BULLETIN №082Last updated · 30 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.2%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 05 Feb 2025 | RESIDENTIAL QUALITY ENJOY, S.L.The company was fined EUR 2,000 by the AEPD for requesting and processing personal data, including minors' IDs, without proper consent or information. The authority found this to be a breach of data protection principles and transparency obligations. | ES | AEPD | GDPR | €2,000 | ↗ |
| 28 Apr 2026 | RESIDENCIAL ETXE-LAN, S.L.RESIDENCIAL ETXE-LAN, S.L. was fined by the AEPD for failing to provide the required information to the supervisory authority. The breach concerned Article 58(1) GDPR and hindered the authority’s supervisory powers. | ES | AEPD | GDPR | €3,000 | ↗ |
| 01 Jan 2024 | REPSOL COMERCIALIZADORA DE ELECTRICIDAD Y GAS S.L.U.REPSOL COMERCIALIZADORA DE ELECTRICIDAD Y GAS S.L.U. was fined by the AEPD for processing personal data without consent, which led to unauthorized access to a customer's data. The authority also found inadequate security measures. | ES | AEPD | GDPR | €1,380,000 | ↗ |
| 04 May 2023 | RENEDO JOHNSEY, S.L.RENEDO JOHNSEY, S.L. was fined by the AEPD €2,000 for not having a privacy policy on its website. The authority treated this as a breach of Article 13 of the GDPR. | ES | AEPD | GDPR | €2,000 | ↗ |
| 26 Oct 2011 | Remida srlRemida srl was fined EUR 22,400 by the Garante for installing a surveillance camera in a condominium without providing adequate information. The authority found this to be a breach of data protection rules. | IT | Garante | GDPR | €22,400 | ↗ |
| 02 Dec 2020 | Region VästerbottenThe Health and Medical Services Board of Region Västerbotten was fined for failing to conduct a needs and risk analysis before granting access rights in the NCS Cross journal system. The authority found this breached GDPR requirements on data security and accountability. | SE | IMY | GDPR | €243,000 | ↗ |
| 26 Jan 2022 | Region Uppsala, personuppgiftsincidenterRegionstyrelsen i Region Uppsala was fined for sending sensitive personal data and personal identification numbers by email without encrypting the content. The authority found a breach of Article 32 GDPR because appropriate security measures were not in place. | SE | IMY | GDPR | €28,710 | ↗ |
| 16 Jul 2021 | Region SyddanmarkRegion Syddanmark was fined 500,000 DKK by Datatilsynet for failing to implement appropriate security measures. The vulnerability allowed unauthorized access to sensitive health data of children and was identified and reported by a citizen. | DK | Datatilsynet | GDPR | €67,220 | ↗ |
| 07 Jun 2021 | Regionstyrelsen Region VärmlandRegionstyrelsen Region Värmland was fined by IMY 250,000 SEK for failing to inform patients calling the 1177 healthcare line that their phone numbers and community IDs were being collected. The authority found this to be a breach of GDPR transparency requirements. | SE | IMY | GDPR | €24,863 | ↗ |
| 07 Jun 2021 | Regionstyrelsen Region SörmlandRegionstyrelsen Region Sörmland was fined by IMY 250,000 SEK for failing to inform callers to the 1177 healthcare line that their phone numbers and community IDs were being collected. The authority found a breach of GDPR transparency requirements. | SE | IMY | GDPR | €24,863 | ↗ |
| 26 Apr 2023 | Regionstyrelsen i Region SkåneRegionstyrelsen i Region Skåne was fined by IMY for storing unencrypted sensitive patient data on a USB drive that was lost. The authority found this to be a breach of Article 32 GDPR, which requires appropriate technical and organisational security measures. | SE | IMY | GDPR | €17,566 | ↗ |
| 02 Dec 2020 | Region ÖstergötlandRegion Östergötland was fined by IMY for failing to perform a needs and risk analysis before granting access rights in its journal system. The authority found that this breached several GDPR provisions. | SE | IMY | GDPR | €243,000 | ↗ |
| 08 Sept 2021 | Region MidtjyllandRegion Midtjylland was fined for failing to implement adequate access restrictions to an archive containing sensitive patient records. This allowed unauthorized access by patients and staff at a lifestyle center. | DK | Datatilsynet | GDPR | €40,344 | ↗ |
| 26 May 2022 | Regione ToscanaThe Garante fined Regione Toscana EUR 16,000 for publishing unnecessary personal data on the web. The data were later removed, but the authority still found a sanctionable breach. | IT | Garante | GDPR | €16,000 | ↗ |
| 10 Feb 2022 | Regione ToscanaRegione Toscana was fined by the Garante EUR 10,000 for failing to implement adequate security measures, which resulted in a data breach. The breach was mitigated by the region’s prompt response to reduce the negative effects on affected individuals. | IT | Garante | GDPR | €10,000 | ↗ |
| 06 Jul 2023 | Regione SicilianaThe Garante fined Regione Siciliana EUR 7,000 for publishing personal data of numerous individuals, including sensitive employment-related information. The authority found breaches of lawfulness, fairness, transparency, and data minimization principles. | IT | Garante | GDPR | €7,000 | ↗ |
| 08 Jul 2021 | Regione PugliaThe Garante fined Regione Puglia EUR 30,000 for the unlawful dissemination of personal health data on the web. The authority found breaches of lawfulness, fairness, transparency, and data minimization principles. | IT | Garante | GDPR | €30,000 | ↗ |
| 06 Feb 2014 | Regione PugliaRegione Puglia was fined EUR 20,000 by the Italian data protection authority, Garante. The breach involved unlawfully publishing health data of individuals with disabilities on its institutional website. | IT | Garante | GDPR | €20,000 | ↗ |
| 23 Sept 2010 | Regione PugliaRegione Puglia was fined EUR 40,000 by the Italian data protection authority, Garante. The case concerned the online publication of sensitive health data relating to disabled individuals, in breach of data protection rules. | IT | Garante | GDPR | €40,000 | ↗ |
| 29 May 2019 | Regione PugliaRegione Puglia was fined by the Garante 10,000 EUR for unlawfully publishing personal data of participants in a selection process on its official website. The disclosure included tax codes and income data, breaching privacy rights. | IT | Garante | GDPR | €10,000 | ↗ |