority found that the processing was more intrusive than necessary and lacked a valid exception for biometric data. | SE | IMY | GDPR | €18,578 | ↗ |
| 08 Aug 2019 | Zala Megyei Kormányhivatal Keszthelyi Járási FöldhivatalThe Zala Megyei Kormányhivatal Keszthelyi Járási Földhivatal was fined 600,000 HUF by NAIH for breaching the principles of data minimization and transparency. The authority found that personal data was made accessible to third parties without clear information about the processing. | HU | NAIH | GDPR | €1,848 | ↗ |
| 25 Jul 2019 | CONTAPUBLI RIOJA, S.L. (GESTIRIOJA)CONTAPUBLI RIOJA, S.L. was fined by the AEPD 2,500 EUR for sending unsolicited commercial emails. The conduct continued despite the recipient's objection and request for data deletion. | ES | AEPD | ePrivacy | €2,500 | ↗ |
| 25 Jul 2019 | VODAFONE ESPAÑA SAUVODAFONE ESPAÑA SAU was fined by the AEPD 60,000 EUR for failing to ensure adequate security of personal data. The breach resulted in unauthorized or unlawful processing, indicating deficiencies in security controls. | ES | AEPD | GDPR | €60,000 | ↗ |
| 25 Jul 2019 | SOCIEDAD ESTATAL CORREOS Y TELEGRAFOS. S.A.The entity delivered correspondence to the wrong recipient, which constitutes a breach of the data protection principles in Article 5 of the GDPR. AEPD imposed a fine of EUR 40,000. | ES | AEPD | GDPR | €40,000 | ↗ |
| 25 Jul 2019 | VODAFONE ONO, S.A.U.VODAFONE ONO, S.A.U. was fined EUR 60,000 by the AEPD for a security breach in its customer portal. The incident allowed unauthorized access to a third party's personal data, indicating insufficient access controls. | ES | AEPD | GDPR | €60,000 | ↗ |