BULLETIN №082Last updated · 30 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.2%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 17 Nov 2023 | Gemeente VoorschotenThe municipality of Voorschoten unlawfully processed personal data about residents’ waste disposal history without a sufficient legal basis. It also failed to properly inform the affected residents, breaching GDPR Articles 5, 6 and 14. | NL | AP | GDPR | €30,000 | ↗ |
| 24 Mar 2021 | ALLIANZ COMPAÑIA DE SEGUROS Y REASEGUROS, S.A.ALLIANZ COMPAÑIA DE SEGUROS Y REASEGUROS, S.A. was fined EUR 30,000 by the AEPD. The authority found that after a policy was canceled, the company continued processing personal data without a lawful basis, in breach of Article 6 GDPR. | ES | AEPD | GDPR | €30,000 | ↗ |
| 25 Mar 2021 | OneDirect S.r.l.OneDirect S.r.l. was fined EUR 30,000 by the Garante. The authority found that the company sent unsolicited promotional emails despite objections and failed to respond to data subject requests. | IT | Garante | GDPR | €30,000 | ↗ |
| 13 Apr 2022 | PYRAMID CONSULTINGPYRAMID CONSULTING was fined by the AEPD EUR 30,000 for unlawful processing of personal data. The company incorrectly identified an individual as responsible for a traffic violation, which led to an improper administrative sanction. | ES | AEPD | GDPR | €30,000 | ↗ |
| 10 Apr 2025 | Yolo Group S.p.a.Yolo Group S.p.a. was fined by the Garante 30,000 EUR for a data breach involving personal and contact data of a large number of individuals. The authority found a violation of Article 33 of the GDPR, which concerns notification of personal data breaches. | IT | Garante | GDPR | €30,000 | ↗ |
| 08 Jul 2021 | Regione PugliaThe Garante fined Regione Puglia EUR 30,000 for the unlawful dissemination of personal health data on the web. The authority found breaches of lawfulness, fairness, transparency, and data minimization principles. | IT | Garante | GDPR | €30,000 | ↗ |
| 15 Feb 2018 | Auto Uno s.r.l.Auto Uno s.r.l. was fined EUR 30,000 by the Italian Garante. The case concerned improper management of a video surveillance system, including excessive retention of recorded images. | IT | Garante | GDPR | €30,000 | ↗ |
| 15 Mar 2018 | Studio Silver Consulting S.r.l.s.Studio Silver Consulting S.r.l.s. was fined EUR 30,000 by the Garante for violations related to the processing of personal data in its debt management activities. The case concerned improper handling of personal data in the context of debt collection operations. | IT | Garante | GDPR | €30,000 | ↗ |
| 05 Sept 2013 | Huawei Technologies Italia S.r.lHuawei Technologies Italia S.r.l was fined EUR 30,000 by the Garante for breaching data protection rules. The company retained surveillance footage for 18 days, exceeding the permitted retention period. | IT | Garante | GDPR | €30,000 | ↗ |
| 16 Dec 2022 | INTER PARTNER ASSISTANCE SERVICIOS ESPAÑA, S.A.INTER PARTNER ASSISTANCE SERVICIOS ESPAÑA, S.A. was fined by the AEPD 30,000 EUR for potentially transferring personal data internationally without proper disclosure. This was contrary to the company’s stated privacy policies. | ES | AEPD | GDPR | €30,000 | ↗ |
| 28 Mar 2022 | CENTRO MÉDICO SALUS BALEARES, S.L.CENTRO MÉDICO SALUS BALEARES, S.L. was fined by the AEPD 30,000 EUR for breaching data protection rules. The case concerned displaying patients’ body temperatures in a way that could be seen by unauthorized third parties, which compromised confidentiality. | ES | AEPD | GDPR | €30,000 | ↗ |
| 01 Jan 2019 | TELEFONICA DE ESPAÑA, S.A.U.Telefónica de España, S.A.U. was fined EUR 30,000 by the AEPD for charging a customer for a phone line they did not own. The authority found a breach of the GDPR data accuracy principle. | ES | AEPD | GDPR | €30,000 | ↗ |
| 29 Apr 2025 | Ordine degli Psicologi della Regione LombardiaThe Garante fined the Ordine degli Psicologi della Regione Lombardia EUR 30,000 for a data breach. The incident exposed personal and sensitive data of about 15,000 individuals, including information covered by professional secrecy and special categories of data. | IT | Garante | GDPR | €30,000 | ↗ |
| 05 Dec 2013 | Associazione culturale KoalaAssociazione culturale Koala was fined 30,000 EUR by the Italian Garante. The case concerned the installation of a fingerprint recognition system for user access without providing the required information to the supervisory authority. | IT | Garante | GDPR | €30,000 | ↗ |
| 01 Jan 2023 | DEH NOTIFICACION ELECTRONICA HABILITADA S.L.DEH NOTIFICACION ELECTRONICA HABILITADA S.L. was fined by the AEPD €30,000 for sending unencrypted passwords for digital certificates. The authority considered this a potential data security risk. The procedure concerning Article 6(1) GDPR was archived due to no infringement. | ES | AEPD | GDPR | €30,000 | ↗ |
| 18 Dec 2024 | GAOLANIA SERVICIOS, S.L.GAOLANIA SERVICIOS, S.L. was fined EUR 30,000 by the AEPD for breaching the GDPR data accuracy principle under Article 5(1)(d). The authority found a lack of diligence in handling data errors. | ES | AEPD | GDPR | €30,000 | ↗ |
| 05 Feb 2020 | TELEFONICA MÓVILES ESPAÑA, S.A.U.TELEFONICA MÓVILES ESPAÑA, S.A.U. was fined by the AEPD 30,000 EUR for failing to comply with a resolution concerning the GDPR right of access. The case indicates non-implementation of an obligation set out in a prior supervisory authority decision. | ES | AEPD | GDPR | €30,000 | ↗ |
| 01 Jan 2019 | VODAFONE ESPAÑA, S.A.U.The AEPD fined Vodafone España, S.A.U. 30,000 EUR for changing a customer's phone plan and purchasing a mobile device without consent. The case concerns a breach of data protection rules and the absence of a valid legal basis for processing the customer's data. | ES | AEPD | GDPR | €30,000 | ↗ |
| 31 May 2018 | Autosat S.p.A.Autosat S.p.A. was fined by the Italian Garante in the amount of EUR 30,000 for breaches of data protection rules. The case concerned the handling of personal data and the security measures used in the company’s IT systems. | IT | Garante | GDPR | €30,000 | ↗ |
| 05 Jul 2017 | Klik s.r.l.Klik s.r.l. was fined EUR 30,000 by the Garante for retaining telephone traffic data for more than 24 months. The authority found this to be a breach of data protection rules. | IT | Garante | GDPR | €30,000 | ↗ |