BULLETIN №082Last updated · 02 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 10 Jan 2020 | AUTOMOCION X.X.X. S.L.The company was fined EUR 1,000 by the AEPD for placing an individual's photo, name, and phone number on an adult contact website without consent. The disclosure led to unwanted calls and constituted a breach of personal data protection rules. | ES | AEPD | GDPR | €1,000 | ↗ |
| 10 Jan 2020 | XFERA MÓVILES, S.A.XFERA MÓVILES, S.A. was fined by the AEPD EUR 30,000 for a data protection breach. A customer's data was incorrectly linked to another person, which allowed unauthorized access to personal information. | ES | AEPD | GDPR | €30,000 | ↗ |
| 12 Jan 2020 | VODAFONE ESPAÑA, S.A.U.The AEPD fined VODAFONE ESPAÑA, S.A.U. 100,000 EUR for charging a customer for a service that had not been contracted. The case concerned non-compliance with consent requirements linked to data processing and service billing. | ES | AEPD | GDPR | €100,000 | ↗ |
| 14 Jan 2020 | REAL CLUB NAÚTICO DE RIBADEOREAL CLUB NAÚTICO DE RIBADEO was fined by the AEPD 6,000 EUR for publishing a court judgment containing personal data on its website and Facebook without anonymization. This constituted a breach of data protection rules. | ES | AEPD | GDPR | €6,000 | ↗ |
| 15 Jan 2020 | TIM S.p.A.TIM S.p.A. was fined by the Garante for making unauthorized promotional calls. The authority found that the company failed to ensure adequate consent and accountability measures under data protection rules. | IT | Garante | GDPR | €27,802,000 | ↗ |
| 15 Jan 2020 | Comune di Francavilla FontanaThe Municipality of Francavilla Fontana was fined 10,000 EUR by the Garante for publishing personal data on its institutional website. The conduct breached data protection rules and triggered supervisory action. | IT | Garante | GDPR | €10,000 | ↗ |
| 16 Jan 2020 | VODAFONE ESPAÑA SAUVODAFONE ESPAÑA SAU was fined 120,000 EUR by the AEPD for unlawful processing of personal data. The case involved threatening to include a minor's data in a credit file over an alleged unpaid debt. | ES | AEPD | GDPR | €120,000 | ↗ |
| 22 Jan 2020 | Res iudicata terjedelme a hozzáférési kérelem elbírálása kapcsánThe controller did not adequately respond to the data subject’s access request, breaching Article 15 GDPR. NAIH imposed a fine of HUF 2,000,000. | HU | NAIH | GDPR | €5,960 | ↗ |
| 23 Jan 2020 | Runwhip s.r.l.Runwhip s.r.l. was fined €80,000 by the Italian supervisory authority, Garante. The sanction concerned failure to respond to information requests, which was treated as a breach of GDPR Article 5. | IT | Garante | GDPR | €80,000 | ↗ |
| 23 Jan 2020 | Azienda Ospedaliero Universitaria Integrata di VeronaAzienda Ospedaliero Universitaria Integrata di Verona was fined by the Garante EUR 30,000 for employees' unauthorized access to patient health records. The authority found a breach of GDPR principles on data protection and security measures. | IT | Garante | GDPR | €30,000 | ↗ |
| 24 Jan 2020 | Adatbiztonsági intézkedések és incidenskezelési gyakorlat hiányosságaiThe entity failed to implement appropriate technical and organizational measures to protect data, including storing access data in printed form. Its internal incident management policy also did not regulate the obligation to notify the supervisory authority. | HU | NAIH | GDPR | €1,490 | ↗ |
| 29 Jan 2020 | B.B.B.The AEPD fined B.B.B. EUR 2,000 for using a phone number for a purpose other than the one for which it was originally collected. The authority found this to be a breach of the GDPR principle of purpose limitation. | ES | AEPD | GDPR | €2,000 | ↗ |
| 29 Jan 2020 | COLEGIO ARENALES CARABANCHELThe school was fined by the AEPD 5,000 EUR for unlawfully sharing and publishing images of children without consent. The case involved a breach of data protection rules and the need for valid consent to process minors’ images. | ES | AEPD | GDPR | €5,000 | ↗ |
| 29 Jan 2020 | CASA GRACIO OPERATION, SLUCASA GRACIO OPERATION, SLU was fined by the AEPD 10,000 EUR for installing a video surveillance system that could capture public areas and access points. The authority found that this processing breached data protection rules. | ES | AEPD | GDPR | €10,000 | ↗ |
| 30 Jan 2020 | Liceo Nobel di Torre del GrecoLiceo Nobel di Torre del Greco was fined EUR 4,000 by the Garante for publishing a teacher ranking list on its website. The conduct breached GDPR principles of lawfulness, fairness, transparency, and data minimization. | IT | Garante | GDPR | €4,000 | ↗ |
| 30 Jan 2020 | Comune di ColledaraComune di Colledara was fined EUR 4,000 by the Garante for publishing personal data in the provisional ranking of a competition on its institutional website. The authority found breaches of lawfulness, fairness, transparency, and data minimization. | IT | Garante | GDPR | €4,000 | ↗ |
| 04 Feb 2020 | XFERA MÓVILES, S.A.XFERA MÓVILES, S.A. was fined by the Spanish data protection authority, AEPD, in the amount of 5,000 EUR. The sanction concerned obstruction of the authority’s inspection function, which breaches Article 58(1) GDPR. | ES | AEPD | GDPR | €5,000 | ↗ |
| 04 Feb 2020 | VODAFONE ESPAÑA, S.A.U.The AEPD imposed a 50,000 EUR fine on VODAFONE ESPAÑA, S.A.U. for sending an SMS indicating a contract using incorrect personal data. The authority found a breach of Article 6 GDPR concerning the lawful basis for processing. | ES | AEPD | GDPR | €50,000 | ↗ |
| 04 Feb 2020 | TELEFONICA MOVILES ESPAÑA, S.A.U.TELEFONICA MOVILES ESPAÑA, S.A.U. was fined 75,000 EUR by the AEPD for processing personal data without consent. The case concerned unauthorized portability of a phone line. | ES | AEPD | GDPR | €75,000 | ↗ |
| 04 Feb 2020 | VODAFONE ESPAÑA, S.A.U.The AEPD fined VODAFONE ESPAÑA, S.A.U. 60,000 EUR for a data protection violation. The case involved unauthorized data processing and signature forgery by an employee, which led to a fraudulent service transfer. | ES | AEPD | GDPR | €60,000 | ↗ |