BULLETIN №082Last updated · 01 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.1%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 23 May 2019 | Ítélet a NAIH/2019/1189/11 sz. ügyben (Fővárosi Törvényszék 105.K.700.364/2019/11)The controller did not provide the requested personal data or information beyond a 2012 lease agreement. This breached the data subject’s access rights under the GDPR. | HU | NAIH | GDPR | €918 | ↗ |
| 23 May 2019 | Sziget Kulturális Menedzser Iroda Zártkörűen Működő RészvénytársaságThe NAIH fined Sziget Zrt. HUF 30,000,000 for unlawful data processing linked to event entry management. The authority found no proper legal basis and insufficient information provided to data subjects. | HU | NAIH | GDPR | €91,800 | ↗ |
| 23 May 2019 | Telenor Magyarország Zrt.Telenor Magyarország Zrt. was fined by the Hungarian NAIH 300,000 HUF for failing to comply with a data subject access request under the GDPR. The authority also found that the company did not inform the data subject of the right to an effective legal remedy. | HU | NAIH | GDPR | €918 | ↗ |
| 23 May 2019 | VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined EUR 60,000 by the AEPD for assigning a customer's DNI to a third party. This enabled unauthorized access to personal data and invoices, constituting a data protection breach. | ES | AEPD | GDPR | €60,000 | ↗ |
| 23 May 2019 | Ordinanza ingiunzione - 23 maggio 2019 [9124593]The Garante imposed a fine of EUR 1,250 for the loss of medical documentation related to a patient's health assessment. The records were not found in either paper or electronic form, which constituted a breach of data protection rules. | IT | Garante | GDPR | €1,250 | ↗ |
| 23 May 2019 | Bérleti jogviszony során keletkezett dokumentumok másolatban történő kiadásaThe controller did not comply with the data subject's access request for personal data beyond the 2012 lease agreement. The authority treated this as a breach of access-right obligations and imposed a fine. | HU | NAIH | GDPR | €918 | ↗ |
| 23 May 2019 | Comune di FerraraComune di Ferrara was fined 2,400 EUR by the Garante for violations linked to its online registry service. The system allowed citizens to obtain personal and civil status certificates at municipal pharmacies without adequate data protection measures. | IT | Garante | GDPR | €2,400 | ↗ |
| 23 May 2019 | Alkotmányjogi panasz elbírálása a NAIH/2019/1189/11. sz. ügyben (IV/1561/2020.)The controller did not comply with a data subject access request under the GDPR. NAIH imposed a fine of HUF 300,000 for unlawful data processing. | HU | NAIH | GDPR | €918 | ↗ |
| 27 May 2019 | VODAFONE ESPAÑA, S.A.U.Vodafone España, S.A.U. was fined 35,000 EUR by the AEPD for processing personal data without consent. The case involved charging a former customer for services not contracted due to a technical error. | ES | AEPD | GDPR | €35,000 | ↗ |
| 28 May 2019 | Geanonimiseerd (APD 04/2019)The APD Litigation Chamber imposed a EUR 2,000 fine for using email addresses collected for urban planning purposes to send election propaganda by a mayor. The authority found a breach of the GDPR purpose limitation principle. | BE | APD | GDPR | €2,000 | ↗ |
| 29 May 2019 | Regione PugliaRegione Puglia was fined by the Garante 10,000 EUR for unlawfully publishing personal data of participants in a selection process on its official website. The disclosure included tax codes and income data, breaching privacy rights. | IT | Garante | GDPR | €10,000 | ↗ |
| 31 May 2019 | Kamerafelvételek kiadásának elmulasztásaThe controller did not inform the data subject about the actions taken on their requests within the required timeframe. It also failed to provide access to certain data, which constituted a GDPR breach. | HU | NAIH | GDPR | €2,156 | ↗ |
| 03 Jun 2019 | Engedély nélkül végzett követelésvásárlási tevékenységgel összefüggő adatkezelésThe authority found that the controller processed personal data without a valid legal basis and for unlawful purposes in connection with unauthorized debt purchasing activities. A fine of HUF 1,000,000 was imposed. | HU | NAIH | GDPR | €3,090 | ↗ |
| 10 Jun 2019 | VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD 10,000 EUR for sending unsolicited advertising SMS messages to a complainant. The messages were sent despite the recipient’s request not to receive such communications. | ES | AEPD | ePrivacy | €10,000 | ↗ |
| 14 Jun 2019 | Facebook Ireland Ltd e Facebook Italy s.r.l.Facebook Ireland Ltd and Facebook Italy s.r.l. were fined EUR 1,000,000 by the Garante for violations involving the unauthorized sharing of user data with the application “Thisisyourdigitallife”. The case affected approximately 214,020 users. | IT | Garante | GDPR | €1,000,000 | ↗ |
| 17 Jun 2019 | TELEFONICA MOVILES ESPAÑA, S.A.U.TELEFONICA MOVILES ESPAÑA, S.A.U. was fined by the AEPD for incorrect processing of personal data. The error caused billing mistakes because one customer’s data was mixed with another subscriber’s information. | ES | AEPD | GDPR | €60,000 | ↗ |
| 18 Jun 2019 | A hozzáférési kérelem pontosítása; a hozzáférési kérelem elektronikus formában való teljesítéseThe controller did not facilitate the data subject’s right of access. It also failed to provide complete information about the personal data processed, including how to access files stored on a DVD. | HU | NAIH | GDPR | €1,550 | ↗ |
| 19 Jun 2019 | VF JEANSWEAR ESPAÑA S.L.VF Jeanswear España S.L. was fined by the AEPD 5,000 EUR for using cookies on its website without obtaining user consent. The case concerns a breach of data protection rules and consent requirements for cookies. | ES | AEPD | ePrivacy | €5,000 | ↗ |
| 20 Jun 2019 | XFERA MÓVILES, S.A. (YOIGO)XFERA MÓVILES, S.A. (YOIGO) was fined by the AEPD €65,000 for improper handling of personal data. The company failed to notify the rectification or deletion of personal data, which led to unwarranted debt collection calls. | ES | AEPD | GDPR | €65,000 | ↗ |
| 24 Jun 2019 | MADRILEÑA RED DE GAS S.A.U.Madrileña Red de Gas S.A.U. was fined by the AEPD 12,000 EUR for failing to ensure adequate security and confidentiality of personal data. This led to unauthorized access by a tenant to the contract holder’s data. | ES | AEPD | GDPR | €12,000 | ↗ |