BULLETIN №082Last updated · 30 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.2%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 03 Dec 2019 | Nusvar ABNusvar AB was fined SEK 35,000 by IMY. The authority found unauthorized processing of personal data relating to criminal offenses and a failure to comply with data minimization principles in credit reporting activities. | SE | IMY | GDPR | €3,313 | ↗ |
| 23 Jan 2024 | CAIXA POPULAR - CAIXA RURAL SOC. COOP. DE CRÉDITO VCAIXA POPULAR was fined EUR 35,000 by the AEPD for a personal data breach. The incident allowed unauthorized third-party access and affected the confidentiality and integrity of the data. | ES | AEPD | GDPR | €35,000 | ↗ |
| 21 May 2015 | BONANZA DIGITAL SERVICES, S.L.BONANZA DIGITAL SERVICES, S.L. was fined EUR 35,000 by the AEPD for sending 20 unsolicited advertising SMS messages without prior consent. The company also failed to provide an opt-out mechanism, breaching the LSSI. | ES | AEPD | ePrivacy | €35,000 | ↗ |
| 12 Sept 2025 | A Düsseldorf-based personnel recruitment companyOn 2025-09-12, the LDI NRW announced a data protection fine of over 35,000 EUR against a Düsseldorf-based personnel recruitment company. The authority said the company repeatedly ignored job seekers’ requests for access and deletion and failed to respond to the supervisory authority’s inquiries. | DE | Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen | GDPR | €35,000 | ↗ |
| 18 Mar 2025 | ALVEA SOLUCIONES TECNOLÓGICAS, S.L.ALVEA Soluciones Tecnológicas, S.L. was fined 35,000 EUR by the AEPD for improper handling of personal data. The authority cited sharing data without consent and failing to comply with data retention policies. | ES | AEPD | GDPR | €35,000 | ↗ |
| 29 Oct 2013 | ESPASA CALPE, S.A.ESPASA CALPE, S.A. was fined EUR 35,000 by the AEPD for sending unsolicited commercial emails. The conduct breached Article 21 of the LSSI despite prior requests to be removed from the mailing list. | ES | AEPD | ePrivacy | €35,000 | ↗ |
| 25 Sept 2025 | E-Power S.r.l.E-Power S.r.l. was fined EUR 35,000 by the Garante for making promotional calls without a valid legal basis. The authority also found that the company failed to respond to data subject rights requests, which breaches GDPR requirements. | IT | Garante | GDPR | €35,000 | ↗ |
| 27 May 2019 | VODAFONE ESPAÑA, S.A.U.Vodafone España, S.A.U. was fined 35,000 EUR by the AEPD for processing personal data without consent. The case involved charging a former customer for services not contracted due to a technical error. | ES | AEPD | GDPR | €35,000 | ↗ |
| 01 Jan 2012 | LET’s BONUS, S.L.LET’s BONUS, S.L. was fined EUR 34,001 by the AEPD for sending unsolicited commercial emails to a user. The conduct continued despite multiple requests to stop, which breached Article 21 of the LSSI. | ES | AEPD | ePrivacy | €34,001 | ↗ |
| 10 Jun 2011 | Azienda mobilità trasporti di Bari s.p.a.Azienda mobilità trasporti di Bari s.p.a. was fined by the Garante for processing employees' biometric data without proper notice, consent, or adequate information. The authority found violations of several provisions of the Italian data protection code. | IT | Garante | GDPR | €34,000 | ↗ |
| 02 Dec 2015 | A.M.A.M. Azienda Meridionale Acque Messina s.p.a.A.M.A.M. Azienda Meridionale Acque Messina s.p.a. was fined by the Garante for processing employees' biometric data without notification and without requesting prior verification. The authority found that the company breached data protection rules. | IT | Garante | GDPR | €34,000 | ↗ |
| 06 Sept 2012 | Azienda sanitaria provinciale di EnnaAzienda sanitaria provinciale di Enna was fined 34,000 EUR by the Garante. The authority found a breach of notification obligations under data protection rules. | IT | Garante | GDPR | €34,000 | ↗ |
| 29 Apr 2026 | Pianeta s.r.l.Pianeta s.r.l. was fined by the Garante 34,000 EUR for unlawfully processing personal data linked to a loyalty card program. The data were used to initiate disciplinary action against an employee, which breached GDPR requirements. | IT | Garante | GDPR | €34,000 | ↗ |
| 08 Feb 2023 | DKN.5131.50.2021StatusprawomocnaTytuUODO imposed a PLN 33,012 fine on the controller and the processor for failing to implement appropriate technical and organizational measures to secure personal data. The authority also found that the controller did not verify whether the processor provided sufficient guarantees of GDPR compliance and protection of data subjects' rights. | PL | UODO | GDPR | €6,967 | ↗ |
| 21 Jun 2023 | Dane anonimowe (H. Sp. z o.o. z siedzibą w W. przy Al.)UODO imposed a PLN 33,012 fine on H. Sp. z o.o. The penalty was issued because the company failed to provide the President of the Personal Data Protection Office with access to information necessary to perform supervisory duties. | PL | UODO | GDPR | €7,447 | ↗ |
| 01 Jan 2012 | IDEAS CREATIVAS DE OPERACION S.L.IDEAS CREATIVAS DE OPERACION S.L. was fined EUR 33,001 by the AEPD for sending unsolicited commercial emails despite requests for data cancellation. The authority found a breach of Article 21 of the LSSI. | ES | AEPD | ePrivacy | €33,001 | ↗ |
| 16 Oct 2013 | FRANCE TELECOM ESPAÑA, S.A.FRANCE TELECOM ESPAÑA, S.A. was fined by the AEPD for sending commercial emails to a complainant despite a request not to use personal data for advertising purposes. The authority found a breach of Article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €33,001 | ↗ |
| 13 Jul 2012 | NH HOTELES, S.A.NH HOTELES, S.A. was fined by the AEPD for sending unsolicited commercial emails to a complainant after confirming the cancellation of their personal data. The authority found a breach of Article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €33,001 | ↗ |
| 28 Oct 2013 | LEGALITAS ASISTENCIA LEGAL, S.L.LEGALITAS ASISTENCIA LEGAL, S.L. was fined by the AEPD 33,000 EUR for sending unsolicited commercial communications. The conduct continued despite requests for data cancellation, which breached Article 21 of the LSSI. | ES | AEPD | ePrivacy | €33,000 | ↗ |
| 04 Jul 2025 | Niepubliczny Zakład Opieki ZdrowotnejUODO imposed a PLN 32,832 administrative fine on Niepubliczny Zakład Opieki Zdrowotnej for failing to conduct a risk analysis for processing patient data during home visits. The authority also found that appropriate technical and organizational measures to secure the data had not been implemented. | PL | UODO | GDPR | €7,733 | ↗ |