BULLETIN №082Last updated · 29 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 17 Jan 2023 | Fusiona Soluciones Energéticas, S.A.Fusiona Soluciones Energéticas, S.A. was fined by the AEPD for unlawfully processing personal data. The company included an individual's data in a credit information system without a lawful basis. | ES | AEPD | GDPR | €50,000 | ↗ |
| 27 Apr 2022 | DIARIO ABC, S.L.DIARIO ABC, S.L. was fined 50,000 EUR by the AEPD for publishing audio of a victim's testimony in a high-profile court case. The authority found that the publication could identify the victim and therefore breached data protection rules. | ES | AEPD | GDPR | €50,000 | ↗ |
| 12 Mar 2026 | ITAS MutuaITAS Mutua was fined EUR 50,000 by the Garante for failing to adequately respond to a former employee’s request for access to personal data. The authority found a breach of GDPR Article 15. | IT | Garante | GDPR | €50,000 | ↗ |
| 27 Apr 2022 | 20 MINUTOS EDITORA, S.L.20 MINUTOS EDITORA, S.L. was fined by the AEPD 50,000 EUR for publishing audio of a victim’s court statement in a high-profile case. The authority found a breach of data protection rules. | ES | AEPD | GDPR | €50,000 | ↗ |
| 02 Nov 2021 | Közterület megfigyelése magánszemély általThe case concerned unlawful processing of personal data through surveillance cameras installed on a property. The authority found breaches of GDPR Articles 5, 6, and 13 and imposed a fine of HUF 50,000 on the controller. | HU | NAIH | GDPR | €139 | ↗ |
| 29 Jan 2026 | Università Telematica e-CampusThe Garante fined Università Telematica e-Campus EUR 50,000 for violations related to biometric data processing. The authority also found that the university failed to carry out a proper Data Protection Impact Assessment (DPIA). | IT | Garante | GDPR | €50,000 | ↗ |
| 17 Jul 2024 | Iliad Italia S.p.A.Iliad Italia S.p.A. was fined EUR 50,000 by the Garante for sending promotional emails without obtaining proper customer consent. The authority found this conduct to be a breach of GDPR rules on electronic marketing. | IT | Garante | GDPR | €50,000 | ↗ |
| 01 Jan 2021 | VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD 50,000 EUR for breaching data protection rules. The case concerned deficiencies in the security and integrity of data processing. | ES | AEPD | GDPR | €50,000 | ↗ |
| 23 Apr 2021 | VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD 50,000 EUR for changing a customer's mobile line ownership without consent. The company also charged the customer's account amounts related to a third party's phone line. | ES | AEPD | GDPR | €50,000 | ↗ |
| 02 Mar 2023 | H&M Hennes & Mauritz s.r.l.H&M Hennes & Mauritz s.r.l. was fined EUR 50,000 by the Garante for violations related to installing surveillance systems without the required authorization. Employees were informed about the systems, but this did not cure the underlying compliance breach. | IT | Garante | GDPR | €50,000 | ↗ |
| 14 May 2020 | Geanonimiseerd (APD 25/2020)The APD Litigation Chamber imposed a EUR 50,000 fine on an anonymized social media platform for processing personal data without a valid legal basis. The case involved several GDPR breaches, including data processing principles and consent requirements. | BE | APD | GDPR | €50,000 | ↗ |
| 16 Jan 2023 | Kildare County CouncilThe Irish DPC imposed a fine of EUR 50,000 on Kildare County Council in inquiry 05/SIU/2018. The fine has been collected. | IE | DPC | GDPR | €50,000 | ↗ |
| 10 Jan 2025 | CRUZ ROJA ESPAÑOLACRUZ ROJA ESPAÑOLA was fined EUR 50,000 by the AEPD for a personal data protection breach. The case involved the unauthorized disclosure of patient data in a communication about a change in embryo bank management. | ES | AEPD | GDPR | €50,000 | ↗ |
| 26 Sept 2024 | Città metropolitana di TorinoCittà metropolitana di Torino was fined by the Garante 50,000 EUR for publishing personal data on its institutional website about individuals fined by voluntary ecological guards. The disclosure included names and contact details, breaching data protection rules. | IT | Garante | GDPR | €50,000 | ↗ |
| 19 Nov 2020 | ALTERNA OPERADOR INTEGRAL, S.L.ALTERNA OPERADOR INTEGRAL, S.L. was fined by the AEPD EUR 50,000 for changing an electricity provider without the customer's consent. The authority found that the processing lacked a valid legal basis under Article 6(1)(b) GDPR. | ES | AEPD | GDPR | €50,000 | ↗ |
| 25 May 2018 | Anonymizováno (ÚOOÚ UOOU-07350/18-21)The entity was fined 50,000 CZK by UOOU for failing to provide the necessary cooperation during an inspection. The breach concerned the legal duty to assist the supervisory authority. | CZ | UOOU | GDPR | €1,941 | ↗ |
| 12 May 2026 | SWDESWDE was fined by the APD 50,000 EUR for unlawful call recordings and monitoring used for quality evaluation and training purposes. The authority found breaches of transparency, data minimization, and other GDPR principles. | BE | APD | GDPR | €50,000 | ↗ |
| 18 Apr 2018 | Futur3 s.r.l.Futur3 s.r.l. was fined EUR 50,000 by the Garante for requiring users to give mandatory consents for marketing and profiling purposes that were not directly related to the requested Wi‑Fi service. The authority found this to be a breach of data protection rules. | IT | Garante | GDPR | €50,000 | ↗ |
| 02 Mar 2023 | Azienda sanitaria locale di BariAzienda sanitaria locale di Bari was fined EUR 50,000 by the Garante for violations in the processing of personal data. The authority found non-compliance with the principles of data minimization and integrity and confidentiality. | IT | Garante | GDPR | €50,000 | ↗ |
| 27 Oct 2020 | VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined 50,000 EUR by the AEPD for requesting payment for services contracted without the complainant’s consent. The case concerns a data protection breach linked to processing and debt collection without a valid legal basis. | ES | AEPD | GDPR | €50,000 | ↗ |