BULLETIN №082Last updated · 02 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 03 Sept 2019 | Национална агенция за приходитеThe National Revenue Agency was fined 55,000 BGN for processing personal data without a lawful basis. The authority found that data were collected and used in enforcement proceedings in breach of Article 6 GDPR. | BG | CPDP | GDPR | €28,122 | ↗ |
| 03 Sept 2019 | ЧСИThe CPDP fined a private bailiff (ЧСИ) for failing to provide a data subject with access to personal data collected through video surveillance. The authority found a breach of Article 12 GDPR. | BG | CPDP | GDPR | €1,790 | ↗ |
| 03 Sept 2019 | А.Т.The CPDP imposed a fine of 23,000 BGN on A.T. for processing personal data without consent, in breach of Article 6 GDPR. The case concerned the creation of financial obligations for the complainant without a valid contract. | BG | CPDP | GDPR | €11,760 | ↗ |
| 06 Sept 2019 | Anonymised (CyDPC ΑΝΟΝΥΜΟΠΟΙΗΜΕΝΗ ΑΠΟΦΑΣΗ δημοσί)A medical practice was fined EUR 14,000 for posting a patient's pre- and post-surgery images on Instagram without consent. The authority found a breach of GDPR rules on personal data processing and the protection of special-category data. | CY | CyDPC | GDPR | €14,000 | ↗ |
| 10 Sept 2019 | Dane anonimowe (V. Sp. z o.o. z siedzibą w S. przy ul.)UODO found that V. Sp. z o.o. breached rules on the security and confidentiality of processed personal data. A fine of PLN 2,830,410 was imposed. | PL | UODO | GDPR | €653,000 | ↗ |
| 12 Sept 2019 | Anonymised (CyDPC ΑΝΩΝΥΜΟΠΟΙΗΜΕΝΗ ΑΠΟΦΑΣΗ ΔΗΜΟΠΡ)A complaint was filed against an individual for using personal data without consent to contact the complainant about a property sale. The Commissioner found a breach of Article 6 GDPR and imposed a fine of EUR 2,000. | CY | CyDPC | GDPR | €2,000 | ↗ |
| 12 Sept 2019 | MALONEY'S SPORT BAR S.L.MALONEY'S SPORT BAR S.L. was fined by the AEPD in the amount of 6,000 EUR for operating a video surveillance system that monitored public spaces without proper justification. The authority found this practice to be in breach of data protection rules. | ES | AEPD | GDPR | €6,000 | ↗ |
| 12 Sept 2019 | VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD EUR 2,500 for sending unsolicited commercial SMS messages without prior consent. The authority found this breached Article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €2,500 | ↗ |
| 17 Sept 2019 | vzw YThe Litigation Chamber fined vzw Y for failing to respond properly to a data subject’s requests for access to and erasure of personal data. The authority found breaches of GDPR Articles 12, 15, and 17. | BE | APD | GDPR | €2,000 | ↗ |
| 17 Sept 2019 | Geanonimiseerd (APD 06/2019)The case concerned a complaint about the use of electronic identity cards to create customer cards. The Litigation Chamber found breaches of data minimization, lawful basis for processing, and information duties under the GDPR, and imposed a fine of EUR 10,000. | BE | APD | GDPR | €10,000 | ↗ |
| 20 Sept 2019 | IBERDROLA CLIENTES, SAUIBERDROLA CLIENTES, SAU was fined by the AEPD 10,000 EUR for including personal data in the SOLCENT file without the required authorization. The authority found this to be a breach of data protection rules. | ES | AEPD | GDPR | €10,000 | ↗ |
| 23 Sept 2019 | VODAFONE ESPAÑA, S.A.U.The AEPD fined VODAFONE ESPAÑA, S.A.U. 60,000 EUR for processing personal data without consent. The breach led to an unauthorized service change and debt collection attempts. | ES | AEPD | GDPR | €60,000 | ↗ |
| 24 Sept 2019 | VUELING AIRLINES, S.L.VUELING AIRLINES, S.L. was fined by the AEPD 30,000 EUR for failing to comply with cookie consent requirements on its website. The authority found that the company did not provide the required information and did not properly obtain user consent. | ES | AEPD | ePrivacy | €30,000 | ↗ |
| 25 Sept 2019 | ASOCIACION DE MEDICOS DEMOCRATASASOCIACION DE MEDICOS DEMOCRATAS was fined by the AEPD EUR 10,000 for processing the personal data of medical professionals without their consent. The authority found a breach of Article 6(1)(a) GDPR. | ES | AEPD | GDPR | €10,000 | ↗ |
| 02 Oct 2019 | Tgroup s.r.l.Tgroup s.r.l. was fined 6,400 EUR by the Italian data protection authority, Garante. The case concerned the activation of a SIM card without the user's knowledge, which breached data protection rules. | IT | Garante | GDPR | €6,400 | ↗ |
| 04 Oct 2019 | Kerepes Város Települési ÖnkormányzataThe municipality of Kerepes was fined for unlawful processing of personal data through security cameras. The authority found a GDPR breach because data subjects were not informed in advance. | HU | NAIH | GDPR | €15,050 | ↗ |
| 07 Oct 2019 | Анонимизирано (CPDP решение-по-жалба-с-рег-№-ппн-01-657-08-0)The Bulgarian data protection authority, CPDP, fined an individual, V.M., BGN 1,000. The sanction concerned failure to provide access to information requested by the authority in connection with a complaint about unlawful dissemination of personal data. | BG | CPDP | GDPR | €511 | ↗ |
| 07 Oct 2019 | OTEOTE was fined by the HDPA EUR 200,000 for failing to process unsubscribe requests from marketing emails due to a technical error. The issue affected about 8,000 subscribers and had been ongoing since 2013. | GR | HDPA | GDPR | €200,000 | ↗ |
| 08 Oct 2019 | Министър на вътрешните работиThe Ministry of Interior was fined for unlawfully processing and sharing the personal data of a Finnish citizen with Togo authorities without a legal basis. The authority found a breach of GDPR principles on lawful processing and data disclosure. | BG | CPDP | GDPR | €5,113 | ↗ |
| 09 Oct 2019 | Vreau Credit S.R.L.Vreau Credit S.R.L. was fined by ANSPDCP in the amount of 20,000 EUR for failing to notify a personal data breach without undue delay. The company had been aware of the incident since December 2018 but did not inform the supervisory authority promptly. | RO | ANSPDCP | GDPR | €20,000 | ↗ |