BULLETIN №082Last updated · 02 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 16 Jun 2020 | SCHOOL FITNESS HOLIDAY & FRANCHISING, S.L.U.SCHOOL FITNESS HOLIDAY & FRANCHISING, S.L.U. was fined by the AEPD 5,000 EUR for breaching the GDPR information obligations under Article 13. The case followed a complaint from the Madrid City Council's Consumer Unit. | ES | AEPD | GDPR | €5,000 | ↗ |
| 17 Jun 2020 | LA CASA COMPROMETIDA, S.Coop.The entity was fined by the AEPD in the amount of 3,000 EUR for failing to comply with data protection rules regarding its website cookie policy. The case concerned deficiencies in the required information or consent related to cookies. | ES | AEPD | ePrivacy | €3,000 | ↗ |
| 18 Jun 2020 | CAIXABANK, S.A.CAIXABANK, S.A. was fined by the AEPD for using pre-marked consents for data processing and charging customers a fee if they refused data sharing with third parties. The authority found that these practices breached GDPR requirements on valid consent and lawful processing. | ES | AEPD | GDPR | €2,100,000 | ↗ |
| 18 Jun 2020 | Azienda Pluriservizi Macerata S.p.A.Azienda Pluriservizi Macerata S.p.A. was fined EUR 4,000 by the Garante for processing colleagues’ personal data in a manner that did not comply with data protection principles. The authority cited breaches of lawfulness, fairness, transparency, and data minimization. | IT | Garante | GDPR | €4,000 | ↗ |
| 18 Jun 2020 | BANCO BILBAO VIZCAYA ARGENTARIA, S.A.Banco Bilbao Vizcaya Argentaria, S.A. was fined by the AEPD in the amount of EUR 30,000 for consulting personal data in credit files without an existing contractual relationship. The authority found that this conduct breached data processing principles. | ES | AEPD | GDPR | €30,000 | ↗ |
| 19 Jun 2020 | IBERDROLA CLIENTES, SAUThe AEPD fined IBERDROLA CLIENTES, SAU EUR 40,000 for emailing a customer's electricity bill, which contained sensitive personal data, to an unrelated third party. The incident indicates a breach of confidentiality and personal data protection obligations. | ES | AEPD | GDPR | €40,000 | ↗ |
| 22 Jun 2020 | ARANOW PACKAGING MACHINERY, S.L.ARANOW PACKAGING MACHINERY, S.L. was fined by the AEPD for non-compliance of its website with data protection rules. The breach concerned the absence of compliant Privacy and Cookie Policies. | ES | AEPD | ePrivacy | €3,000 | ↗ |
| 22 Jun 2020 | PARTIT DELS SOCIALISTES DE CATALUNYA (PSC-PSOE)PSC-PSOE was fined by the AEPD 5,000 EUR for using personal data obtained in a doctor-patient relationship to send requests for political support. The authority found this breached purpose limitation rules for data processing. | ES | AEPD | GDPR | €5,000 | ↗ |
| 23 Jun 2020 | B.B.B.B.B.B. was fined by the AEPD EUR 3,000 for improperly identifying an individual as the author of a traffic violation. The authority found that this conduct breached GDPR data protection principles. | ES | AEPD | GDPR | €3,000 | ↗ |
| 23 Jun 2020 | SALBEGAP, S.L.SALBEGAP, S.L. was fined by the AEPD EUR 2,000 for installing surveillance cameras in common areas without authorization from the homeowners' association. The authority found that this breached data protection principles. | ES | AEPD | GDPR | €2,000 | ↗ |
| 23 Jun 2020 | COMUNIDAD DE PROPIETAROS R.R.R.The entity was fined for installing video surveillance cameras without the required informational signage. The case concerned a breach of data protection rules and the obligation to properly inform individuals subject to monitoring. | ES | AEPD | GDPR | €2,000 | ↗ |
| 24 Jun 2020 | Azienda Sanitaria Universitaria Giuliano IsontinaAzienda Sanitaria Universitaria Giuliano Isontina was fined by the Garante for unlawfully communicating health data without an adequate legal basis. The conduct breached Article 20 of the Italian Privacy Code. | IT | Garante | GDPR | €10,000 | ↗ |
| 24 Jun 2020 | VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD 75,000 EUR for continuing to send promotional SMS messages to an individual whose personal data had previously been deleted. The authority found this conduct to be in breach of Article 6 GDPR. | ES | AEPD | GDPR | €75,000 | ↗ |
| 24 Jun 2020 | MIGUEL IBÁÑEZ BEZANILLA S.L.The entity was fined for failing to implement adequate security measures on its website and for providing insufficient privacy policy information. Non-compliance with cookie policy requirements was also identified. | ES | AEPD | GDPR | €3,000 | ↗ |
| 26 Jun 2020 | ESLORA PROYECTOS, S.L.ESLORA PROYECTOS, S.L. was fined by the AEPD 10,000 EUR for failing to provide cookie information and for not obtaining user consent before using cookies. The authority cited a breach of Article 22.2 of the LSSI. | ES | AEPD | ePrivacy | €10,000 | ↗ |
| 29 Jun 2020 | VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD EUR 60,000 for unauthorized processing of personal data. The case involved a fraudulent contract and the porting of a customer's phone line without a valid legal basis. | ES | AEPD | GDPR | €60,000 | ↗ |
| 29 Jun 2020 | NEW YORK COLLEGE A.ENEW YORK COLLEGE A.E was fined EUR 5,000 by the HDPA for conducting targeted phone calls without providing the required GDPR information. The authority found breaches of data processing principles and accountability obligations. | GR | HDPA | GDPR | €5,000 | ↗ |
| 30 Jun 2020 | VODAFONE ESPAÑA, S.A.U.VODAFONE ESPAÑA, S.A.U. was fined by the AEPD 15,000 EUR for incorrectly listing a customer's ex-spouse as the account holder, even though the customer's data appeared on invoices. The company acknowledged responsibility and paid the reduced fine. | ES | AEPD | GDPR | €15,000 | ↗ |
| 30 Jun 2020 | AOK Baden-WürttembergThe Baden-Württemberg data protection authority fined AOK Baden-Württemberg EUR 1.24 million on 2020-06-30. It found that personal data from more than 500 contest participants was processed for advertising purposes without valid consent, and that the technical and organizational measures required under Article 32 GDPR were insufficient. | DE | Landesbeauftragter für den Datenschutz und die Informationsfreiheit Baden-Württemberg | GDPR | €1,240,000 | ↗ |
| 30 Jun 2020 | Lejre KommuneLejre Kommune was fined by Datatilsynet for failing to implement appropriate security measures. This led to unauthorized access to sensitive personal data, including information about minors. | DK | Datatilsynet | GDPR | €6,709 | ↗ |