BULLETIN №082Last updated · 30 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.2%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 11 Aug 2022 | Lolland KommuneLolland Kommune was fined 50,000 DKK for failing to implement basic security measures. Employees were able to disable passwords on mobile devices, exposing sensitive citizen data to unauthorized access. | DK | Datatilsynet | GDPR | €6,721 | ↗ |
| 23 May 2022 | EL DIARIO DE PRENSA DIGITAL, S.L.EL DIARIO DE PRENSA DIGITAL, S.L. was fined by the AEPD 50,000 EUR for publishing audio of a victim's testimony in a high-profile court case. The authority found a breach of the GDPR data minimization principle. | ES | AEPD | GDPR | €50,000 | ↗ |
| 15 Jun 2021 | VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined 50,000 EUR by the AEPD for continuing to pursue a debt that had already been settled. The authority treated this as a breach of data protection rules. | ES | AEPD | GDPR | €50,000 | ↗ |
| 25 May 2022 | Roularta Media GroupRoularta Media Group was fined EUR 50,000 by the APD for using cookies on its media websites without obtaining valid user consent. The authority found this practice breached GDPR and ePrivacy Directive requirements. | BE | APD | ePrivacy | €50,000 | ↗ |
| 28 Sept 2023 | Azienda Usl Toscana centroThe Garante imposed a fine of EUR 50,000 on Azienda Usl Toscana centro for data protection violations related to the former Sanatorio Guido Banti premises. The case concerned irregularities in the processing of personal data in that context. | IT | Garante | GDPR | €50,000 | ↗ |
| 01 Jan 2024 | FLEXICAR IBÉRICA, S.L.FLEXICAR IBÉRICA, S.L. was fined €50,000 by the AEPD for a personal data breach. The incident occurred when information belonging to other clients was mistakenly shared via WhatsApp. | ES | AEPD | GDPR | €50,000 | ↗ |
| 20 Dec 2023 | Dane anonimowe (Wójta Gminy P.)UODO imposed a PLN 50,000 administrative fine on the controller for failing to implement appropriate technical and organizational measures proportionate to the risk of processing. The authority found insufficient safeguards for confidentiality, integrity, availability, and resilience of systems, as well as inadequate recovery capability after an incident. | PL | UODO | GDPR | €11,518 | ↗ |
| 10 Jul 2025 | Magna PT S.p.A.Magna PT S.p.A. was fined EUR 50,000 by the Garante for requiring employees to complete a questionnaire after absences due to illness. The authority found that this practice breached GDPR rules on the processing of personal data. | IT | Garante | GDPR | €50,000 | ↗ |
| 01 Jan 2019 | TELEFONICA MOVILES ESPAÑA, S.A.U.TELEFONICA MOVILES ESPAÑA, S.A.U. was fined 50,000 EUR by the AEPD. The authority found that the company used personal data to fraudulently contract phone lines without the data subjects’ consent. | ES | AEPD | GDPR | €50,000 | ↗ |
| 18 Apr 2018 | Marigliano GianpaoloMarigliano Gianpaolo was fined by the Garante 50,000 EUR for unlawfully using personal data to activate 15 phone cards without the consent of the individuals concerned. The case indicates a breach of lawful processing requirements and consent rules. | IT | Garante | GDPR | €50,000 | ↗ |
| 21 Sept 2020 | CONSEGURIDAD S.L.CONSEGURIDAD S.L. was fined 50,000 EUR by the AEPD for failing to appoint a Data Protection Officer. The authority found a breach of Article 37(1)(b) of the GDPR. | ES | AEPD | GDPR | €50,000 | ↗ |
| 10 Jun 2022 | ORANGE ESPAGNE, S.A.U.ORANGE ESPAGNE, S.A.U. was fined 50,000 EUR by the AEPD for processing personal data without consent. The breach resulted in identity theft in a phone contract. | ES | AEPD | GDPR | €50,000 | ↗ |
| 03 Oct 2023 | Digivo Media LimitedBetween 24 March 2021 and 7 September 2021, 415,041 text messages were sent without valid consent, breaching Regulation 22 of PECR. The ICO identified the matter after reviewing debt management complaints submitted via the SPAM reporting tool. | GB | ICO | ePrivacy | €57,620 | ↗ |
| 13 Jul 2022 | GRUPO TRANSAHER, S.L.GRUPO TRANSAHER, S.L. was fined by the AEPD 50,000 EUR for installing surveillance cameras in employee rest areas. The authority found that the company did not properly inform employees and may have infringed their privacy under the GDPR. | ES | AEPD | GDPR | €50,000 | ↗ |
| 23 Apr 2018 | Anonymizováno (ÚOOÚ UOOU-06702/17-47)The entity was fined CZK 50,000 by the UOOU for failing to cooperate during an inspection. The authority found a breach of the duty to create conditions for the inspection and provide necessary assistance. | CZ | UOOU | GDPR | €1,968 | ↗ |
| 02 Feb 2018 | Anonymizováno (ÚOOÚ UOOU-06702/17-37)The entity was fined CZK 50,000 by the Czech data protection authority for failing to provide the required cooperation during an ongoing inspection. This breached the duty to create conditions for the inspection and to allow the inspector to exercise their powers. | CZ | UOOU | GDPR | €1,985 | ↗ |
| 07 Sept 2023 | IBERIA LÍNEAS AÉREAS DE ESPAÑA, S.A. OPERADORAIberia was fined by the AEPD EUR 50,000 for a breach related to personal data handling during a flight from Quito to Dublin. Passengers were asked to provide identity documents and marriage certificates to justify travel during COVID-19 restrictions. | ES | AEPD | GDPR | €50,000 | ↗ |
| 14 Mar 2013 | PONTE EN FORMA ONLINE, S.L.PONTE EN FORMA ONLINE, S.L. was fined by the AEPD EUR 50,000 for sending unsolicited commercial email communications. The conduct breached Article 21 of the LSSI, which restricts marketing emails sent without prior consent. | ES | AEPD | ePrivacy | €50,000 | ↗ |
| 01 Jan 2025 | PROYECTOS VISUALES ZARAGOZA SLPROYECTOS VISUALES ZARAGOZA SL was fined by the AEPD 50,000 EUR for a personal data breach. The authority found that the company failed to ensure data integrity and confidentiality under Article 5(1)(f) GDPR. | ES | AEPD | GDPR | €50,000 | ↗ |
| 24 Mar 2021 | Ålesund kommuneÅlesund kommune was fined by Datatilsynet for using the Strava app in schools without conducting a risk assessment. As a result, students’ personal data was processed without adequate controls and safeguards. | NO | Datatilsynet | GDPR | €4,923 | ↗ |