BULLETIN №082Last updated · 30 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 05 May 2022 | SOCIEDAD ESPAÑOLA DE RADIODIFUSIÓN, S.L.The Spanish Data Protection Agency (AEPD) fined SOCIEDAD ESPAÑOLA DE RADIODIFUSIÓN, S.L. EUR 50,000 for publishing audio of a victim’s court testimony without adequate data protection safeguards. The authority found a breach of GDPR Article 5(1)(c) on data minimization. | ES | AEPD | GDPR | €50,000 | ↗ |
| 26 Apr 2024 | Nationalt Genom CenterThe Danish DPA fined Nationalt Genom Center 50,000 DKK for processing personal data without consulting the supervisory authority. Its own DPIA identified a high risk, which should have triggered prior consultation before processing began. | DK | Datatilsynet | GDPR | €6,705 | ↗ |
| 19 Jan 2024 | L.A.D.H LimitedL.A.D.H Limited sent 31,329 direct marketing text messages to individuals in breach of regulations 22 and 23 of PECR. The ICO imposed a fine of GBP 50,000 and issued an enforcement notice. | GB | ICO | ePrivacy | €58,260 | ↗ |
| 03 May 2022 | TITANIA COMPAÑÍA EDITORIAL, S.L.TITANIA COMPAÑÍA EDITORIAL, S.L. was fined by the AEPD 50,000 EUR for publishing an audio recording of a victim’s testimony in a high-profile court case. The authority found that the company processed personal data excessively and breached data protection principles. | ES | AEPD | GDPR | €50,000 | ↗ |
| 11 Jan 2024 | Comune di TrentoThe Garante fined Comune di Trento EUR 50,000 for conducting two research projects using cameras, microphones, and social networks in breach of data protection rules. The case concerns improper processing of personal data in the context of research activities. | IT | Garante | GDPR | €50,000 | ↗ |
| 01 Jan 2023 | SUMINISTRADOR IBÉRICO DE ENERGÍA, S.L.SUMINISTRADOR IBÉRICO DE ENERGÍA, S.L. was fined by the AEPD 50,000 EUR for processing personal data without consent. The case involved formalizing an electricity supply contract and charging the complainant's bank account without authorization. | ES | AEPD | GDPR | €50,000 | ↗ |
| 30 Dec 2022 | SECURITAS DIREC ESPAÑA, S.A.SECURITAS DIREC ESPAÑA, S.A. was fined by the AEPD 50,000 EUR for failing to provide complete access to personal data logs linked to an alarm system. The case concerned an inadequate response to a data subject access request. | ES | AEPD | GDPR | €50,000 | ↗ |
| 23 Apr 2021 | VODAFONE SERVICIOS, S.L.U.Vodafone Servicios, S.L.U. was fined by the AEPD 50,000 EUR for failing to verify a customer's identity. The lapse enabled identity fraud and the unauthorized creation of an account. | ES | AEPD | GDPR | €50,000 | ↗ |
| 09 May 2018 | Sioufas and Partners Law FirmThe law firm was fined for operating a video surveillance system that covered workspaces without proper justification. It also failed to notify the authority in a timely manner and did not inform individuals about the surveillance, breaching several provisions of Greek data protection law. | GR | HDPA | GDPR | €50,000 | ↗ |
| 29 Jul 2011 | INFORMA D&B, SAINFORMA D&B, SA was fined by the AEPD 50,000 EUR for continuing to send commercial emails after the recipient requested unsubscribing and objected to data processing. The authority found a breach of Article 21 of the LSSI. | ES | AEPD | ePrivacy | €50,000 | ↗ |
| 14 Oct 2024 | ATRESMEDIA CORPORACIÓN DE MEDIOS DE COMUNICACIÓN, S.A.ATRESMEDIA was fined by the AEPD EUR 50,000 for publishing a video containing violent content and the voices of the aggressors and the victim. The authority found a breach of data protection rules. | ES | AEPD | GDPR | €50,000 | ↗ |
| 28 Jul 2020 | Anonymizováno (ÚOOÚ UOOU-05226/19-22)The entity was fined for publishing personal data of court proceeding participants on a website. The authority found this to be a breach of data protection law. | CZ | UOOU | GDPR | €1,905 | ↗ |
| 22 Jul 2019 | VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD 50,000 EUR for sending an SMS to a third party with a link to a customer's purchase summary. This disclosed personal data without proper authorization. | ES | AEPD | GDPR | €50,000 | ↗ |
| 01 Jan 2023 | ATRESMEDIA CORPORACIÓN DE MEDIOS DE COMUNICACIÓN, S.A.ATRESMEDIA was fined by the AEPD in the amount of 50,000 EUR for publishing excessive personal data. The case concerned an audio recording of a victim's court statement, which was not necessary for the journalistic purpose. | ES | AEPD | GDPR | €50,000 | ↗ |
| 08 Apr 2022 | SECURITAS DIRECT ESPAÑA, S.A.SECURITAS DIRECT ESPAÑA, S.A. was fined by the AEPD 50,000 EUR for disclosing a customer's personal information to another client via email. The authority found a breach of confidentiality and insufficient security measures under the GDPR. | ES | AEPD | GDPR | €50,000 | ↗ |
| 28 Apr 2022 | DISPLAY CONNECTORS, S.L.DISPLAY CONNECTORS, S.L. was fined by the AEPD EUR 50,000 for processing excessive personal data. The company published audio of a victim’s testimony without necessity, breaching the data minimisation principle under Article 5(1)(c) GDPR. | ES | AEPD | GDPR | €50,000 | ↗ |
| 04 Oct 2011 | NGI s.p.a.NGI s.p.a. was fined by the Garante 50,000 EUR for breaches of data protection rules. The authority found that the company failed to designate data processing officers, did not prepare the required security program document, and improperly retained traffic data. | IT | Garante | GDPR | €50,000 | ↗ |
| 10 May 2022 | CONECTA5 TELECINCO, S.A.U.CONECTA5 TELECINCO, S.A.U. was fined by the AEPD 50,000 EUR for publishing audio of a victim’s court testimony without voice distortion. The authority found a breach of data protection principles. | ES | AEPD | GDPR | €50,000 | ↗ |
| 26 Apr 2022 | CORPORACIÓN DE RADIO Y TELEVISIÓN ESPAÑOLA S.A.The company published audio of a victim's court statement in a high-profile case. The authority found a breach of the data minimization principle because excessive personal data was processed. | ES | AEPD | GDPR | €50,000 | ↗ |
| 20 Sept 2012 | Casa di cura privata Montevergine s.p.a.The private clinic Montevergine was fined 50,000 EUR by the Garante. The authority found that it processed employees' biometric data for attendance tracking without first notifying the supervisory authority. | IT | Garante | GDPR | €50,000 | ↗ |