BULLETIN №082Last updated · 03 Aug 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.7%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 24 Jul 2020 | I-DE REDES ELÉCTRICAS INTELIGENTES, S.A.UI-DE REDES ELÉCTRICAS INTELIGENTES, S.A.U was fined by the AEPD EUR 200,000 for sending letters to customers without a legal basis. The authority found that this breached the principles of data minimization and purpose limitation. | ES | AEPD | GDPR | €200,000 | ↗ |
| 24 Jul 2020 | IBERIA LÍNEAS AÉREAS DE ESPAÑA, S.A. OPERADORA UNIPERSONALThe AEPD fined Iberia Líneas Aéreas de España, S.A. Operadora Unipersonal 30,000 EUR. The authority found that the website did not provide users with an option to reject cookies in line with consent requirements. | ES | AEPD | ePrivacy | €30,000 | ↗ |
| 28 Jul 2020 | Geanonimiseerd (APD 39/2020)The case concerns a complaint about the processing of voters’ personal data during municipal elections. The controller used old electoral lists without a lawful basis, breaching the GDPR principles of purpose limitation and lawfulness. | BE | APD | GDPR | €5,000 | ↗ |
| 28 Jul 2020 | Anonymizováno (ÚOOÚ UOOU-05226/19-22)The entity was fined for publishing personal data of court proceeding participants on a website. The authority found this to be a breach of data protection law. | CZ | UOOU | GDPR | €1,905 | ↗ |
| 29 Jul 2020 | CALLESGARCIA S.C.CALLESGARCIA S.C. was fined by the AEPD €4,000 for using a wedding photo in business advertising without authorization. The authority found a breach of Article 6 GDPR on lawful processing of personal data. | ES | AEPD | GDPR | €4,000 | ↗ |
| 31 Jul 2020 | ASOCIACIÓN DE VIGILANTES DE SEGURIDAD DEL AEROPUERTO DE BARCELONAThe organization was fined by the AEPD in the amount of 3,000 EUR for sending an electoral census of workers to private phones via WhatsApp. The authority found a breach of data protection principles. | ES | AEPD | GDPR | €3,000 | ↗ |
| 04 Aug 2020 | PrivatBo A.M.B.A. af 1993PrivatBo was reported to the police, and Datatilsynet recommended a fine of 150,000 DKK for inadequate data security measures. The incident led to the unintended disclosure of tenants' confidential information on USB drives. | DK | Datatilsynet | GDPR | €20,145 | ↗ |
| 05 Aug 2020 | BANKIA, S.A.BANKIA, S.A. was fined by the AEPD 50,000 EUR for retaining a former client’s personal data for more than 16 years without a valid basis. The authority found this to be a breach of data protection principles, especially storage limitation. | ES | AEPD | GDPR | €50,000 | ↗ |
| 06 Aug 2020 | Hozzáférési jog, adatpontosság és átláthatóság elvének megsértéseThe decision concerned unlawful processing of personal data during debt collection and breaches of access rights and information obligations under the GDPR. Both entities involved in the case were fined for their actions. | HU | NAIH | GDPR | €5,780 | ↗ |
| 07 Aug 2020 | TELEFÓNICA MÓVILES ESPAÑA, S.A.U.TELEFÓNICA MÓVILES ESPAÑA, S.A.U. was fined by the AEPD 75,000 EUR for unauthorized access to a customer's data and harassment through excessive calls and messages. The case indicates failures in data protection controls and customer contact practices. | ES | AEPD | GDPR | €75,000 | ↗ |
| 11 Aug 2020 | FEDERACIÓN DE BALONCESTO DE CASTILLA Y LEÓNFEDERACIÓN DE BALONCESTO DE CASTILLA Y LEÓN was fined by the AEPD 5,000 EUR for the unauthorized disclosure of personal data. The data included names, DNI numbers, and signatures, which were published in a newspaper and on social media. | ES | AEPD | GDPR | €5,000 | ↗ |
| 11 Aug 2020 | DERDIX 5000 SLThe entity published photos of minors in a magazine without obtaining consent, which constitutes a breach of data protection rules. The case concerns the unauthorized disclosure of children’s images and was sanctioned by the AEPD. | ES | AEPD | GDPR | €2,000 | ↗ |
| 12 Aug 2020 | TuslaThe Irish DPC fined Tusla EUR 85,000 in inquiry IN-18-11-4. The fine has been collected. | IE | DPC | GDPR | €85,000 | ↗ |
| 13 Aug 2020 | Engedményezés után kezelt telefonszám és e-mail címThe case concerned unlawful processing of personal data in connection with debt collection. The controller was fined for breaching the GDPR principles of data minimization and lawful basis. | HU | NAIH | GDPR | €5,800 | ↗ |
| 18 Aug 2020 | HSEThe Irish DPC fined HSE EUR 65,000 in inquiry IN-19-9-1. The fine was collected. | IE | DPC | GDPR | €65,000 | ↗ |
| 19 Aug 2020 | Anonymizováno (ÚOOÚ UOOU-05284/19-36)The entity was fined for publishing a partially anonymized criminal order on Facebook that still contained personal data. The authority found a breach of GDPR principles governing lawful processing and personal data protection. | CZ | UOOU | GDPR | €383 | ↗ |
| 21 Aug 2020 | ZSOUODO imposed a PLN 50,000 fine on ZSO for breaching personal data protection rules. The case concerned non-compliance with requirements under data protection regulations. | PL | UODO | GDPR | €11,369 | ↗ |
| 24 Aug 2020 | Głównego Geodetę KrajuUODO imposed a fine of PLN 100,000 on the Chief Surveyor of Poland. The authority found a breach of the lawfulness principle in personal data processing due to the intentional disclosure, without a legal basis, of land and mortgage register numbers obtained from the land and building records. | PL | UODO | GDPR | €22,735 | ↗ |
| 26 Aug 2020 | Anonymizováno (ÚOOÚ UOOU-03916/19-49)The entity was fined for sending unsolicited commercial communications without a valid legal basis. The conduct violated the Czech law on certain information society services. | CZ | UOOU | ePrivacy | €228,000 | ↗ |
| 01 Sept 2020 | Asociația de proprietari Bl. FC 5, orașul Năvodari, județul ConstanțaThe homeowners' association was fined by ANSPDCP EUR 500 for unlawfully processing an individual's image from the video surveillance system. The image was displayed on the building's notice board, which breached data processing principles. | RO | ANSPDCP | GDPR | €500 | ↗ |