BULLETIN №082Last updated · 30 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.2%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 20 Jul 2020 | CENTRO DE INVESTIGACIÓN Y ESTUDIO PARA LA OBESIDAD, S.L.The entity unlawfully transferred personal data without consent, in breach of Article 6 of the GDPR. The case resulted in an administrative fine of 50,000 EUR. | ES | AEPD | GDPR | €50,000 | ↗ |
| 15 May 2020 | JobTeam A/SJobTeam A/S was reported to the police, and Datatilsynet recommended a fine of 50,000 DKK for breaching GDPR principles. The company deleted personal data after a data subject access request, which hindered the exercise of the individual's rights. | DK | Datatilsynet | GDPR | €6,705 | ↗ |
| 04 Oct 2021 | ENDESA ENERGÍA, S.A.U.ENDESA ENERGÍA, S.A.U. was fined by the AEPD 50,000 EUR for breaching GDPR data accuracy principles. The case involved identity theft and false documentation in a request to transfer an electricity contract. | ES | AEPD | GDPR | €50,000 | ↗ |
| 05 May 2022 | THOMAS INTERNATIONAL SYSTEMS, S.A.THOMAS INTERNATIONAL SYSTEMS, S.A. was fined by the AEPD 50,000 EUR for processing special categories of personal data without proper legal justification. The company requested sensitive information, including disability and ethnicity, in psychometric questionnaires. | ES | AEPD | GDPR | €50,000 | ↗ |
| 01 Sept 2021 | ORANGE ESPAGNE, S.A.U.ORANGE ESPAGNE, S.A.U. was fined by the AEPD 50,000 EUR for making unsolicited marketing calls and sending messages without consent. The conduct breached data protection principles. | ES | AEPD | GDPR | €50,000 | ↗ |
| 19 Jan 2022 | DISPLAY CONNECTORS, S.L.DISPLAY CONNECTORS, S.L. was fined by the AEPD EUR 50,000 for processing excessive personal data, including the name of a minor, that was not necessary for the intended purpose. The authority found this to be a breach of data protection principles. | ES | AEPD | GDPR | €50,000 | ↗ |
| 21 Dec 2022 | Politie NederlandThe Dutch Data Protection Authority fined the police chief for failing to carry out a data protection impact assessment before using mobile camera cars in Rotterdam. The measure created a high risk to individuals' rights and freedoms. | NL | AP | GDPR | €50,000 | ↗ |
| 25 Nov 2021 | Azienda Ospedaliera di Rilievo Nazionale “Antonio Cardarelli"The hospital was fined by the Garante 50,000 EUR for unlawfully publishing on its website the personal data of participants in a competitive procedure, including health data. The authority found a breach of data protection principles. | IT | Garante | GDPR | €50,000 | ↗ |
| 17 May 2021 | Vodafone Servicios, S.L.U.The AEPD fined Vodafone Servicios, S.L.U. 50,000 EUR for processing personal data without proper consent. The breach led to unauthorized charges on a customer's bank account. | ES | AEPD | GDPR | €50,000 | ↗ |
| 26 May 2021 | VODAFONE ESPAÑA, S.A.U.The AEPD fined VODAFONE ESPAÑA, S.A.U. 50,000 EUR for sending SMS messages about an alleged debt for services not contracted by the complainant. The case involved incorrect processing of personal data and the use of inaccurate contact details. | ES | AEPD | GDPR | €50,000 | ↗ |
| 14 May 2020 | Geanonimiseerd (APD 24/2020)The decision concerns an insurance company that failed to provide sufficient transparency in its privacy policy. It involved the use of health data without explicit consent for purposes beyond hospitalization insurance. | BE | APD | GDPR | €50,000 | ↗ |
| 03 Jun 2025 | Regione LombardiaThe Italian Data Protection Authority, Garante per la protezione dei dati personali, imposed a EUR 50,000 fine on Regione Lombardia. The case concerned unlawful retention of employees' email metadata, excessive retention of web browsing logs, and prolonged storage of helpdesk ticket data. | IT | Garante per la protezione dei dati personali | GDPR | €50,000 | ↗ |
| 16 Dec 2021 | Frederiksberg KommuneFrederiksberg Kommune was fined by Datatilsynet for failing to implement adequate security measures in a self-service solution. This led to unauthorized access to protected personal data. | DK | Datatilsynet | GDPR | €6,724 | ↗ |
| 11 May 2022 | LA VANGUARDIA EDICIONES, S.L.LA VANGUARDIA EDICIONES, S.L. was fined by the AEPD 50,000 EUR for publishing audio of a victim's court statement in a high-profile case. The authority found excessive processing of personal data and a breach of data protection rules. | ES | AEPD | GDPR | €50,000 | ↗ |
| 17 Dec 2024 | Geanonimiseerd (APD 166/2024)The hospital was fined by the APD for failing to carry out a data protection impact assessment and for lacking effective information security policies. These deficiencies contributed to a ransomware incident affecting up to 300,000 individuals. | BE | APD | GDPR | €50,000 | ↗ |
| 11 Feb 2022 | Etterforsker1 Gruppen ASEtterforsker1 Gruppen AS was fined NOK 50,000 by Datatilsynet for conducting a credit assessment of an individual without a legal basis. The assessment was carried out on behalf of a client who claimed to have a compensation claim against the complainant. | NO | Datatilsynet | GDPR | €4,964 | ↗ |
| 09 Dec 2020 | Guldborgsund KommuneGuldborgsund Kommune was fined 50,000 DKK by Datatilsynet for a data breach. Sensitive information was mistakenly sent to an unauthorized recipient, causing significant consequences for the affected individuals. | DK | Datatilsynet | GDPR | €6,718 | ↗ |
| 01 Jan 2024 | UNIVERSITAS NEBRISSENSIS, S.A.UNIVERSITAS NEBRISSENSIS, S.A. was fined by the AEPD EUR 50,000 for requesting a full copy of a student's ID. The authority found that this breached GDPR data minimization principles and security requirements. | ES | AEPD | GDPR | €50,000 | ↗ |
| 01 Jan 2020 | VODAFONE ESPAÑA, S.A.U.The AEPD fined VODAFONE ESPAÑA, S.A.U. 50,000 EUR for sending unsolicited promotional SMS messages. The messages were sent despite the complainant having exercised the right to object and request deletion of their data, which breached Article 21 of the LSSI. | ES | AEPD | ePrivacy | €50,000 | ↗ |
| 13 Jan 2023 | Intellexa A.E.Intellexa A.E. was fined EUR 50,000 by the HDPA. The authority found that the company failed to cooperate with the supervisory authority as required under Article 31 of the GDPR. | GR | HDPA | GDPR | €50,000 | ↗ |