BULLETIN №082Last updated · 31 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.4%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 29 Jun 2023 | FUNDACIÓN VEDRUNA EDUCACIÓN COLEGIOA teacher publicly disclosed the content of an email concerning a student's issues, breaching the duty of confidentiality. The AEPD found a violation of data protection rules and imposed a 15,000 EUR fine. | ES | AEPD | GDPR | €15,000 | ↗ |
| 28 Jun 2023 | FESTINA LOTUS S.A.FESTINA LOTUS S.A. did not respond to requests to delete a user's account and personal data. The authority found a breach of Article 17 GDPR and imposed a fine of EUR 1,000. | ES | AEPD | GDPR | €1,000 | ↗ |
| 28 Jun 2023 | Fortis Insolvency LimitedFortis Insolvency Limited sent 558,354 direct marketing SMS messages without valid consent, of which 527,481 were received by subscribers between 26 July 2020 and 26 July 2021. This breached regulation 22 of PECR. The company was fined £30,000 and issued with an enforcement notice. | GB | ICO | ePrivacy | €34,713 | ↗ |
| 27 Jun 2023 | OPTIME 2016 SLOPTIME 2016 SL was fined EUR 500 by the AEPD for failing to provide requested information. The authority treated this as a breach of Article 58(1) GDPR. | ES | AEPD | GDPR | €500 | ↗ |
| 27 Jun 2023 | Farmacia Ardealul SRLFarmacia Ardealul SRL was fined by ANSPDCP EUR 2,500 for a data security breach on its website. Unauthorized malware installation led to the compromise of personal data confidentiality, including banking data, of a significant number of clients. | RO | ANSPDCP | GDPR | €2,500 | ↗ |
| 27 Jun 2023 | A.I.C. ehf.A.I.C. ehf. was fined by Persónuvernd 3,500,000 ISK for registering loan defaults with Creditinfo Lánstraust hf. without meeting the required registration conditions. The case also involved defaults on loans below the minimum threshold for registration. | IS | Persónuvernd | GDPR | €23,520 | ↗ |
| 27 Jun 2023 | Creditinfo Lánstraust hf.Creditinfo Lánstraust hf. was fined by Persónuvernd for recording loan default information without meeting the required registration conditions. The authority found breaches of GDPR transparency and lawfulness requirements in the processing of personal data. | IS | Persónuvernd | GDPR | €254,000 | ↗ |
| 27 Jun 2023 | embætti landlæknisThe Icelandic DPA fined embætti landlæknis 12,000,000 ISK for security weaknesses in the Heilsuvera website. The flaw allowed unauthorized access to personal data, indicating a failure to maintain adequate safeguards. | IS | Persónuvernd | GDPR | €80,640 | ↗ |
| 27 Jun 2023 | eCommerce 2020 ApSeCommerce 2020 ApS was fined by Persónuvernd in the amount of 7,500,000 ISK for registering loan defaults with Creditinfo Lánstrausti hf. without meeting the required conditions. The authority noted, among other issues, that claims below the minimum threshold were registered. The case concerns improper handling of debt-related personal data. | IS | Persónuvernd | GDPR | €50,400 | ↗ |
| 26 Jun 2023 | Hozzáférési kérelem nem teljesítéseThe controller did not properly handle the data subject’s requests for access and deletion of personal data. NAIH imposed a fine of HUF 500,000 for violating Article 15 GDPR. | HU | NAIH | GDPR | €1,355 | ↗ |
| 26 Jun 2023 | Bonnier News ABBonnier News AB was fined by IMY SEK 13,000,000 for processing personal data without a legal basis. The authority found that the company profiled individuals using behavioral data to display targeted ads and for direct marketing purposes. | SE | IMY | GDPR | €1,112,000 | ↗ |
| 26 Jun 2023 | B.B.B.B.B.B. was fined by the AEPD 10,000 EUR for uploading sexual and personal content of an ex-partner to YouTube and ForoCoches without consent. The authority found this to be a breach of data protection rules. | ES | AEPD | GDPR | €10,000 | ↗ |
| 24 Jun 2023 | BANCO BILBAO VIZCAYA ARGENTARIA, S.A.BBVA was fined EUR 5,000 by the AEPD for repeatedly sending commercial emails to a client despite requests to unsubscribe. The authority found this breached Article 21 of the LSSI on unsolicited commercial communications. | ES | AEPD | ePrivacy | €5,000 | ↗ |
| 23 Jun 2023 | LINKEDIN IRELAND LIMITEDThe AEPD fined LinkedIn Ireland Limited EUR 10,000 for sending advertising emails after the recipient had opted out. The authority found a breach of Article 21.1 of the LSSI governing unsolicited marketing communications. | ES | AEPD | ePrivacy | €10,000 | ↗ |
| 23 Jun 2023 | BKM Budapesti Közművek Nonprofit Zrt.NAIH imposed a 16,000,000 HUF fine on BKM Budapesti Közművek Nonprofit Zrt. for failing to implement adequate technical and organizational measures to protect data security. The authority also found deficiencies in the reporting of a personal data breach. | HU | NAIH | GDPR | €43,200 | ↗ |
| 22 Jun 2023 | MIFARMA TIENDA ON-LINE, S.L.MIFARMA TIENDA ON-LINE, S.L. was fined by the AEPD €2,000 for sending commercial electronic communications after the recipient had requested that they stop. The authority found a breach of Article 21.1 of the LSSI. | ES | AEPD | ePrivacy | €2,000 | ↗ |
| 22 Jun 2023 | ASOCIACIÓN CANNÁBICA CLUB 26The entity installed surveillance cameras facing public spaces without prior administrative authorization. This may have infringed third-party rights and data protection rules. | ES | AEPD | GDPR | €500 | ↗ |
| 22 Jun 2023 | Futuro Molise S.r.l.Futuro Molise S.r.l. was fined EUR 2,000 by the Garante for publishing an article that contained personal data without demonstrating a public interest basis. The authority found a breach of data protection rules. | IT | Garante | GDPR | €2,000 | ↗ |
| 22 Jun 2023 | More News società cooperativa a r.l.The Garante fined More News società cooperativa a r.l. 5,000 EUR for publishing a minor’s personal data without proper anonymization. The disclosure allowed acquaintances to identify the child and caused embarrassment. | IT | Garante | GDPR | €5,000 | ↗ |
| 22 Jun 2023 | Digi Távközlési és Szolgáltató Kft.Digi Távközlési és Szolgáltató Kft. was fined by the NAIH for failing to delete a test database containing personal data after the tests were completed. The authority found a breach of storage limitation and data security obligations. | HU | NAIH | GDPR | €216,000 | ↗ |