BULLETIN №082Last updated · 31 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.4%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 21 Nov 2018 | Legea s.p.a.Legea s.p.a. was fined for processing personal data through forms on its website without providing the required information notice to data subjects. The case concerned a breach of Article 13 of the Italian Privacy Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 29 Nov 2018 | Wind Tre S.p.A.Wind Tre S.p.A. was fined EUR 600,000 by the Garante for unsolicited promotional calls and SMS. The authority found breaches of several provisions of the Italian Data Protection Code. | IT | Garante | GDPR | €600,000 | ↗ |
| 29 Nov 2018 | Istituto Nazionale Previdenza Sociale (INPS)INPS was fined for processing the personal data of 12.6 million private workers using automated software without prior verification. The authority found this to be a breach of data protection rules. | IT | Garante | GDPR | €40,000 | ↗ |
| 11 Dec 2018 | Anonymizováno (ÚOOÚ UOOU-00313/19-23)The supervisory authority found that the entity failed to implement adequate technical and organizational measures to secure personal data processing and did not properly inform data subjects. Personal data of loan applicants were retained longer than necessary, in breach of the GDPR. | CZ | UOOU | GDPR | €3,869 | ↗ |
| 13 Dec 2018 | Anonymizováno (ÚOOÚ UOOU-08001/18-14)The entity was fined 40,000 CZK by the UOOU for insufficient security measures in the processing of personal data. The authority cited inadequate audit logs and a lack of regular access checks to electronic health records. | CZ | UOOU | GDPR | €1,549 | ↗ |
| 13 Dec 2018 | Ordinanza ingiunzione - 13 dicembre 2018 [9124641]The sole proprietorship acting as an agent for Western Union carried out unauthorized money transfers using personal data without consent. The authority found a breach of data protection rules and imposed a EUR 8,000 fine. | IT | Garante | GDPR | €8,000 | ↗ |
| 13 Dec 2018 | Ministero dell’Istruzione, dell’Università e della Ricerca – Ufficio Scolastico Regionale per la Lombardia – Ufficio III – Ambito territoriale di BergamoThe Ministry of Education’s regional office in Bergamo was fined for unlawfully publishing personal data related to disciplinary proceedings on its website. The authority found a breach of data protection rules. | IT | Garante | GDPR | €4,000 | ↗ |
| 18 Dec 2018 | ORGANIZACION NACIONAL DE CIEGOS (ONCE)ONCE was fined EUR 40,000 by the AEPD for sending more than 200 unsolicited commercial emails without prior consent. The authority found this to be a breach of Article 21 of the LSSI governing electronic marketing communications. | ES | AEPD | ePrivacy | €40,000 | ↗ |
| 20 Dec 2018 | Anonymisiert (DSB DSB-D550.037/0003-DSB/2018)The DSB imposed a fine of EUR 2,200 for unlawful video surveillance covering common areas and neighboring properties without consent. The conduct breached GDPR principles of data minimization and purpose limitation. | AT | DSB | GDPR | €2,200 | ↗ |
| 21 Dec 2018 | Nationale PolitieThe Dutch Data Protection Authority imposed a penalty payment on Nationale Politie for failing to regularly and proactively review log files. The authority found this breached the Police Data Act. | NL | AP | GDPR | €40,000 | ↗ |
| 21 Dec 2018 | Nationale PolitieThe Dutch Data Protection Authority imposed a penalty payment on Nationale Politie for failing to regularly and proactively review log files. The authority found this breached the Police Data Act. | NL | AP | GDPR | €40,000 | ↗ |
| 01 Jan 2019 | IKEA IBERICA, S.A.U.The AEPD fined IKEA IBERICA, S.A.U. 10,000 EUR for installing cookies on users’ devices without obtaining prior informed consent. The authority found this breached Article 22.2 of the LSSI. | ES | AEPD | ePrivacy | €10,000 | ↗ |
| 01 Jan 2019 | VODAFONE ESPAÑA, S.A.U.Vodafone España was fined 40,000 EUR by the AEPD for charging a customer for a Netflix service that had not been contracted. The authority found a breach of GDPR Article 6 due to the lack of a lawful basis for the charge and related processing. | ES | AEPD | GDPR | €40,000 | ↗ |
| 01 Jan 2019 | ELECTRIC RENTING GROUP, S.L.ELECTRIC RENTING GROUP, S.L. was fined by the AEPD EUR 2,500 for sending a promotional email without using BCC. This exposed recipients’ email addresses and breached data protection rules. | ES | AEPD | GDPR | €2,500 | ↗ |
| 01 Jan 2019 | XFERA MÓVILES, S.A. (YOIGO)XFERA MÓVILES, S.A. (YOIGO) was fined by the AEPD EUR 60,000 for incorrectly including personal data in a creditworthiness file. The authority found a breach of the GDPR accuracy principle under Article 5(1)(d). | ES | AEPD | GDPR | €60,000 | ↗ |
| 01 Jan 2019 | ZHANG BORDETA 2006, S.L.ZHANG BORDETA 2006, S.L. was fined EUR 6,000 by the AEPD for disproportionate video surveillance of public areas. The authority also found that no informational notice was provided inside the establishment, breaching data protection rules. | ES | AEPD | GDPR | €6,000 | ↗ |
| 01 Jan 2019 | AVON COSMETICS SAUAVON COSMETICS SAU was fined by the AEPD 60,000 EUR for improper processing of personal data. The company included an individual in a creditworthiness file without first verifying the person’s identity. | ES | AEPD | GDPR | €60,000 | ↗ |
| 01 Jan 2019 | VIAQUA XESTIÓN INTEGRAL DE AUGAS DE GALICIA, S.A.The company changed contract data without authorization, which constituted a breach of Article 6 of the GDPR. The AEPD imposed a fine of 60,000 EUR. | ES | AEPD | GDPR | €60,000 | ↗ |
| 01 Jan 2019 | VODAFONE ESPAÑA, S.A.UVodafone España, S.A.U was fined by the AEPD in the amount of 2,500 EUR for sending unsolicited advertising messages to a business phone number without consent. The case concerned Article 21 of the LSSI, which governs marketing communications without prior recipient consent. | ES | AEPD | ePrivacy | €2,500 | ↗ |
| 01 Jan 2019 | IBERIA LÍNEAS AÉREAS DE ESPAÑA, S.A. OPERADORA UNIPERSONALIberia was fined by the AEPD 20,000 EUR for continuing to send emails to a customer who had requested removal from the loyalty program and deletion of personal data. The authority found this conduct to be a breach of GDPR Article 6. | ES | AEPD | GDPR | €20,000 | ↗ |