BULLETIN №082Last updated · 31 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.4%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 22 Jun 2020 | PARTIT DELS SOCIALISTES DE CATALUNYA (PSC-PSOE)PSC-PSOE was fined by the AEPD 5,000 EUR for using personal data obtained in a doctor-patient relationship to send requests for political support. The authority found this breached purpose limitation rules for data processing. | ES | AEPD | GDPR | €5,000 | ↗ |
| 01 Jan 2015 | ZOWROOM, S.L.ZOWROOM, S.L. was fined by the AEPD EUR 500 for sending unsolicited commercial emails. The authority also found that unsubscribe requests were not honored, which constitutes a breach of the LSSI. | ES | AEPD | ePrivacy | €500 | ↗ |
| 29 Jan 2020 | CASA GRACIO OPERATION, SLUCASA GRACIO OPERATION, SLU was fined by the AEPD 10,000 EUR for installing a video surveillance system that could capture public areas and access points. The authority found that this processing breached data protection rules. | ES | AEPD | GDPR | €10,000 | ↗ |
| 23 Jan 2025 | XFERA MÓVILES, S.A.XFERA MÓVILES, S.A. was fined 100,000 EUR by the AEPD for inaccuracies in data retention relating to SIM card purchasers. The authority found a breach of the GDPR data accuracy obligation. | ES | AEPD | GDPR | €100,000 | ↗ |
| 01 Jan 2015 | SOTO GLOBAL SERVICE, S.L.SOTO GLOBAL SERVICE, S.L. was fined by the AEPD €3,200 for sending nine unsolicited commercial emails without prior consent. The authority found a breach of Article 21 of the LSSI. | ES | AEPD | ePrivacy | €3,200 | ↗ |
| 14 Jun 2021 | B.B.B.The entity was fined by the AEPD EUR 3,000 for publicly disseminating surveillance footage without justification. The conduct breached data protection principles. | ES | AEPD | GDPR | €3,000 | ↗ |
| 15 Sept 2022 | EDITORIAL RIBADEO S.L.EDITORIAL RIBADEO S.L. was fined EUR 1,000 by the AEPD for failing to meet the information obligations under Articles 12 and 13 of the GDPR. The authority also noted non-compliance with previous data protection decisions. | ES | AEPD | GDPR | €1,000 | ↗ |
| 04 Mar 2021 | ALAVA NORTE, S.L.ALAVA NORTE, S.L. was fined by the AEPD in the amount of 4,000 EUR for installing surveillance cameras without sufficient justification. The cameras captured both public and private spaces, which breached data protection principles. | ES | AEPD | GDPR | €4,000 | ↗ |
| 01 Jan 2019 | GLOVOAPP23, S.L.GLOVOAPP23, S.L. was fined by the Spanish data protection authority, AEPD, in the amount of €25,000. The authority found a breach for failing to appoint a Data Protection Officer as required by Article 37 of the GDPR. | ES | AEPD | GDPR | €25,000 | ↗ |
| 05 Dec 2025 | XThe European Commission imposed a EUR 120 million fine on X for breaching transparency requirements under the Digital Services Act. The penalty covered deceptive verification design, an inadequate ad repository, and restricted access for researchers. | EU | European Commission | DSA | €120,000,000 | ↗ |
| 10 Oct 2023 | TemuThe European Commission imposed a EUR 200 million fine on Temu under the Digital Services Act. The authority said Temu failed to identify, analyse, and assess systemic risks linked to illegal products offered on its platform. | EU | European Commission | DSA | €200,000,000 | ↗ |
| 05 Jul 2021 | Anonymisoitu (TSV 943)The controller unlawfully processed employees' location data, breaching the GDPR principles of data minimization and lawfulness. The case concerned processing that went beyond what was necessary for the stated purpose. | FI | TSV | GDPR | €25,000 | ↗ |
| 28 Oct 2025 | Aktia PankkiThe sanction panel of the Finnish Data Protection Ombudsman’s Office imposed an EUR 865,000 fine on Aktia Pankki for deficiencies in information security in its strong electronic identification service. The incident caused some users to see other customers’ data in services requiring strong authentication. | FI | Tietosuojavaltuutetun toimisto | GDPR | €865,000 | ↗ |
| 17 Dec 2024 | Sambla Group OySambla Group Oy was fined EUR 950,000 by TSV for failing to adequately protect loan applicants' data. The data was accessible to third parties through unique URLs, which breached GDPR requirements on data protection and security. | FI | TSV | GDPR | €950,000 | ↗ |
| 29 Apr 2022 | TelemarkkinointiyritysA telemarketing company was fined for failing to comply with a Data Protection Ombudsman's order to provide a data subject access to a call recording. The case concerned a breach of GDPR Article 15 on the right of access. | FI | TSV | GDPR | €8,300 | ↗ |
| 10 Sept 2025 | S-PankkiThe sanctions board of the Office of the Data Protection Ombudsman imposed a EUR 1.8 million fine on S-Pankki for failing to ensure information security in its online banking authentication service. The case concerned a software vulnerability in S-mobiili that allowed logins using another customer’s credentials and resulted in a personal data security breach. | FI | Office of the Data Protection Ombudsman | GDPR | €1,800,000 | ↗ |
| 01 Jan 2025 | Sambla GroupThe Finnish Data Protection Authority fined Sambla Group EUR 950,000 after unauthorized parties accessed credit application data by manipulating web addresses. The authority found that the company had not implemented adequate safeguards to prevent the breach. | FI | Tietosuojavaltuutetun toimisto | GDPR | €950,000 | ↗ |
| 23 Jul 2020 | Anonymisoitu (TSV 632)The controller failed to implement data subject rights under GDPR Articles 12, 15, 17, and 21. It also did not obtain valid consent for electronic direct marketing. A fine of EUR 7,000 was imposed. | FI | TSV | GDPR | €7,000 | ↗ |
| 04 Jun 2025 | Yliopiston ApteekkiThe Finnish Data Protection Ombudsman’s sanctions board imposed a EUR 1.1 million fine on Yliopiston Apteekki for data protection deficiencies. The decision states that cookies and other tracking technologies used in the online pharmacy disclosed prescription-related and other customer data to Google and Meta. | FI | Office of the Data Protection Ombudsman | GDPR | €1,100,000 | ↗ |
| 16 Dec 2021 | LiikennevakuutuskeskusThe entity was fined for collecting patient data excessively for insurance claim resolution. The authority found breaches of data minimization and fairness principles. | FI | TSV | GDPR | €52,000 | ↗ |