BULLETIN №083Last updated · 07 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.5m
- YoY volume
- -23.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 14 Mar 2013 | PONTE EN FORMA ONLINE, S.L.PONTE EN FORMA ONLINE, S.L. was fined by the AEPD EUR 50,000 for sending unsolicited commercial email communications. The conduct breached Article 21 of the LSSI, which restricts marketing emails sent without prior consent. | ES | AEPD | ePrivacy | €50,000 | ↗ |
| 01 Jan 2025 | PROYECTOS VISUALES ZARAGOZA SLPROYECTOS VISUALES ZARAGOZA SL was fined by the AEPD 50,000 EUR for a personal data breach. The authority found that the company failed to ensure data integrity and confidentiality under Article 5(1)(f) GDPR. | ES | AEPD | GDPR | €50,000 | ↗ |
| 24 Mar 2021 | Ålesund kommuneÅlesund kommune was fined by Datatilsynet for using the Strava app in schools without conducting a risk assessment. As a result, students’ personal data was processed without adequate controls and safeguards. | NO | Datatilsynet | GDPR | €4,923 | ↗ |
| 22 Feb 2024 | Trasporto Passeggeri Emilia-Romagna S.p.A.The Garante fined Trasporto Passeggeri Emilia-Romagna S.p.A. 50,000 EUR for improper data processing and a lack of transparency in collecting consent for marketing purposes. The case concerned failures to properly inform data subjects and to meet consent requirements. | IT | Garante | GDPR | €50,000 | ↗ |
| 06 May 2021 | YThe APD Litigation Chamber imposed a 50,000 EUR fine on Y. The authority found that the privacy policy lacked transparency and breached several GDPR provisions. | BE | APD | GDPR | €50,000 | ↗ |
| 13 Jul 2023 | EUROPA PRESS DE CATALUNYA, S.A.EUROPA PRESS DE CATALUNYA, S.A. was fined by the AEPD 50,000 EUR for publishing audio of a victim's court statement in a high-profile case. The authority found that the company processed excessive personal data in breach of GDPR Article 5(1)(c). | ES | AEPD | GDPR | €50,000 | ↗ |
| 01 Jul 2010 | TELEFONICA MOVILES ESPAÑA S.A.U.TELEFONICA MOVILES ESPAÑA S.A.U. was fined by the AEPD EUR 50,000 for sending unsolicited SMS advertisements without proper consent. The conduct breached Article 21.2 of the LSSI on electronic marketing communications. | ES | AEPD | ePrivacy | €50,000 | ↗ |
| 29 Apr 2022 | RADIO TELEVISION MADRID, S.A.RADIO TELEVISION MADRID, S.A. was fined by the AEPD 50,000 EUR for processing excessive personal data. The case concerned the publication of audio of a victim's court statement in a high-profile case, which breached the data minimization principle. | ES | AEPD | GDPR | €50,000 | ↗ |
| 29 Apr 2025 | Regione LombardiaThe Garante fined Regione Lombardia 50,000 EUR for violations related to the processing of personal data. The authority cited inadequate technical and organizational measures to protect data, as well as improper handling of employee metadata and internet navigation logs. | IT | Garante | GDPR | €50,000 | ↗ |
| 21 Aug 2020 | ZSOUODO imposed a PLN 50,000 fine on ZSO for breaching personal data protection rules. The case concerned non-compliance with requirements under data protection regulations. | PL | UODO | GDPR | €11,369 | ↗ |
| 27 Jan 2021 | De Nationale Dienst voor Promotie van Kinderartikelen, NVThe company was fined for unlawfully sharing personal data of (expectant) mothers with third parties for direct marketing without valid consent. The authority found breaches of GDPR transparency and information obligations. | BE | APD | GDPR | €50,000 | ↗ |
| 23 Jun 2025 | Piraeus Bank S.A.Piraeus Bank S.A. was fined by the HDPA 50,000 EUR for unlawfully transferring personal data to third parties without the data subject's consent. The authority found breaches of GDPR principles of lawfulness and accuracy. | GR | HDPA | GDPR | €50,000 | ↗ |
| 05 Aug 2020 | BANKIA, S.A.BANKIA, S.A. was fined by the AEPD 50,000 EUR for retaining a former client’s personal data for more than 16 years without a valid basis. The authority found this to be a breach of data protection principles, especially storage limitation. | ES | AEPD | GDPR | €50,000 | ↗ |
| 14 Oct 2022 | VODAFONE ONO, S.A.U.The AEPD fined VODAFONE ONO, S.A.U. 50,000 EUR for consulting a credit information system without the individual's consent. The company had no contractual relationship with the person, so there was no valid basis for the inquiry. | ES | AEPD | GDPR | €50,000 | ↗ |
| 25 May 2022 | RoulartaThe Belgian data protection authority, APD, sanctioned Roularta in decision 85/2022 of 25 May 2022. The case concerned the placement of non-essential cookies on its press websites without prior user consent. The fine was EUR 50,000. | BE | Autorité de protection des données | GDPR | €50,000 | ↗ |
| 24 Oct 2023 | UNIPREX, S.A.UNIPREX, S.A. was fined 50,000 EUR by the AEPD for processing an excessive amount of personal data. The authority found that the data collected went beyond what was necessary for the intended purpose. | ES | AEPD | GDPR | €50,000 | ↗ |
| 29 Nov 2019 | VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD 50,000 EUR for sending a customer's personal data to the wrong address. The authority found this to be a breach of data security requirements under GDPR Article 5(1)(f). | ES | AEPD | GDPR | €50,000 | ↗ |
| 26 Apr 2024 | SANTANDER CONSUMER, S.A.SANTANDER CONSUMER, S.A. was fined by the AEPD in the amount of 50,000 EUR for sending postal advertising after the complainant had exercised the right to object to processing for marketing purposes. The case concerns failure to respect the data subject’s objection to commercial use of personal data. | ES | AEPD | GDPR | €50,000 | ↗ |
| 29 Apr 2022 | EDITORIAL PRENSA CANARIA, S.A.The company was fined by the AEPD 50,000 EUR for publishing audio of a victim's testimony in a high-profile court case. The authority found a breach of data protection principles. | ES | AEPD | GDPR | €50,000 | ↗ |
| 30 Jan 2026 | deținătorul site-ului evita-teparii.roANSPDCP imposed total fines of 51,000 lei, about 10,000 euro, on the operator, a natural person who runs the site evita-teparii.ro. The case involved multiple GDPR breaches, including the unlawful publication of identity, contact, sensitive, and alleged criminal data without a legal basis. | RO | ANSPDCP | GDPR | €10,007 | ↗ |