BULLETIN №082Last updated · 31 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.4%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 01 Jan 2019 | AMADOR RECREATIVOS, S.L.AMADOR RECREATIVOS, S.L. was fined by the AEPD 6,000 EUR for installing a video surveillance system aimed at public space without justified cause. The case concerned an unjustified scope of monitoring and a breach of data protection rules. | ES | AEPD | GDPR | €6,000 | ↗ |
| 01 Jan 2019 | CAFE BAR NINA (Nina Cb)CAFE BAR NINA was fined €2,000 by the AEPD for installing an unauthorized surveillance camera. The conduct breached data protection requirements. | ES | AEPD | GDPR | €2,000 | ↗ |
| 01 Jan 2019 | KNLTBThe Dutch tennis association KNLTB was fined by the Autoriteit Persoonsgegevens for violating the GDPR/AVG. The original fine was 525,000 EUR and was later reduced to 250,000 EUR because KNLTB shared members’ personal data with two sponsors without a valid legal basis. | NL | Autoriteit Persoonsgegevens | GDPR | €525,000 | ↗ |
| 01 Jan 2019 | EDP ENERGÍA, S.A.U.EDP ENERGÍA, S.A.U. was fined by the AEPD EUR 75,000 for processing personal data without consent. The case concerned an energy contract to which the complainant was not a party, constituting a breach of Article 6(1) GDPR. | ES | AEPD | GDPR | €75,000 | ↗ |
| 01 Jan 2019 | TELEFONICA MOVILES ESPAÑA, S.A.U.TELEFONICA MOVILES ESPAÑA, S.A.U. was fined 50,000 EUR by the AEPD. The authority found that the company used personal data to fraudulently contract phone lines without the data subjects’ consent. | ES | AEPD | GDPR | €50,000 | ↗ |
| 01 Jan 2019 | GESTIÓN DE COBROS, YO COBRO SLThe company was fined EUR 60,000 by the AEPD for unlawfully processing personal data. The breach involved sending debt collection emails to an institutional email address without consent, in violation of data protection rules. | ES | AEPD | GDPR | €60,000 | ↗ |
| 01 Jan 2019 | Don B.B.B.Don B.B.B. was fined by the AEPD in the amount of 1,000 EUR for sending an unsolicited commercial email. The conduct breached Article 21 of the LSSI, which governs marketing communications without prior consent. | ES | AEPD | ePrivacy | €1,000 | ↗ |
| 01 Jan 2019 | Vodafone España, S.A.U.Vodafone España, S.A.U. was fined EUR 75,000 by the AEPD for a data protection breach. The case involved unauthorized contract portability using a customer's personal data without consent. | ES | AEPD | GDPR | €75,000 | ↗ |
| 01 Jan 2019 | VODAFONE ESPAÑA, S.A.U.The AEPD imposed a fine of EUR 55,000 on Vodafone España, S.A.U. for breaching data protection principles. The case involved sending a customer's personal data to a third party without adequate security measures. | ES | AEPD | GDPR | €55,000 | ↗ |
| 01 Jan 2019 | LINEA DIRECTA ASEGURADORA, S.A.LINEA DIRECTA ASEGURADORA, S.A. was fined by the AEPD for sending unsolicited advertising emails without a prior relationship with the recipient. The authority found this breached Article 21 of the LSSI. | ES | AEPD | ePrivacy | €2,500 | ↗ |
| 01 Jan 2019 | GLOVOAPP23, S.L.GLOVOAPP23, S.L. was fined by the Spanish data protection authority, AEPD, in the amount of €25,000. The authority found a breach for failing to appoint a Data Protection Officer as required by Article 37 of the GDPR. | ES | AEPD | GDPR | €25,000 | ↗ |
| 09 Jan 2019 | TOM TOM SALES BV SUCURSAL EN ESPAÑATOM TOM SALES BV SUCURSAL EN ESPAÑA was fined by the AEPD 2,500 EUR for sending a promotional email to a user after confirming the deletion of their data. The authority found this conduct breached Article 21 of the LSSI. | ES | AEPD | ePrivacy | €2,500 | ↗ |
| 17 Jan 2019 | Учебно заведениеThe school was fined 1,000 BGN by the CPDP for unlawfully processing students' personal data. It shared the data with a financial institution without proper consent, which breached GDPR requirements. | BG | CPDP | GDPR | €511 | ↗ |
| 21 Jan 2019 | XFERA MÓVILES, S.A.XFERA MÓVILES, S.A. was fined by the AEPD in the amount of 2,500 EUR for sending unsolicited commercial SMS messages. The authority found that this conduct breached Article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €2,500 | ↗ |
| 29 Jan 2019 | LOS SEIS MAESTROS S.L.LOS SEIS MAESTROS S.L. was fined by the AEPD EUR 3,000 for processing personal data without consent. The breach involved sending an email offering a discount for an event, contrary to Article 6.1 of the LOPD. | ES | AEPD | ePrivacy | €3,000 | ↗ |
| 31 Jan 2019 | Istituto Comprensivo Paolo StefanelliIstituto Comprensivo Paolo Stefanelli was fined by the Garante 4,000 EUR for publishing personal data on its website that revealed individuals' health status. The case involved a breach of privacy rules and the protection of sensitive data. | IT | Garante | GDPR | €4,000 | ↗ |
| 31 Jan 2019 | Comune di BardolinoThe Municipality of Bardolino was fined EUR 8,000 by the Garante for publishing personal data on its institutional website without an appropriate legal basis. The disclosure included names and tax codes of beneficiaries of economic contributions, as well as personal information of two municipal employees. | IT | Garante | GDPR | €8,000 | ↗ |
| 31 Jan 2019 | Istituto di Istruzione Superiore C.Istituto di Istruzione Superiore C. was fined EUR 4,000 by the Garante for publishing sensitive personal data, including health information, on its website. The conduct breached data protection requirements. | IT | Garante | GDPR | €4,000 | ↗ |
| 31 Jan 2019 | Istituto Scolastico Superiore “Andrea Mantegna”Istituto Scolastico Superiore “Andrea Mantegna” was fined by the Garante €4,000 for unlawfully publishing personal data on its institutional website. The disclosure included health information about teaching staff, which is sensitive personal data. | IT | Garante | GDPR | €4,000 | ↗ |
| 31 Jan 2019 | Comune di CataniaThe Municipality of Catania was fined EUR 6,000 by the Garante for unlawfully publishing personal data on its institutional website in connection with housing and rental assistance programs. The disclosed information included names, dates of birth, tax codes, and addresses. | IT | Garante | GDPR | €6,000 | ↗ |